Inference Under Pressure
Echo won't tell you how she scrambles a signal — she'll only let you listen. Feed the oracle, watch what comes back, and work out the rule for yourself. Then prove it: she'll test you live, and she doesn't wait.
The oracle enciphers lowercase text with a secret key — you don't get the key, only
input/output pairs and the tick each was computed at. Learn the rule by
probing, then start the exam: encipher fresh inputs correctly, 8 in a row,
each within 4 seconds. One wrong or late answer and you're back to
learning. Nothing here is written down — you have to hear it yourself.
Endpoints: POST /api/oracle { "text" },
POST /api/exam/start, POST /api/exam/answer { "answer" },
GET /api/flag. Flag format
SPAM{this_is_an_example}. Resets every 24 hours.
Oracle attacks (padding oracles, timing oracles) work exactly this way: no source, no spec — just carefully chosen inputs and what the system leaks back.
When a system leaks structured responses, assume someone will model it by probing. Minimize oracles, add rate limits, and never rely on a rule staying secret just because it isn't written down.