Contradiction Hunting: Finding the Alibi the Evidence Does Not Support
The challenge
At 02:14 UTC someone used a shared CI token to force-push the release branch and made 214 commits of history unreachable. Only four engineers hold that token, and all four gave an account of their night. Three of those accounts are corroborated by records that none of them controls: an airline manifest, a badge export, a voice bridge log. The fourth is backed only by evidence the person produced themselves, and that evidence does not survive being checked. Do not look for a confession, look for the statement the artifacts contradict. Submit the username of the engineer whose alibi breaks.
What you'll learn
- Rank evidence by the independence of its source
- Read EXIF DateTimeOriginal as capture time rather than publication time
- Cross-check a claimed event against an independent listing
- Use session logs to place an account online during an incident window
- Reason toward a conclusion by contradiction instead of by confession
- Recognise a red herring whose scope does not cover the claim
Skills tested
Prerequisites
- Reading timestamps across time zones
- Awareness that images carry EXIF metadata
How it works
Investigations rarely turn on a confession. They turn on the moment one account stops fitting the record. The productive question is not who looks guilty but which statement the artifacts refuse to support, and getting there means grading evidence by who produced it.
Three of the four alibis rest on records the suspect does not control. Kiera Hale's is an airline manifest: boarding scan at 22:11 on the 28th, arrival 15:20 on the 29th, no connectivity fitted to the aircraft. Sofia Bergstrom's is a recorded incident bridge with her voice logged at 02:12 and 02:16, minutes either side of the push. Rafael Mendez's is a badge turnstile with no re-entry, supported by the absence of any VPN session in his name. None of these can be manufactured by the person they exonerate.
Tomiwa Okafor's alibi is the exception: it rests entirely on a photo he posted himself. The photo is real, the GPS really is the venue, and that is exactly what makes it persuasive. What it is not is contemporaneous. DateTimeOriginal reads 2026-08-22 21:47, seven days before the incident, and the venue listing confirms the band played London only once on the tour, on the 22nd. Posting time and capture time are different facts, and only one of them is evidence of where you were.
The VPN concentrator closes it independently: a session for t.okafor from 01:58 to 02:39, wrapped around the 02:14 push. The badge export is a red herring, because it covers the building and remote access does not require being in it.
Common mistakes
- Accusing r.mendez because his alibi is the weakest. Going home unobserved is unverifiable, but unverified is not contradicted, and the VPN log shows no session in his name at all.
- Using the badge export as proof of innocence or guilt. It only records the building. Every engineer here could work remotely.
- Trusting the social post timestamp. The post went up at 02:52, but a post's publication time says nothing about when the image was captured.
- Accusing s.bergstrom because she had a VPN session. She did, and she was also on a recorded voice bridge speaking at 02:12 and 02:16. Being online is not the same as being the actor.
- Answering deploy-bot. That is the shared CI token used to make the push, not a person, which is why the investigation is needed at all.
- Stopping at the first inconsistency. The EXIF date alone is suggestive; the venue listing and the VPN session are what make it conclusive.
How to defend against it
The investigation was only necessary because the push was made with a credential four people share. Attribution has to be designed in before an incident, not reconstructed after one.
- Eliminate shared tokens. Issue per-user, short-lived credentials so the audit log names a person rather than a bot.
- Protect release branches: block force-push entirely, require signed commits, and require review for history-altering operations.
- Correlate identity across systems, so a VPN session, a git action and a badge scan can be joined on one principal automatically.
- Retain independent logs. The bridge recording and the concentrator log were decisive precisely because no single team owned both.
- For anyone submitting evidence, treat self-produced artifacts as claims to verify rather than facts, and check metadata before accepting an image as proof of presence.