deuterium(1)

NAME

deuterium — security blog, occasionally self-aware

SYNOPSIS

deuterium [--skin=SKIN] [--no-buttons] [POST…]

The command line is a joke. The links and browser controls below work.

DESCRIPTION

CTF writeups, cryptography tutorials, and ramblings. Start at Home, browse the Archive, or pick Writeups, Tutorials, or Ramblings. Archive filtering needs JavaScript; the full list remains readable without it. The feed works in a feed reader.

For controls, see OPTIONS, GAME CENTER, SCOREBOARD, ENCRYPTED PAGES, BROWSER PRACTICE, PLAYGROUND, TETRASQUARES, CITATIONS AND PRINT, and SHARING.

OPTIONS

--skin=SKIN
Open the Theme menu and choose a Visual theme, or use ?skin= with a theme ID. Try Grid Meltdown or return to RPN Garden. A valid query overrides the saved skin and saves the new choice. An unknown ID falls back to the saved skin, or RPN Garden. The choice is remembered, like most mistakes.
dice
The dice button chooses a different visual theme from the picker. It does not change the separate light/dark preference.
dark mode
The moon/sun button switches light and dark mode and remembers your choice. Until you choose, it follows the system preference. Theme controls need JavaScript; blocked storage can make preferences last only for the current page.
--no-buttons
Unsupported. See BUGS.
-v, --verbose
No-op. Everything is already verbose.
-h, --help
You are reading it.

GAME CENTER

Some posts carry challenge boxes. Enter your answer and press Check flag. The checker runs SHA-256 locally in your browser; it needs JavaScript and Web Crypto, normally over HTTPS. Answers are case-sensitive, with surrounding whitespace removed. Follow the challenge's stated format. A format warning is not a hint about the answer.

When a post supplies hints, use its hint buttons to reveal them. Attempts and used hints are saved alongside local solve progress. Sound toggles the success chime; the system's reduced-motion setting also disables that chime and replaces confetti with a static ribbon. Neither the hints nor the scoreboard are a competition referee.

SCOREBOARD

The scoreboard reads this browser's progress: solve timestamps, local verification labels, attempts, and hints used. These records are editable, answer-free history, not an account score or proof of a solve. Clearing browser site data can lose them; there is no automatic cross-device sync.

Choose Copy public progress as JSON, then paste the result in another browser's scoreboard and press Import pasted progress. If clipboard access is blocked, copy the text from the box. Exports use version 3 and include only public challenge IDs and their known aliases. Private or retired challenges remain old local progress on this device, outside the transfer.

This empty version-3 example contains no answers or challenge IDs. Importing it does not reset progress:

{"version":3,"solves":{},"attempts":{},"hints":{}}

Imports validate the schema, public IDs, dates, counts, and hint numbers before merging. An imported receipt alone stays unverified, even if its JSON claims verification; an already checked local solve keeps its status. Version-2 legacy imports are also accepted. Only a supplied legacy answer that matches the public checker can make that imported solve checked locally. A bad answer or invalid record rejects the import. Legacy answers are not saved in progress or handed to encrypted pages. Old answers already in local storage are stripped when the checker engine loads, leaving unverified history. Storage failures can prevent that cleanup or make new progress temporary.

ENCRYPTED PAGES

An encrypted article needs its actual key. Enter it in the unlock field and press Unlock; manual unlocking does not require saved progress or answer storage. Decryption runs locally with JavaScript and Web Crypto over HTTPS (or localhost). A checked scoreboard row cannot unlock ciphertext. Public titles, teasers, routes, and ciphertext are not private, even for pages omitted from listings.

Answer handoff is optional and off by default. Before solving, enable Keep correct answers in this tab for chained pages on a checker, or Remember answers in this tab on an encrypted page. Matching pages can then try the remembered answer; successful decryption still decides whether they open. If you solved before opting in, use Enter answer again and submit it afresh. Tab storage holds at most 32 answers, dropping the oldest entries when full.

Relock
Hides the opened article without forgetting remembered answers. During decryption the control says Cancel unlock. A reload may open the article again while its answer is saved.
Clear tab answers
On a checker, removes saved tab answers, opts out, and relocks an encrypted article on the current page. On the encrypted-page form, the equivalent control is Clear saved answers and lock. Neither control erases scoreboard progress.

Tab answers are plaintext in sessionStorage, readable by scripts on this site, including analytics. Browser restore or tab duplication may retain them; closing a tab is not a cleanup guarantee. Clearing or relocking cannot erase other tabs, browser memory, copied text, or downloaded attachments. Downloads made after unlocking are plaintext. If clearing reports a storage failure, saved answers may remain; use the browser's site-data controls for cleanup.

BROWSER PRACTICE

Some archived challenges have a practice terminal. Choose a listed Version, then Start; nothing runs before that. Enter sends input, Shift+Enter adds a line, and Send submits the input box. Stop interrupts computation. Reset clears the running session without starting another, but keeps saved completion. JavaScript and module Worker support are required.

Practice rewards are public dummy values, not original event flags. They do not satisfy the original answer checker or unlock its encrypted writeup. Completion is stored separately for each challenge version on this device, outside the scoreboard and its JSON export. The terminal's Browser limits and console API panel documents input limits and scripted use.

PLAYGROUND

The playground runs Z3 in your browser. In Sudoku, choose Easy, Medium, or Hard, edit the grid, and press Solve; Clear empties it. In SMT-LIB, pick Trivial assert, n-Queens (6), or Sudoku, as SMT-LIB, or write your own SMT-LIB 2 script, then press Run. These are the available presets.

The engine loads on first Solve or Run, not on page open. It is about 35 MB uncompressed and may register a service worker and reload to enable worker execution. This needs JavaScript and WebAssembly. The worker path has a 30-second run budget; the synchronous fallback cannot guarantee an interrupt and can stall on heavier scripts.

TETRASQUARES

Tetrasquares is the falling-tetromino game. Build gold and silver 4x4, 6x6, and 8x8 squares. Choose Start 1,008-piece daily for a dated game or Start endless play. The game lists keyboard bindings, lets you rebind them, and supplies on-screen buttons. Its layout is separate from the blog's theme picker.

The square catalog has examples and construction practice. Practice has no gravity or timer, disables Hold, and does not count toward daily results. The scoring guide explains how squares earn points when their rows clear. The game and interactive catalog need JavaScript; the scoring guide is readable without it.

CITATIONS AND PRINT

Eligible public articles and writeups have a Cite panel with selectable BibTeX and Download .bib. These work without JavaScript. A PDF link appears only in releases built with optional PDFs; an ordinary HTML release does not advertise missing files. Locked, hidden, unlisted, and noindex material is excluded, as are standalone pages such as this manual.

Use the browser's Print command, Ctrl+P (Cmd+P on macOS), for a print view or your browser's Save as PDF option. That is separate from a published PDF download. Inspect the preview before saving, especially if you have unlocked private content; a local printout or PDF remains a copy after you relock the page.

SHARING

The floating Share this page button needs JavaScript. It opens a QR code and the page's canonical URL, with Copy link. Escape, an outside click, or the same button closes it. If QR loading or clipboard access fails, the URL text is still available to copy manually.

Article footers also have Share this article. That expandable panel contains a build-time QR image, URL text, and Open QR SVG link, all usable without JavaScript. With JavaScript, its button uses the browser's share sheet when available, then falls back to clipboard copying or displaying the URL if sharing fails. Both QR controls share the canonical page address, not the current theme query, fragment, or saved progress. A link to an encrypted page does not carry its key or unlocked content.

MISSING PAGES

The 404 page handles missing addresses. Its invented article titles are wordplay, not recovered posts or promises of future articles. Use the archive to find actual posts.

EXIT STATUS

0
You learned something.
1
You pressed the buttons anyway.
130
You left mid-read. The tab understands.
418
See teapot(1).

ENVIRONMENT

HOME
You are here.
JavaScript
Optional for ordinary reading, required for the interactive controls described above.
browser storage
Preferences and progress belong to this browser profile and site origin. Private browsing, blocked storage, quotas, and clearing site data can affect persistence.

FILES

~/.deuterium/progress
Imaginary pathname. Real progress lives in browser localStorage, under deuterium-solves, deuterium-attempts, and deuterium-hints.
tab answers
Optional sessionStorage entry deuterium-chain-session; excluded from progress exports.
practice progress
Separate localStorage entry deuterium-browser-practice-v1.

BUGS

  1. Buttons may be pressed. Consequences unknown.
  2. The dice is not cryptographically secure. Do not derive keys from it.
  3. 3am prose ships as-is.
  4. Some skins are loud.
  5. If you find a real one, the security policy accepts mail.

STANDARDS

Implements no known standard. Aspires to RFC 2324.

AUTHOR

Written by Himanshu Sheoran. Complaints may be directed to the teapot.

This is the reader manual. Authors working in a source checkout can use python3 script/blog.py --help, python3 script/blog.py preview --port 8000, or python3 script/blog.py build. Preview builds and verifies before serving locally; it is not watch mode. Full author instructions live in the checkout's AUTHORING.md, which is not deployed as a site page.

SEE ALSO

about(1), archive(1), scoreboard(1), playground(1), tetrasquares(1), square-catalog(5), square-scoring(7), 404(1), teapot(1), writeups(7), sudo(8), crypto(7), crypt(3) (unrelated)