New every day

The Daily Adversary

Three questions All tools

Three questions, the same three for everyone, replaced at midnight UTC. The format rotates — forged mail headers one day, a prompt injection buried in something an agent read the next, then typosquats, then a CVE headline that may be invented, then a Content-Security-Policy to read honestly. It takes about two minutes. There is no account and your answers stay in your browser.

What this is

Security awareness training is annual, an hour long, and forgotten by Thursday. The reason is not that the content is bad. It is that recognition is a perishable skill, and you cannot build a perishable skill in one sitting a year any more than you can get fit at a single gym session. What works is small and frequent — two minutes, every day, on material that changes.

So: three questions a day. Everyone gets the same ones, which is what makes it worth arguing about with a colleague. They are replaced at midnight UTC. Your streak and your answers live in this browser's local storage and go nowhere else, which also means they are gone if you clear your site data — a fair trade for not asking you to make an account.

The five formats

Forged or genuine. A set of raw mail headers, as they arrive. Read what SPF, DKIM and DMARC actually concluded, notice when the authenticated domain is not the one in the From line, and decide. This is the format most people are worst at, because the visible From header is the one field an attacker fully controls.

Find the prompt injection. A transcript of an agent doing ordinary work — reading a page, a ticket, a PDF, a calendar invite — with an instruction hidden in the content it retrieved. Your job is to point at the line that is talking to the model rather than to you. This is the newest of the five and the one with the least training material anywhere, which is exactly why it is here.

Spot the lookalike. Four package names, three of them the real, widely installed ones. Typosquatting works because nobody reads a dependency name twice, and the install runs code before you ever import anything.

Real or invented. A vulnerability headline. Some are real and some were made up for this drill. The tell is almost never the CVE number — it is whether the described mechanism could exist in that component at all, which is a far more useful instinct than memorising identifiers.

What does this permit? A Content-Security-Policy, and four readings of it. Policies are written once, copied forever, and misread constantly; a policy that looks strict while permitting everything is the normal case rather than the exception.

The grid

When you finish, you get a small result block you can paste anywhere — the day number, the format, the score, your streak, and three squares. It says how you did and not what the answers were, so pasting it into a team channel spoils nothing for the people who have not played yet. The squares are accompanied by the score in plain numbers, because a row of coloured boxes on its own is unreadable to a lot of people and this is meant to travel.

Missed a day?

The last two weeks are playable from the archive at the bottom. Those run in practice mode: they are marked as practice, and they do not repair a broken streak. A streak you can backfill is not measuring anything.

Where the questions come from

They are written by the people on this site, drawn from the same work the blog is drawn from — incident mail, audits, and the things that keep arriving in support. Every answer carries the reasoning, not just the verdict, because the point is the tell rather than the score. If a question is wrong, or its explanation is, say so and it gets fixed.

The tools are the other half of this: the phishing email analyzer for a real message rather than a drill one, the prompt sanitizer for what you are about to paste into a model, and the CSP builder for a policy you have to ship. The reasoning behind the injection questions is in the lethal trifecta.

← All tools