Nicholas TongCanarytokens

49 / 56

the password file that exists to be stolen

5 min read 1,109 words

A mining foreman holding a canary cage at a coal mine, 1928, U.S. Bureau of Mines photograph, the origin of the canary idea

The email arrived at 3:12am with the subject line "Canarytoken triggered". Somebody, somewhere, had just opened passwords.xlsx on my NAS, the decoy one, the one with four fake passwords in it that exists to be stolen. I sat up. I pulled the alert apart with the enthusiasm of a man who thinks he has a story, and the source IP resolved to my own laptop, on a hostname I'd typed myself two days earlier.

The attacker was my new laptop's antivirus. It was crawling network shares that night and opened the file to scan it, exactly the way a curious intruder would. Nobody stole my password file. The tripwire caught the one machine in the house guaranteed to be innocent. And that's not a complaint, because that false positive is the most useful hour of detection engineering the tool ever taught me. I'll get to why.

the part everyone gets wrong

Canarytokens are free tripwires from Thinkst, and people hear "free honeypot" and reach for the flashiest token first: a fake AWS key, because leaked cloud credentials are the scariest story on the internet. This is going to sound paranoid, but the AWS key is the wrong first token, and the reason is boring: the scanners got smart. More on that in a minute.

The part everyone gets wrong is the model itself. A canarytoken is not a honeypot server, it's an artifact whose only job is to be noticed, wired so that touching it fires an alert. Four minutes to make. You pick a type, put in an email address, and get back a file or a URL or a credential that does nothing except tell you who opened it. The Word document that phones home. The DNS name that alerts if anything ever resolves it. The kubeconfig sitting in a folder it should never leave. The token list now runs from web bugs and DNS tokens through Excel, PDF, AWS keys, Azure login certs, a Windows folder trigger, WireGuard configs, credit cards, and as of June an MCP decoy aimed at AI agents. The code is open source and self-hostable in Docker, and the paid product, full Thinkst Canaries, starts around five thousand a year for two devices by the site's calculator. I can't verify that figure anywhere official, so treat it as ballpark.

The security value isn't the decoy. It's the asymmetry: a legitimate user has no reason to open a file called passwords.xlsx in a folder called "old backups", so any touch is signal. Most detections wait for something bad to happen. This one rings the second someone takes the bait, which puts you ahead of the playbook instead of behind it.

where the tokens actually go

I run mine in three places. The decoy spreadsheet on the NAS share. A PDF with an embedded web bug in a directory I'd expect an intruder to rummage through. And a couple of DNS tokens attached to names nothing legitimate would ever resolve. Total build time for all of it, one evening, most of which I spent deciding where, not making.

Where was the actual work. The alert has to land somewhere a person reads. My first month, the alerts went to an inbox I never opened, which means for thirty days I owned a tripwire that no one would have heard trip. I know why it happens: an alert sent to a shared inbox nobody owns feels like work completed. This is the oldest lesson I have from the MSP bench, and I paid it out twice. An alert that goes to an inbox nobody reads is not an alert. It's a diary.

So the honest cost isn't four minutes. It's four minutes plus whatever routing you build so the alert reaches a screen that's on. Mine route into the same channel as my homelab's other real alerts, which is why the AV false positive woke me at all.

where it breaks

The AWS key problem first, because I promised. Researchers noticed that free tokens from canarytokens.org sit on a fixed set of AWS account IDs, and the account ID is decodable from the key itself. TruffleHog, the secret scanner half the internet uses on its own repos, now decodes that account ID and flags the key as a canary without ever using it. Which means the token never fires. Against an intruder running the standard tooling, your scariest decoy is a decoy that announces itself as a decoy. Thinkst could rotate accounts, but the fingerprinting is structural: the scanner reads the account, not the behavior. The tokens that survive are the ones only a human opens. Nobody's scanner rummages through a folder called "taxes 2019". People do.

Second break is time. The docs say AWS key alerts can lag from 2 to 30 minutes behind the actual API call, and meanwhile the measured world is faster: Palo Alto's Unit 42 watched exposed keys get abused within five minutes of landing on GitHub, and Clutch Security later measured sub-40-second exploitation on Docker Hub. A detection with minutes of lag is fine against a human rummaging through your NAS. It's poor odds against a bot scraping public buckets.

Third break is the one that woke me: everything that opens files looks like a person. Antivirus crawls, backup jobs, indexers, sync clients. My alert was a false positive because the machine that tripped it was mine. Budget for that. A token that fires twice a year for benign reasons is normal, and if your routing punishes false alarms by muting itself, the tripwire is dead.

And the limit: this is detection, not prevention. Nothing stops the exfiltration. You find out.

what to do

  1. Make the boring token first. One decoy passwords.xlsx on your NAS share tonight. Four minutes.
  2. Route the alert to something you actually read, then test the path: open the decoy yourself and time how long the email takes.
  3. Put a second token somewhere only a person would go. A folder named for an old tax year works, and costs one click.
  4. Skip the AWS key token, or use it knowing TruffleHog will spot it. The docs won't tell you that. The TruffleHog changelog will.
  5. Add a heartbeat. Files get tidied. Check monthly that your traps still exist, because a deleted trap alerts no one, forever.

The total bill for all of this is one evening and an email address. The 3:12am wakeup cost me nothing but pride, and it bought me the only certainty I have about my own detection: it works, it's fast, and it points at whoever opens the file, including me.

My laptop is still the only thing that ever stole it.