Project Gates of Valhalla
Sign in Sign up

Guide

The security quiz

The one part of this platform that teaches rather than investigates. Open to strangers, on purpose.

The short version

  1. Pick a round. Twelve presets, twenty-three disciplines, 444 questions.
  2. Answer once per question — the set is dealt at the start and there is no going back.
  3. Read the explanation, especially when you got it wrong. The explanation is the point; the score is the hook.
  4. No account needed. Close the tab and come back tomorrow; the round is still there.

The idea

The one part of this platform that teaches rather than investigates, and the only one open to strangers by design. Gating it behind a sign-up would defeat it: somebody who wants to find out whether they know what a padding oracle is should not have to hand over an email address first.

444 questions across 23 disciplines, in 12 preset rounds. Difficulty runs 2 to 5 — there are deliberately no easy ones.

Playing

  1. Pick a round from the quiz page.
  2. Answer each question. The set is dealt at the start.
  3. Read the explanation. Especially the ones you got wrong.
  4. Finish and get a diploma with your rank.

The explanation is the product; the score is the hook. Nobody reads a paragraph handed to them free, and a lot of people read one they have just lost points to. That is the entire design.

One shot per question

You cannot go back, retry, or skip ahead. The set is dealt when the round starts, the current question is always the lowest unanswered one, and the moment a question is served you are committed to it.

Scoring

  • Multi-select gives partial credit as (right − wrong) ÷ (total right), so ticking everything scores nothing.
  • Ordering is graded on pairwise concordance rather than exact positions — one displaced item should not grade as total failure.
  • Bonuses routinely take a score past par. Par is the baseline, not a maximum; a flawless round has scored more than double it.
  • Grading is entirely server-side and pure, in one file. The question payload sent to your browser contains no answers, so every scoring dispute is a bug in one place.

Playing without an account

An anonymous player is identified by a hash of a cookie, never the token itself — which is what makes "close the tab and finish tomorrow" work with no account.

Anonymous rounds still count and still reach the scoreboard, carrying a generated handle rather than a name you choose. Two rounds by the same anonymous player get different handles. A public leaderboard that accepts free text from unauthenticated strangers is an impersonation problem within the hour.

Achievements and ranks

80 achievements, listed in the catalogue — completion and mastery per round and per discipline, plus a set for the unusual things. Six ranks, each with its own coin on the diploma.

An achievement earned on the final question is announced with the result rather than quietly appearing later.

Sharing a result

Share buttons are plain intent links — no SDK, no tracking pixel. The share text is built from the result data rather than read off the screen, and it carries no name, so an anonymous run stays anonymous.