6 ms·
Fake Documents that Alarm if Opened
- jgrahamc 15y agoBut like my 'email canary': http://blog.jgc.org/2011/06/my-email-canary.html http://blog.jgc.org/2011/06/my-email-canary.html
- 0x0x0x 15y agoHi, just wanted to say thanks for the idea. I setup canaries on both my wife and my own accounts after your article made the rounds. So far no hits..
- mike-cardwell 15y agoThat's a really nice idea. I think my solution is better though. If an attacker manages to access my email account, all they're going to see are PGP encrypted emails. https://grepular.com/Automatically_Encrypting_all_Incoming_Email https://grepular.com/Automatically_Encrypting_all_Incoming_E... They wont be able to read password reset emails or anything else in there. I might set up a canary though, as it sounds like a useful way of being made aware of a compromise.
- Splines 15y agoIt'd be interesting to see how your (and other's) setup have endured actual attacks. As someone non-versed in security, I think your approach sounds great. But how does it fare when someone comes knocking? I wonder the same thing about my setups. I have a password manager with random passwords for every site/forum that I encounter. It'd be nice to know of the efficacy of this work - has it helped me in any way? I'll never know.
- lawnchair_larry 15y agoI don't like this because it only works if you enable remote loading of images on your own account, which feels like huge collateral damage to me. A ton of email you receive will attempt to use this technique against you, so I've always disabled that.
- tincholio 15y agoIn gmail you can whitelist addresses from which you allow the loading of images.
- lawnchair_larry 15y agoAh, nice tip. I like it now.
- phpnode 15y agoI've been doing this for a while with http://trackmycv.com/ http://trackmycv.com/ basically you can embed a transparent pixel in an MS word (or any other kind of MS office document) and get notifications whenever it's opened.
- praptak 15y agoThere is a much better (and older) idea: introduce subtle watermarks into the actual content of the document itself. Minor typos, changes of word order, maybe even different facts. Different people in your organization get access to those slightly different versions. Once a document emerges where it's not supposed to be, your knowledge about who might have leaked it increases. I have heard (not confirmed) that mapmakers introduce small errors into their maps to detect competition copying their maps instead of the terrain.
- delinka 15y agoWhile reading the blog post, I was thinking about steganographically inserting data into printed documents. It might be more difficult in this age of grammar and spell checkers, but sounds fun to play with. It just occurred to me that stego could be applied at the word level to get around spelling and grammar corrections.
- onemoreact 15y agoI think subtle forming and or font changes is probably the easiest approach.
- mseebach 15y agoI don't think it's unreasonable to think that a well-funded team of computational linguists could come up with enough equivalent grammatical/synonym permutations to render a very large number of versions of text. Two problems: 1: When outlets learn this is the case, they just make sure never to publish the exact phrasing of any such leaked document. 2: This only helps you track down the leaker, not prevent him from leaking. The "phone home" document would presumably catch the leaker as he's collecting the documents.
- Djehngo 15y agoThere was a tool which was used to trace forum leaks/mirrors, it was made/used by an Eve Online Alliance of all things. (If you can find a 2010/2011 mirror of the "Pandemic Legion" forums there should be a description of it on there). From what I read it would introduce subtle changes based upon some identifier (either IP address, user account or both). The variation was generated by using unicode characters which were either invisible or very close substitutions to actual characters. This could be countered by anyone who knew it was there however. There was also the ability to write a block of the post in multiple different ways. With 5 blocks written 5 ways each you can get 3125 different variations of a post. There is probably some interesting mathematics relating the level of redundancy to the minimum number of documents that would be required to make an un-tracable version.
- TorKlingberg 15y agoThe phone home mechanism is not necessarily on the client side in MS Word macros. It could be the file server logging access to the fake documents.
- jasonkolb 15y agoThis is why I would never heavily use a computer without something like Little Snitch (http://www.obdev.at/products/littlesnitch/index.html http://www.obdev.at/products/littlesnitch/index.html) installed. Highly recommend.