Hacking / Opsec

Is tforum a honey pot?

Started by 08ujdi · Jun 30, 2026

#1447
↳ Replying to @Selenium
the point i was making is that a LE honeypot would not STAY down when extortionists hit it. a real honeypot has federal resources. cloudflare. ddos mitigation. 24/7 ops team. if LE ran tforum and some russian booter knocked it offline for 3 days they would fix it in 20 minutes. when tforum goes down and stays down for days while hugbunter posts about it from his personal account, that is not how a government operation behaves.

the ddos deanonymization thing is real though. you can knock a hidden service offline by flooding its intro points. then when it comes back up you watch for new circuits being built and try to correlate. that has been used against markets. against tforum though? nobody has published a successful correlation attack on tforum. if it happened we would see indictments referencing tforum user data. we do not.

and the multi agency thing you mentioned is interesting. if tforum was a honeypot... which agency would run it. fbi. europol. nca. afp. they do not share. they would fight over who gets the arrests. the fact that tforum has survived 8 years with no agency claiming credit is its own argument. someone would have leaked it by now for career points.
#1448
↳ Replying to @08ujdi
Did you edit your post or something? Shows it’s pending now, if so you need to tag one of the mods to reapprove it.

And the Feds having his PGP doesn’t put them any closer to de-anonymizing him or knowing his real identity.
#1450
↳ Replying to @08ujdi
You just tag one of them from the side panel (to the right) like so /u/newbieforever2018 and ask them to reapprove your post.
#1451
↳ Replying to @08ujdi
LE honeypot would not STAY down when extortionists hit it. a real honeypot has federal resources. cloudflare. ddos mitigation. 24/7 ops team. if LE ran tforum and some russian booter knocked it offline for 3 days they would fix it in 20 minutes


LOL the same government that runs the DMV and made the Obamacare website? They have limited budgets and resources for criminal investigations too. Also, there is no Ckoudflare for Tor hidden services. DrugHub has the best DDOS prevention because they can afford to.

if it happened we would see indictments referencing tforum user data. we do not.


tforum stores very little user info that isn't public. Not even last login time.

There was a recent vendor bust because of tforum. A vendor uploaded a photo without scrubbing the EXIF data, and the geotag led right to their pill pressing operation.

which agency would run it. fbi. europol. nca. afp. they do not share. they would fight over who gets the arrests.


Huh? Have you never seen a seizure page? They almost always include dozens of LE agency logos from all over the world.

As for tforum being a honepypot... it's not really a target. Taking over tforum would have limited upside because it's a public message board. Sure, they could spy on PMs - but only the mundane ones. Anything worth reading is encrypted with PGP.
#1454
↳ Replying to @08ujdi
It's not a honeypot and since the site takes ad money for drugs and shit the operator is committing crimes. I doubt that anyone really wants to take this site down though, it's as valuable to law enforcement as it is to users.
#1455
↳ Replying to @08ujdi
the point about the pgp keys not changing still stands though


Good point on underrated topic

Members-only continuation

This discussion contains more posts.

Create an account or sign in to continue reading the full conversation. 7 additional posts await inside.

Create an accountSign in