docs(prd): add PRD 0014 — Learn about a breach when the stolen credential is used - #63
Merged
Merged
Conversation
…tial is used PRD.md describes this as serving fake data to attackers, which has limited value against someone already reading your files — they have won by then. The valuable version of the same idea is the CANARY TOKEN: a fake credential planted where only an intruder would find it, which alerts the moment somebody tries to use it. That inversion changes what it detects and when. Every other module tries to catch the intrusion as it happens; a canary catches it afterwards, when the attacker who already got in undetected starts using what they took. That is the case where dwell time runs to months. It also fires on theft at rest — a leaked backup, a stolen laptop — wherever the token ends up. Like the honeypot it has no false positives by construction. The design hazard is internal: the planted files must be excluded from this product's own secrets scanner, or code-scanner reports the decoys and operators learn to dismiss credential alerts — the worst possible outcome. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
vu1nz Security Review0 finding(s) in PR #? No security issues found. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Specification for the
deceptioncore module, listed inPRD.mdand not yet specified.PRD.md describes this as serving fake data to attackers, which has limited value against someone already reading your files — they have won by then. The valuable version of the same idea is the CANARY TOKEN: a fake credential planted where only an intruder would find it, which alerts the moment somebody tries to use it.
That inversion changes what it detects and when. Every other module tries to catch the intrusion as it happens; a canary catches it afterwards, when the attacker who already got in undetected starts using what they took. That is the case where dwell time runs to months. It also fires on theft at rest — a leaked backup, a stolen laptop — wherever the token ends up.
Like the honeypot it has no false positives by construction. The design hazard is internal: the planted files must be excluded from this product's own secrets scanner, or code-scanner reports the decoys and operators learn to dismiss credential alerts — the worst possible outcome.
Spec only — no implementation in this PR.