I'd pay for that service.
I'd pay for that service.
I can imagine paying for a 'cloud watch' service that keeps an eye on all my online accounts and tells me if something odd is happening.
Agreed, this is another problem. However, I think that it also depends on who you think might be targeting you. I know that a few years ago, plenty of everyday non-technical folks "hacked" their ex-girlfriend or boyfriends' accounts by doing a password reset with known details.
If the aim is to get notified of similar issues (e.g. my home laptop accessing during office hours), such a service could have merit.
Which is another reason why the IP-based approach works better.
An IP based check won't help you there. This canary would.
Suppose he uses http://googleblog.blogspot.com/2011/02/advanced-sign-in-secu... and has it remember the second authentication for 30 days (available from a checkbox). Then someone who has compromised his machine and has installed a keylogger can find it password, and log back in as him from that machine when he is not there. Two-factor has not saved you. Nor has the IP check.
And yes, you're right. If someone owns your personal machine you have a whole lot of other problems. This fact makes discovering that someone owns your machine more important, not less.
If any of the tools you mention were readily doable today, I fear we'd be so deep in trouble, no canary would help.
Seriously, most online security works only because the competent people have better things to do.
I wasted _days_ recently trying to track down code bugs that weren't there - a piece of Cisco gear that was in the clients network was running a standard configuration called SMTP Fixup which was deep packet inspecting and rewriting the "250-STARTTLS" capability responses and passing them on as "250-XXXXXXXA" on the fly. It took me way longer than it should have to debug, partly 'cause I started looking in the wrong place, but largely because most of the testing we did was with mail clients that were perfectly happy to transfer mail unencrypted when the STARTTLS capability wasn't announced.
Anybody MITMing you in Starbucks could easily do the same.
A little bit of thinking with my "evil hat" on leads me to believe a similar protocol aware packet inspection/modification tool could easily rewrite webpages on the fly, looking for links to common service login forms and rewrite appropriate links and form actions to be http instead of https...
Maybe an appropriately paranoid way to set up this sort of canary is to have all your mobile (ie, non-fixed ip address) devices use a vpn into a trusted and well secured host?
That already exists in the form of sslstrip: http://www.thoughtcrime.org/software/sslstrip/