← back to Domain Sniper
readme: v1 vs v2 head-to-head + 4.20h slice 0-1 re-check #2 (0/10)
855ea94765b6461431c871dd539a8f95d0d9636d · 2026-05-12 17:48:53 -0700 · steve
Cumulative spot-check now 0/120 DoH checks across 13 datapoints. Added
a side-by-side table comparing v1 (random CVCVC, lured, 0-result so far)
vs v2 (cohort-shaped, gated, not yet lured). The v1 0/120 result drives
the v2 desirability-hypothesis experiment.
Files touched
Diff
commit 855ea94765b6461431c871dd539a8f95d0d9636d
Author: steve <steve@designerwallcoverings.com>
Date: Tue May 12 17:48:53 2026 -0700
readme: v1 vs v2 head-to-head + 4.20h slice 0-1 re-check #2 (0/10)
Cumulative spot-check now 0/120 DoH checks across 13 datapoints. Added
a side-by-side table comparing v1 (random CVCVC, lured, 0-result so far)
vs v2 (cohort-shaped, gated, not yet lured). The v1 0/120 result drives
the v2 desirability-hypothesis experiment.
---
README.md | 14 ++++++++++++++
1 file changed, 14 insertions(+)
diff --git a/README.md b/README.md
index c65baa4..56d9290 100644
--- a/README.md
+++ b/README.md
@@ -56,12 +56,26 @@ Spot-checks via DoH at increasing intervals to find where the snipe window close
| ~3.24h | A/B/C/D/E (2 ea, slice 4-5) | 0 / 10 — **30 of 50 baits checked, all 0** |
| ~3.49h | A/B/C/D/E (2 ea, slice 0-1 re-check) | 0 / 10 — no late snipes between 3.08h and 3.49h |
| ~3.87h | full 50-bait sweep | **0 / 50** (A 0/10, B 0/10, C 0/10, D 0/10, E 0/10) |
+| ~4.20h | A/B/C/D/E (2 ea, slice 0-1 re-check #2) | 0 / 10 — **120 cumulative DoH checks, 0 snipes** |
| ~6h | _pending_ | — |
| ~24h | full batch | — |
| ~48h | full batch (final) | — |
**Interpretation of the 3.87h flat result** — pure-random CVCVC bait names (`kuwavi`, `tahoz`, `fobahu`) across Verisign/Google-.app/nic.co/GoDaddy/control channels produced ZERO snipes despite deliberate leaks. The original callr.app / callr.co / butlr.app snipes hit pronounceable English-flavored names. Hypothesis: aggregators filter leak streams for desirability (English-likeness, brand-adjacency, prior-search signal) before paying registry fees. Next experimental iteration should use English-pronounceable / brand-adjacent baits to confirm.
+### Honeypot v1 vs v2 — head-to-head
+
+| Dimension | v1 (`honeypot.js`) | v2 (`honeypot-v2.js`) |
+| --- | --- | --- |
+| Bait shape | random CVCVC (`kuwavi`, `tahoz`) | `pronounceable` or `brand-adjacent` cohorts |
+| Generates + lures | one shot (`lure` does both) | two-step (`generate` → `lure`, batch persisted between) |
+| Pre-check availability | at generation time only | at lure time (so freshly-taken names get auto-skipped) |
+| Lure safety gate | command-line only | **`LURE_CONFIRM_LEAK_2026=yes` env required** (YOLO cannot trigger) |
+| Resumable lure | partial — writes after each phase | yes — writes after every item |
+| Result (so far) | **0/50 at 4.2h; 0/120 DoH cumulative** | not yet lured |
+
+The v1 0-result over 120 DoH checks across 13 datapoints is the headline finding driving v2: pure-gibberish baits don't bite, so v2 tests whether English-pronounceable or brand-adjacent shapes do.
+
### Honeypot v2 — desirability-shaped baits (scaffold; lure NOT auto-fired)
`honeypot-v2.js` ships two new bait cohorts to test the desirability hypothesis:
← 4893045 honeypot-v2: wire actual lure body (still env-gated)
·
back to Domain Sniper
·
audit-noise: surface candidate NOISE_PATTERNS by suffix tall 44a0139 →