What Makes a Good Puzzle Solving Team
By Mystic of Co9
I have been working with The Council of Nine to solve puzzles since 2012. Our team is made mainly of people who met entirely through attempting (and failing) to solve the Defcon 20 Badge Challenge. Through the years we’ve continued to work together, eventually earning two black badges for being the first to solve DC23 and DC24.
We have learned a lot about puzzle solving through this experience, but we’ve also learned a lot about working as a team. My intention with this post is to share a bit of this wisdom. I will start by dispelling some common misconceptions and then present what I think might actually make a good puzzle solving team.
Misconceptions
1. Tools: Great teams have some kind of magic tool that solves everything.Tools help, but a good puzzle will be resistant to advanced tools and/or require only the most basic of tools to solve. Every Defcon badge puzzle that I’ve worked on could have been solved with nothing more than pencil, paper, and google. Occam’s Razor is always your friend. Forgetting that can lead you down some interesting rabbit holes (See the CryptoK Cipher: https://twitter.com/0xCryptoK/status/1292316580957700096).
2. Genius: There’s one uber solver on the team that does all the work.
You may in fact have some real smart people on the team, but beware that solving puzzles isn’t something you can master like programming or music. Even if you have someone who is a master cryptographer on your team that person isn’t going to just know that, for example, the drum beat in the background of the audio is morse code. That takes more than technical skill to solve. That master cryptographer on your team is very useful for running cipher text though obvious solutions (like Caesar or basic transposition) but don’t assume that they are going to be able to throw intellect at every problem while everyone else sits back and enjoys the show.
3. Team Size: Having 30 people on your team means you are 30X more likely to solve.
It’s more about how you organize your team than how many people are on it. The last thing you want is lots of people generating lots of noise. If you can pull off a 30 person team, more power to you, but you’ll find that most large teams only have a small number of people actively working on a puzzle at a time. You’ll also find that smaller teams tend to be way more organized, which is critical if you want to succeed. With good organization you could have a bad ass team with only 3 people. For more on how to organize your team see the suggested team roles later in this post.
4. Deception and Social Engineering: The best teams social engineer their way to the solution and play dirty.
We use every tool available to us and social engineering and deception are part of the game, however it is rare that teams succeed on this alone. Information gained through social engineering, in my experience, can certainly give you an edge, but only a small one. Your team has to combine this with your own unique solves. The reality is that if your team is good you’ll be so far ahead at points that social engineering is useless.
Let me also give you a word of warning: beware of social engineers who want to join your team. They might at some point use their skills against you. I’m sure every good team has a story about this to tell over some beers.
What Actually Makes a Good Team?
1. Variety of skills: Hardware, coding, music, languages, pop culture, and classic/modern cryptography are all valuable skills to have represented on your team. Don’t worry too much about finding geniuses. A lot of our solves came from people who were simply willing to try something no one else thought of yet. That comes out of having people with a variety of perspectives and knowledge bases.
2. Team Players: People on the team should want to be on a team. They need to be willing to be a part of something greater than themselves. If you want individual glory, then maybe you shouldn’t be on a team. It sounds harsh, but if you join a team you are part of that team. Even if you didn’t have any solves yourself or you ended up solving a ton of the puzzles, it’s the team that succeeds or fails, not you personally. There will be arguments, there will be frustrations. Deal with this as a team. Strong egos and chasing individual glory can be toxic to a team at its core. Don’t let it fester too long.
3. Clearly Defined Roles: Especially for larger teams you’ll want to decide on some roles. We would suggest having at least these three:
Front line: People who take all the puzzles and start trying everything to solve them right away. They are gathering all the clues, running them through tools, trying different analysis methods, etc..
Middle line: There people are taking everything the front line folks are doing and verifying it. If the front line says for example, “the cipher text is 40 characters and here is the hex and binary of it, I tried all ROTs, nothing” then the middle line does all of that again to make sure there weren’t any mistakes or anything missed. They are also looking for missed correlations. For example, they might say “oh the text on the badge is also 40 characters, I’ll try OTP with all of them”.
Documentation: These people are taking anything that seems like a solution or a clue and documenting it. This can be done in a google doc, a flow chart, markdown in github, etc.. For larger teams, it can be a good idea to split this role so one person is documenting and the other is communicating when the docs are updated with new information. This helps a lot in moments where everyone is stuck. Did we miss a clue? Is there something we still haven’t solved? Is there a keyword we haven’t used? The documentation should be able to answer all these questions.
4. Year Around Communication: Don’t be a “see you next year” team. Keep up communication year around. Try solving puzzles outside of your main focus. Not everyone on the team will be able or willing to do this, but some will. The more you work together the better you are going to get at it. Also, Don’t take for granted the fact that your team is full of smart people who share a common interest. I’ve gotten to know people through Co9 that helped me to improve my skills in a lot of areas beyond puzzle solving. In the end, isn’t the real solve all the friends you made along the way?
I hope this post helped to dispel some myths about puzzle solving teams. I also hope this inspires others to start new teams or improve their own. A lot of the members of Co9 genuinely enjoy helping others with this stuff. Don’t hesitate to reach out. We know this is a competition, but we love solving puzzles and meeting others who share this pretty niche passion.
Defcon tends to give out only one black badge to the winners of the badge challenge (if at all). We don’t do it for the badge (although when we do get a black badge we make more [links to badge copy posts]). We do it for the challenge. I think this embodies the hacker ethos in a pure way. Let others take the spotlight, the sponsorships, the glamorous parties, and the fancy job offers. Who has time for that? We’re here in this hotel room solving.
