Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Built a "defensive deception" layer that feeds believable fake data to unauthorized readers — looking for fresh eyes to try to break it (beta) ?

0
Medium
Published: 07/27/2026 (07/27/2026, 02:13:47 UTC)
Source: Reddit BlueTeam

Description

Built a "defensive deception" layer that feeds believable fake data to unauthorized readers — looking for fresh eyes to try to break it (beta) ? Source: https://break-izanami.com

Reddit Discussion

r/AskNetsec·posted by u/Super_Ticket6533
00

I've been working on a defensive-deception layer for sensitive records (think honeypot + decoy + tarpit, but at the data layer). The idea: an authorized reader gets the real record; an unauthorized reader doesn't get an error or a block — they get a believable fake record and a maze of plausible-but-useless data, so they can't easily tell whether they succeeded.

It's been through several internal red-team passes already (trust boundary, decrypt-only-after-authorization, atomic anti-replay, closing an encryption oracle, generic errors, a fuzzing campaign). I'm now looking for fresh, external eyes — the internal reviewers stop finding obvious things, so I want people who think differently.

The challenge: there's a live API. The target is a single synthetic occupational-health record that contains a flag (IZANAMI{...}). Without a valid token you should only ever get decoys. The goal is to make it hand you the real record — or to show a logic flaw that breaks the "unauthorized ⇒ never the real data" guarantee.

Start here: https://break-izanami.comGET /challenge returns the rules and scope in JSON.

Rules / scope (short version):

  • The data is 100% synthetic. No real people, no real PII.
  • In scope: the documented endpoints (/challenge, /challenge/package, /v1/decrypt, /v1/health).
  • Please report, don't weaponize: a proof-of-concept is enough, no need to go further.
  • No DoS / brute-force / traffic floods — it's a small box, and that's out of scope.
  • Win = submit the flag string to [email protected]. First blood gets credited.

Honest disclaimers: the domain is brand-new (yes, I know how that looks), we're a small team staying low-key during the beta, and this is a beta — I may adjust or pause things and I'm genuinely after feedback, not claiming it's unbreakable. If it breaks in five minutes, I want to know why.

Happy to answer questions about the threat model in the comments.

Links cited in this discussion

Technical Details

Source Type
reddit
Subreddit
blueteamsec+AskNetsec+Information_Security
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a66c44f9c2644c7f824f6db

Added to database: 07/27/2026, 02:37:03 UTC

Last updated: 07/27/2026, 03:32:39 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses