For added security, maybe better to hide the canary URL in a bit.ly link? Someone might know your 3 URLS.
For added security, maybe better to hide the canary URL in a bit.ly link? Someone might know your 3 URLS.
If seeing that the bit.ly URL redirects to a known-urlcanary domain would put you off visiting the URL, then seeing the raw known-urlcanary domain (not behind bit.ly) would also be enough to put you off visiting it.
MyURL.com/101/passwords /private /logins
Is the idea that you'd embed this in a way that it is automatically triggered? Or that you would leave it in plaintext somewhere and assume someone would eventually visit it if they were snooping around your stuff?
(But obviously it needs to be a hostname you're not already using for something else).
This means you don't break the system when you move IP address. Moreover, should you ever need to, you can round-robin the domain for either reliability or load-balancing (though I doubt that would be necessary).
Also, doesn't bit.ly access a URL to pull a title or generate a preview? This would send a click through to the canary as well.