DevOpsDays Barcelona 2026 · Ignite talk
One Fake Password Is Worth More Than 10,000 Alerts
A five-minute Ignite about honeypots, canary credentials and alert fatigue: why one tripped fake secret tells you more than a wall of low-confidence alerts, and why that makes it the signal you can safely automate on.
- When
- Where
- BAU, c/ Pujades 118, Barcelona
- Track
- Pujades Track (English), Ignite Talks block
- Speaker
- Ilia Dubovskii, Beamreach
The talk in one paragraph
Some alerts are already high-confidence, like a GuardDuty finding or a Falco rule for a shell spawned in a container, and you should automate on those. Most alerts aren't. If one alert in a thousand is a real attack, wiring an automatic reaction to it means 999 self-inflicted outages, so a human gates it, and the human waits until Monday. A canary credential flips that ratio: nobody legitimate has a reason to use it, so when it's used, you know. The principle is automate on certainty, and canaries are the cheapest way I know to create certainty.
The talk walks through one weekend, twice: once with alerts only, once with a canary.
Abstract
Modern security teams are drowning in alerts while attackers increasingly automate reconnaissance and exploitation. This Ignite explores why a well-placed honeypot asset can provide a higher-confidence signal than thousands of traditional security alerts, especially against AI-powered attacks.
Rather than asking what an attacker could do, deception technologies focus on detecting what an attacker actually did.
Key takeaways
- Why alert volume is becoming a liability.
- How deception technologies work in modern environments.
- Why AI-assisted attacks increase the value of honeypots.
- The difference between exposure-based and intent-based detection.
- Practical ideas for implementing low-cost deception techniques.
The argument
Symptom versus intent
An alert measures an effect, like traffic up or CPU high, against a baseline. That baseline is exactly where attackers hide, and it's also where your own deploys and batch jobs live. A canary trip measures a decision: someone found a credential and chose to use it. There's no baseline to argue about, and it points at one exact task.
AI on maybes versus AI on certainty
Letting AI act on maybes is dangerous. Letting it act on certainty, with an action you can undo, like stopping one container task and letting the orchestrator replace it from a clean image, is just good engineering.
Keep both
Canaries don't replace your alerts and they aren't the only high-confidence signal. Alerts give you coverage. A canary only covers the places you plant it, but when it fires there's very little doubt, so it's a good first place to automate a response.
Cheap to start
Canary credentials need no agents and work on Fargate. You can set one up in an afternoon: put a fake credential where an attacker would look (environment variables, secrets, CI), point it at a decoy that only logs, and decide in advance what a trip means: stop the task, tell a human.
Who it's for
Platform, DevOps and security engineers who are on call, who have tuned alerts until they stopped trusting them, and who want a detection signal they'd be comfortable letting automation act on in the middle of the night. No security background needed.
Materials
The QR code on the last slide leads to beamreach.ai/honeypot-security.html, where the replay will live. Everything below will also be linked from this page.
Slides
Published after the talk on 14 November 2026.
Talk recording
Published after the talk on 14 November 2026.
Replay of the canary weekend
Published after the talk on 14 November 2026, on the honeypot security page.
The Terraform
Published after the talk on 14 November 2026.
Read more
- AWS Canary Credentials: How to Set Up an IAM Honeytoken — a step-by-step guide to the technique in this talk.
- Cloud honeypot security and canary assets — how Compass suggests and plants canaries through Terraform PRs.
- Guides for cloud teams
- Compass — autonomous DevOps for cloud teams.
- Autonomous DevOps — my 30-minute talk at KCD Porto x DevOpsDays Portugal, 19–20 Nov 2026.
- All talks
Beamreach