Blackout in Regia
A cybersecurity escape room you play in the browser, by typing commands into a terminal.
What it is
It’s the night of Zeta’s biggest live stream. Fifteen minutes to go, and a hacker going by the name Ombra has broken into the studio network, locked the control room door with you inside and, if you don’t get out in time, will leak Zeta’s private videos during the stream.
You play in a terminal, typing commands like ls, cd and cat. The studio
network is split into VLANs, and each one has a weak spot to close: phishing,
weak passwords, the second factor, ransomware and backups, updates. Every
challenge you solve gives you one word of the code that opens the door.
The game is in Italian.
Who it’s for
Two to four players, ten to fifteen minutes, even if you’ve never seen a
terminal: there’s a tutorial, coloured text can be clicked to type it for you,
and hint gives up to three clues per challenge. There’s no game over: when
the timer hits zero you just keep going. If you get stuck, the game page also
has a full walkthrough.
Every name, password, site and piece of data is made up: nothing real gets attacked.
Technical choices
A single HTML file, no libraries and no server: everything runs in the browser. MD5 and SHA-256 are written by hand in JavaScript, so the terminal really computes file fingerprints and really finds the weak passwords: first it tries the username with numbers and years, then a list of common passwords. The second-factor code changes every 30 seconds, like in an authenticator app.