Live data from Hacker News

Tell HN: YC companies scrape GitHub activity, send spam emails to users

news.ycombinator.com

1–10 of 278 posts

Tell HN: YC companies scrape GitHub activity, send spam emails to users

#1
Hi HN,

I recently noticed that an YC company (Run ANywhere, W26) sent me the following email:

From: Aditya

Subject: Mikołaj, think you'd like this

[snip]

Hi Mikołaj,

I found your GitHub and thought you might like what we're building.

[snip]

I have also received a deluge of similar emails from another AI company, Voice.AI (doesn't seem to be YC affiliated). These emails indicate that those companies scrape people's Github activity, and if they notice users contributing to repos in their field of business, send marketing emails to those users without receiving their consent. My guess is that they use commit metadata for this purpose. This includes recipients under the GDPR (AKA me).

I've sent complaints to both organizations, no response so far.

I have just contacted both Github and YC Ethics on this issue, I'll update here if I get a response.

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#5
I was also spammed (twice) by voice.ai.

You mention GDPR, which also "applies" to me, though I wonder if what they're doing is actually illegal. I mean, after all, I'm putting my email on GitHub precisely to give people a way to contact me.

Of course, I do that naïvely, assuming good faith, not expecting _companies_ to use it to spam me. So definitely what they're doing is, at the very least, in poor taste.

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#6
post #2

This is atleast fine as it's just spam, I got pulled into an actual scam and it never made it to the frontpage. https://news.ycombinator.com/item?id=45357205

Looks like GH nuked it, though.

Hope they didn’t get too many folks.

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#7
> These emails indicate that those companies scrape people's Github activity, and if they notice users contributing to repos in their field of business, send marketing emails to those users without receiving their consent. My guess is that they use commit metadata for this purpose.

There are likely marketing email datasets floating around the internet that contain email addresses scraped from commit metadata.

I use a catchall with a specific Git client (not GitHub) email address, and found spam and phishing emails being sent there quite a few times.

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#8
I remember this being discussed a while ago

https://news.ycombinator.com/item?id=9332418 (11 years ago)

https://news.ycombinator.com/item?id=20660624 (7 years ago)

https://news.ycombinator.com/item?id=27855152 (5 years ago)

https://news.ycombinator.com/item?id=30900237 (4 years ago)

Seems it’s a reoccurring issue

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#9
I’m not especially bothered by this [yet -AI is likely to make this worse]. It’s a fairly insignificant component of my spam catcher. At least, it’s a bit focused.

Every day, I get deluged with hundreds of spam and scam emails, often because some knucklehead entered my email in a form (either accidentally, or as a throwaway red herring).

Post reply on HN