Canarytokens: Honeypot for critical credentials, get notified when they are used (2015)
canarytokens.org
canarytokens.org
For example, an application-specific HTTP proxy for your GITHUB_TOKEN. You can use a canary token for the internal user-facing auth. https://github.com/legobeat/git-auth-proxy [0].
That piece is being used here[1] in order to make it transparent for the user and I intend to add more features there for credentials- and secrets compartmentalization. Been keeping it fairly structured so you could also use it as a reference if you ever do similar stuff and want some inspiration or copypasta for your personal hacking.
[0]: Caveat: The proxy repo is a fork and the documentation is still more reflective of the previous owners intentions. I ripped out all the Azure/k8s integrations.
As opposed to something which can be smuggled out and reused offsite.
I'm also thinking that by centralizing (still locally) the configuration, we can get better key rotation hygiene habits without needing to compromise on credential granularity .
Just like there are security benefits in using a secured HSM instead of a world-readable private-key file stored in your unencrypted home directory, even if, yes, the HSM can be abused by a locally privileged attacker.
(I'm definitely not saying I have a silver bullet though, and I don't think one exists. Like any realistic solution, it should be part of a defense-in-depth strategy. Things like hardware keys make for incremental gains, etc)
You can lock down access to vault with whatever degree of 2FA/IdP you wish. So - your workflow is authenticate to Vault, which uses your identity (and possibly group membership from an IdP like Okta) - to identify the groups/policies you have, which in turn then grant you the authority to request (short lived < 24 hours typically) tokens that are generated in real-time (and likewise terminated when they age out).
The added benefit here is that if your service token is exposed - (A) The window of vulnerability is very short lived, and, (B) it's isolated to a single service.
I haven't worked with Boundary - but it sounds like your solution has some closer comparison to Hashicorp Boundary, right?
While you certainly can run Vault and Boundary independently, they are more designed to be deployed across an organization. Setting them up is anything but seamless - by design. Again, I think they can be complementary. Adding a Vault component to l7-devenv is a thought that came up before but I'll probably wait until popular demand before making anything public there. If you already have a setup it should not be too tricky to integrate, I think.
If you squint closer I think you can start seeing even more parallels to HC solutions but that is more because none of these patterns are really fundamentally new but the building blocks of we've all been doing for decades. It's just new clothes and ways to make things play together nicely (xkcd 927). And hopefully we can bring these strategies like mTLS to new audiences and bring down barriers for adoption of secure practices in general.
> no proxy
Look again ;) (Envoy)
https://learn.microsoft.com/en-us/defender-xdr/deception-ove...
But in my opinion, deception tech is best implemented in-house. Nothing wrong with using externally developed tools, especially for high signal-to-noise things like honeypots but the actual monitoring and alerting data flow should be ideally be environment specific.
If your company is making deception software, then you already know that Microsoft, Google and similar companies are your competition if your strategy is to do what they do, but I'm sure you've already strategized around all this.
Bingo - between this and not confining yourself into the restrictions of a single platform (what the platform feature vendors have to do - Microsoft deception offers solutions only specific to certain Microsoft infrastructure, etc. ), you can create some terrific outcomes in this domain.
I totally support your approach, and I hope your startup succeeds. Although you should really name-drop it here.
Hit me up if you'll be at Vegas hacker summer camp next week and want to get a friendly coffee in, the founders email on the website lands into my mailbox.
I also have a lot of security knowledge (mostly from books rather than practical experience) from non infosec case studies like intel agency operations, insurgent groups, law enforcement, military, organised crime and other scenarios where the consequences of making bad decisions is incredibly high and probably involves some level of violence at a minimum.
I always thought that this XKCD comic (https://xkcd.com/538/) summed it up nicely precisely how that factor can actually change your threat model fairly significantly in a way that I don’t generally see turn up in the field of cyber security specifically.
But more than that I just generally found that to be an invaluable resource for when it comes to how to think about what actually makes these things work in the real world and what you can actually do in order to really make life very miserable for an adversary long before they even realise what’s going on.
It’s probably been the most fun thing I’ve built in 20 years.
`-p rxwa` causes logging of any read, exec, write or attributes change on that file. More in `man auditctl`.
Among others, this has a benefit that, in principle, such honeypot triggers immediately and not only after someone decides to try using some actual credentials/data.
Obviously needs some work to make this robust (logs monitoring plus alerting), but it's a nice building block worth knowing and, if you care, then you probably already have those additional pieces in place anyway.
If someone receives an email coming from your employer's domain with a virus or a child porn video attached, your employer had better be able to identify the sender account through logs & audit trails.
If you embed a URL in emails then a lot of corporate email gateways will blindly follow the link, trying to check it for malware.
This may or may not be a useful security measure but it has many issues. One of which is that it could look like spying.
And when the ip address comes from the employers location…
Super easy to configure via webhooks into a siem or any kind of alerting platform.
But basically they would embed a remote image inside the file so it would call out to a web server upon loading the image. It also had the added benefit from a LEO perspective that if the users main defence was running TOR browser that it would bypass that and provide the users true IP address.
However, as I mentioned in another comment here, I actually think those particular kinds of honeypots are kind of dumb in that they only catch stupid adversaries.
Opening those files on your own machine as an attacker while connected to the net is one of those do not pass go, do not collect $200 go directly to jail moves.
It's enough to catch one guy, one time. Then you follow his physical or digital traces.
There’s even an argument that all you’ve done is tipped your hand to the adversary that deception is at play in this scenario and allow them to adjust their approach accordingly.
Not even suggesting that would be a horrible thing to happen, even in that scenario you most likely can at least slow them down but if you never know you’re being targeted in the first place it doesn’t matter too much when that clock starts.
The ideal scenario I think you should actually be aiming for here is to craft a situation where you know about them but they don’t know that you know. That’s a window of time where you very clearly have an upper hand.
That isn’t actually that hard to create. For example one technique I have at that really early stage is to return a 403 auth error on a web service and set a cookie that looks very natural to its environment but is also very obvious as to how you could change it in order to no longer get a 403 response.
The moment I get a request with that new cookie value I instantly know I have something I should be paying attention to and I know it’s a real person not a bot. The adversary however has no idea yet what’s going on, they just think they hit a gold mine.
As a defender, you only get to fail once for it to be costly. As an attacker, you can often fail hundreds or thousands of times depending on what they have for observability. Adding offensive elements helps level the playing field.
I have story after story after story of people who should have known better who got done for really silly shit.
I’m only making the argument here that that specific technique has some real limitations and known work arounds to the point that people actively know to look for it and that as a result I would personally look for other techniques that don’t have the same set of trade offs.
They get your foot in the door, and (particularly techniques) eyeballs looking at ads for their hardware. Looking at their site[0], the minimum you can buy is 2, at a price of $5k total