But I didn't try anything fancy. In retrospective, I probably should have turned on my VPN and see what happened.
As a 10 year redditor, that really frustrates me, since I can't go back and see my early posts any more.
https://www.reddit.com/r/announcements/comments/8m2yr4/were_...
I'd much rather they let you get your own history out and then make it impossible to get said history for anyone else (unless that person chooses to allow it).
To the first part: I would characterize certain scraping, usually behind an authentication wall, as malicious--though admittedly that's not the right word. An example would be scraping Facebook profiles to build a marketing list.
So, by 'non malicious,' i mostly mean 'publicly available data'
That way you can easily control the fake success rate, and you make sure that if the attacker realises they are being tricked, they can't just retry successful logins to double check, since they get the same result every time.
OP mentioned the attack is easily identified so legitimate traffic gets served correctly bad traffic gets "logged in" to the poisoned honeypot. 301 after login perhaps
It will hopefully waste their time and discourage them from trying to find other ways.