Fake Documents that Alarm if Opened
schneier.com
schneier.com
So far no hits..
https://grepular.com/Automatically_Encrypting_all_Incoming_E...
They wont be able to read password reset emails or anything else in there.
I might set up a canary though, as it sounds like a useful way of being made aware of a compromise.
I wonder the same thing about my setups. I have a password manager with random passwords for every site/forum that I encounter. It'd be nice to know of the efficacy of this work - has it helped me in any way? I'll never know.
I have heard (not confirmed) that mapmakers introduce small errors into their maps to detect competition copying their maps instead of the terrain.
It just occurred to me that stego could be applied at the word level to get around spelling and grammar corrections.
Two problems: 1: When outlets learn this is the case, they just make sure never to publish the exact phrasing of any such leaked document. 2: This only helps you track down the leaker, not prevent him from leaking. The "phone home" document would presumably catch the leaker as he's collecting the documents.
From what I read it would introduce subtle changes based upon some identifier (either IP address, user account or both).
The variation was generated by using unicode characters which were either invisible or very close substitutions to actual characters. This could be countered by anyone who knew it was there however.
There was also the ability to write a block of the post in multiple different ways. With 5 blocks written 5 ways each you can get 3125 different variations of a post.
There is probably some interesting mathematics relating the level of redundancy to the minimum number of documents that would be required to make an un-tracable version.
Highly recommend.