3 ms·
Suggestion: Start slipping unique URLs into the "hidden" backend fields of systems where you'd like to know if your data was breached, improperly used, or hande
by jehb 3y ago
Suggestion: Start slipping unique URLs into the "hidden" backend fields of systems where you'd like to know if your data was breached, improperly used, or handed over to a three letter agency.
Suddenly getting hits at mydomain.com/[uuid]? At least you know somebody has looked at the data, or at the very least fed it through some processing tool that is extracting and visiting the URLs.
- mmsc 3y agoThis is called a canary and can be used in so many places: https://blog.thinkst.com/2022/09/sensitive-command-token-so-much-offense.html https://blog.thinkst.com/2022/09/sensitive-command-token-so-...
- austinjp 3y agoI'm pretty sure I've seen a SaaS that does this, but I can't remember the name.
- tailspin2019 3y agohttps://canarytokens.org https://canarytokens.org
- krick 3y agoHow do you suggest it should've been used in this case? As a PyPI username (obviously pointless), or what?
- jehb 3y agoGood question. I'm not familiar with what fields might be be collected on the PyPi backend. But the email address field alone could be enough, if you set up a wildcard DNS and made your account email something@[uuid].mydomain.com, and looked for any http traffic to that subdomain.
- datenwolf 3y agoOr run your own authorative DNS for example.com (or a subdomain used for this) and track queries on those UUID.