The MIRE/C³ is a honeypot that sits behind my websites and wastes the time of anyone who probes them. Someone reading the sites never meets it. A scanner hunting for .env files, admin panels and backups falls straight in.

“Clients that ignore the rules the site owner sets are treated as hostile.”

Why “The MIRE”

Picture Glastonbury after a week of rain: the paths are mud, a lone Wellington boot stands where its owner gave up, and still people keep coming. That’s the idea – easy to walk into, slow and costly to get through, and nothing worth taking at the end.

A lone Wellington boot stuck in the mud of a rain-soaked festival field, tents and a stage behind it

How it works

Requests reach my sites through Cloudflare and a Caddy server. Anything a real visitor asks for is served normally. Anything that ignores robots.txt, probes for files that don’t exist, or behaves like a scanner is handed to The MIRE – and it answers with the C³: causing cost and confusion.

The C³Causing cost and confusion

Cost

Responses are slowed down, some by a minute or more, and some arrive wrapped in large archives. Every request costs the scanner time, bandwidth and storage.

Confusion

Everything looks real: configuration files, database dumps, admin logins, cloud credentials. None of it is.

… and since October 2026, some of it bites back

A few of those credentials are live canaries. Use one and it reports back: who used it, from where, and what they tried.

Who falls in

Seconds after a new certificate appears in the public Certificate Transparency logs, the first scanners arrive. After them come credential harvesters, vulnerability scanners, AI crawlers that ignore the rules – and now and then a person at a keyboard. The blog and the field reports tell their stories.

What it doesn’t do

It doesn’t attack back, and it holds no real data: every secret in it is fake, or a canary that only exists to be caught using. Real visitors never see it.

Follow along

Rewritten for release 2026.10. MIRE/C³ – Causing Cost and Confusion.