View Single Post
  #17  
Old 09-10-2026, 23:13
chants's Avatar
chants chants is online now
VIP
 
Join Date: Jul 2016
Posts: 884
Rept. Given: 48
Rept. Rcvd 53 Times in 32 Posts
Thanks Given: 766
Thanks Rcvd at 1,182 Times in 550 Posts
chants Reputation: 53
Thumbs down

Quote:
Originally Posted by th3tuga
From that point onward, my efforts shifted to locating the Claude and OpenAI accounts that IT‑security staff share(from companies they are employed like KrebsOnSecurity etc)... We simply use the frontier‑AI accounts that the military and other government agencies provide, which lower‑level personnel hand out for a modest fee... accessed through their own proxy servers...
Look at how fast those goalposts are moving!
First it was "totally legit leaked US Military accounts on Telegram." Now that they got called out on how impossible it is to scan the US Military network with Shodan, the story completely flips. Now it's "Oh, we aren't hacking them, lower-level personnel are just renting out their access codes for a modest fee through a proxy server!"
This is hilarious. Let's break down the new set of lies they are cooking up to keep the scam alive:
1. The "Corrupt Low-Level Personnel" Lie
Do you honestly believe that an analyst at a top federal agency or a tier-1 cybersecurity firm like KrebsOnSecurity is risking a felony conviction, losing their security clearance, and getting blacklisted from the entire tech industry just to make a "modest fee" splitting an OpenAI API key on Telegram?
Furthermore, high-level corporate and government API access doesn't just work with a simple username and password you can pass to a buddy. It is locked behind strict enterprise Single Sign-On (SSO), hardware security keys (YubiKeys), and strict device posture checks. A "low-level" employee couldn't easily pipe this out to a random internet proxy even if they wanted to.
2. The Reverse-Proxy Smoke Screen
"All requests to the AI providers appear to come from the reverse‑proxy IP addresses, not ours... our identities remain protected."
This is standard scam-operator jargon meant to sound deeply technical to newbies. If you route your traffic through a proxy server provided by the seller, you are the one being spied on. The person running that reverse proxy can see every single line of code you paste into that model, your reverse-engineering targets, and your own actual IP address if the proxy isn't configured right. You aren't "protected"—you are handing your data directly to a sketchy middleman.
3. The Classic "Bait and Switch" Technique
Notice how th3tuga tries to gain unearned credibility by name-dropping respected community figures (like mrexodia) and talking about local open-source setups like Qwen and MCP (Model Context Protocol).
  • They start with actual, legitimate tech topics (running open-source models on rented GPUs, local LLMs).
  • Then they smoothly pivot back to justifying their sketchy, paid "leaked frontier accounts" service.
This is a classic social engineering trick: wrap a blatant lie inside 80% genuine tech talk so that beginners can't tell where the facts end and the scam begins.
The Bottom Line:
They are trying desperately to sanitize their scam because their original "US Military hack" story fell apart under scrutiny. It's the same old tune: they want you to trust a "proxy" controlled by god-knows-who, to use "leaked" enterprise access that will likely get banned in 48 hours anyway.
If you want to use LLMs for reverse engineering reliably, stick to what deepzero ironically suggested at the bottom: run capable open-source models (like Qwen or Llama 3) locally or on a clean, legitimate cloud GPU instance (like Vast.ai or RunPod). Don't pay middlemen for "magical military proxies."
__________________

Last edited by chants; 09-10-2026 at 23:18.
Reply With Quote