Chanakya's Rules for Guarding Secrets Map Perfectly Onto Password and OTP Security
Aishwarya Kapoor | Times Life Bureau | Sept 10, 2026, 07:40 IST
Chanakya's Rules for Guarding Secrets Map Perfectly Onto Password and OTP Security
Image credit : Times Life Bureau
Chanakya spent a career studying how information leaks destroy power. His rules from the Arthashastra, about who holds secrets, who you trust, and when silence is the only protection, describe exactly what modern digital security demands. Passwords and OTPs fail the same way state secrets did: not through hacking, but through disclosure.
The secret's existence is the first secret
This maps exactly onto how passwords get compromised. Most people think of a password breach as a technical event, a server gets cracked, a database leaks. The far more common path is social: someone mentions they use the same password across accounts, or confirms which email they use to log in, or says out loud that they have an account on a particular platform. Each of those statements is a piece of the picture. None of them is the password. All of them reduce the attacker's problem.
Chanakya understood that a spy doesn't need the full secret. He needs enough to narrow the search. Your job, by his logic, is to give him nothing to narrow.
Trust narrows as stakes rise
The OTP is the cleanest modern expression of this principle. A one-time password exists for one person, for one transaction, for one window of time. The moment you share it, even with someone calling from what sounds like your bank, even with a family member trying to help, the entire protection collapses. The OTP doesn't care about your relationship with the person you gave it to. It only knows it was used.
Chanakya's distrust of familiarity as a security criterion was considered cold by his contemporaries. It is now standard in digital security design. Systems don't ask whether you trust the person asking. They ask whether the person asking has the credential.
Partial disclosure is full exposure
Phishing works on this principle. A fraudulent call that already knows your name, your bank, and the last four digits of your card isn't guessing. It has the partial information and needs you to supply the rest. The caller sounds credible because he is credible, up to a point. The OTP or the full card number is the point where his partial picture becomes complete.
This is why Chanakya argued that secrets should not be disclosed in stages, even to test loyalty. The test itself transfers information. By the time you know whether someone can be trusted, you have already trusted them with something real.
The window closes for a reason
Chanakya applied the same logic to timing in statecraft. He wrote that decisions communicated too early give opponents time to prepare, and decisions communicated too late lose the advantage of surprise. The operative window, the moment between decision and execution, should be as short as possible. Information that travels inside that window is protected by time itself.
When you screenshot an OTP and send it over WhatsApp, you have extended that window indefinitely. The screenshot sits in a chat, on a server, in a backup. The expiry on the OTP means nothing once the number has been copied out of the system it was designed for.
The extraction doesn't look like theft
Vishing calls, voice phishing, follow this script with mechanical precision. The caller creates urgency (your account is being accessed right now), establishes false authority (I'm calling from the fraud department), and then asks a question that sounds like verification (can you confirm the OTP we just sent?). The target isn't tricked into giving up the OTP. The target is made to feel that giving up the OTP is the responsible thing to do.
Chanakya's spy used the same architecture: make the disclosure feel like cooperation, not surrender. The defence he recommended was structural, not interpersonal. Don't evaluate the person asking. Evaluate the ask itself. A legitimate institution does not need your OTP. A real bank employee cannot be helped by your password. The ask is the tell.
The Arthashastra was written for a world of physical secrets, troop movements, succession plans, treasury locations. What Chanakya kept returning to, across every chapter on espionage and statecraft, was that information almost never fails at the point of storage. It fails at the point of human contact. Passwords and OTPs are technically sound. The breach happens in the moment someone decides the situation is an exception to the rule, and that moment, Chanakya would have recognised immediately.