Live data from Hacker News

Tell HN: YC companies scrape GitHub activity, send spam emails to users

news.ycombinator.com

101–110 of 278 posts

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#101

Earlier quoted context omitted.

i am not sure of anywhere it is illegal . but areas i am familiar with can consider a negative reference to be defamation, thus anyone providing a negative reference should only do so if they are able to defend it (i.e. prove their statement is substantially true, or prove that the statement was honestly believed to be true and published with no malice or reckless disregard). seems risky, at least, to build a whole b…

There are many definitions of illegal (criminal, civil, regulatory, the much much looser “license to operate” as used in chemical industry, etc). A blacklist seems dubious. I’d advise the founders to get counsel on their obligations under the FCRA, which they may be construed to be regulated by. That said, I believe "Bad News" is an AI hallucination. The most similar company I can find historical news is "Peeple"[0],…

>There are many definitions of illegal (criminal, civil, regulatory, the much much looser “license to operate” as used in chemical industry, etc).

yes, but i am not sure why this matters here. i am not aware of negative references, in general, being illegal under any of those definitions of illegal.

no one would say regular speech is illegal just because it can be subject to a defamation lawsuit. same logic.

but i agree, if it is a real business, it seems exceptionally risky.

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#102
post #71
post #70

Earlier quoted context omitted.

I can't find any website for it. Are you sure it's not just some posting category on Bookface, YC's internal social network?

[flagged]

Why are you obfuscating so much and telling people to use ChatGPT? How hard would it be to paste what they renamed to and/or the founders' names?

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#104
post #93

I also had unsolicited spam from Vincent Jiang of Aden, another YC company. Hi Daniel, I just came across your profile on social media and wondered if you'd be interested in joining our Discord community for AI agent development. Currently, we see that agents break, loop, get lost, hallucinate, and cost a fortune, and therefore built a space where developers can share challenges and insights.

I had a similar one from that guy asking me to make open source PRs to some repo of theirs for, err, $25-50/hour. I replied explaining that senior software engineers in the UK aren’t quite as desperately poor as that, and got a canned response saying that they were looking forward to reviewing my PRs :D

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#105

Doesn't YC have some code of conduct or legal/ethical guidelines? I would assume a legal and compliance department would have some major headache if documented cases of misconduct jeopardize later due diligence. I would not fund or aquire a company on the radar of national regulatory bodies for something as stupid as this.

When you are a team of 3 people eating ramen there is no legal or ethical compliance department.

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#106

Maybe a dumb question, but isn't this trivially solved with this .gitconfig? [user] name = lordgrenville email = +lordgrenville@users.noreply.github.com

Perhaps, but it doesn't change the fact that this is bad behavior for the company sending the email. Since YCombinator funded this company it makes sense that YC would want to know about how they are conducting business.

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#107
post #86

Earlier quoted context omitted.

It's definitely illegal in the UK.

i dont believe that it is illegal to provide a negative reference in the UK, as long as it is honest, factual, and provided in good faith. from gov.uk: >" If you think you’ve been given an unfair or misleading reference, you may be able to claim damages in court. Your previous employer must be able to back up the reference, such as by supplying examples of warning letters. You must be able to show that: - it’s mislea…

Providing a negative reference is totally different than gathering negative references and selling them. The former could be legal while the latter could be illegal.

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#108

Martin from GitHub here. This type of behaviour is explicitly against the GitHub terms of service, when we catch the accounts doing this we can (and do) take action against those accounts including banning the accounts. It's a game of whack-a-mole for sure, and it's not just start-ups that take part in this sketchy behaviour to be honest. I've been plenty of examples in my time across the board. The fundamental natur…

I’ve made over five reports for this exact spam scenario, and never once have y’all acted on them. I have a hard time believing you ban spam accounts that clearly violate your ToS.

I even wrote about a specific example of a YC company spamming me from my GitHub email at https://benword.com/dont-tolerate-unsolicited-spam

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#109
post #70
post #54

Earlier quoted context omitted.

[flagged]

I can't find any website for it. Are you sure it's not just some posting category on Bookface, YC's internal social network?

Same. While it doesn't help that their name is about as generic as it gets, I searched across Kagi, Google, etc. and couldn't find any such YC company.

That being said, it wouldn't entirely surprise me if somebody's tried to start the tech equivalent of the casino "Black Book".

https://en.wikipedia.org/wiki/Black_Book_(gambling)

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#110

Earlier quoted context omitted.

There are many definitions of illegal (criminal, civil, regulatory, the much much looser “license to operate” as used in chemical industry, etc). A blacklist seems dubious. I’d advise the founders to get counsel on their obligations under the FCRA, which they may be construed to be regulated by. That said, I believe "Bad News" is an AI hallucination. The most similar company I can find historical news is "Peeple"[0],…

> There are many definitions of illegal (criminal, civil, regulatory, the much much looser “license to operate” as used in chemical industry, etc). yes, but i am not sure why this matters here. i am not aware of negative references, in general, being illegal under any of those definitions of illegal. no one would say regular speech is illegal just because it can be subject to a defamation lawsuit. same logic. but i a…

https://www.law.cornell.edu/uscode/text/15/1681d

It's more than just "subject to a defamation lawsuit" (including class action lawsuits). Although for me, even if it were "just that", I'd still call it "potentially illegal". Rather, they'd potentially face FTC penalties and CFPB enforcement actions under 15 U.S.C. section 1681d(a), (b).

This law would likely classify such a company as falling under laws pertaining to "investigative consumer reports" under FCRA. This is any report on someone's "character, general reputation, personal characteristics, and mode of living" used for the purposes of employment, loans, housing, etc.

> A consumer reporting agency shall not prepare or furnish an investigative consumer report on a consumer that contains information that is adverse to the interest of the consumer and that is obtained through a personal interview with a neighbor, friend, or associate of the consumer or with another person with whom the consumer is acquainted or who has knowledge of such item of information, unless—

> (A) the agency has followed reasonable procedures to obtain confirmation of the information, from an additional source that has independent and direct knowledge of the information; or

> (B) the person interviewed is the best possible source of the information.

They'd find themselves subject to legal penalties under:

FCRA Willful Noncompliance (15 U.S. Code § 1681n) (if they did not disclose their existence/use/content of reports to employment candidates)

FCRA Negligent Noncompliance (15 U.S. Code § 1681o) (if they made somewhat reasonable but insufficient efforts to comply with the FCRA)

or

Administrative Enforcement (15 U.S. Code § 1681s)

and be subject to fines up to $4,700 per violation plus actual damages, plus punitive damages, plus legal fees. State Attorneys General can also bring FCRA lawsuits on behalf of their constituents, not just the federal government. FTC / CFPB can name the founders individually in the lawsuits, not just their corporate entity, and ban[1][2] them from operating any similar businesses in the future.

That all said, to some extent, YCombinator partners are on the record[3] supporting the idea of their startups sometimes doing illegal things. Generally they'll frame this as challenging outdated regulations, but they acknowledge that the founders whose strategies they fully support sometimes come into office hours and discuss how they're worried that the strategy puts them at risk of going to jail.

0: https://www.law.cornell.edu/uscode/text/15/1681d

1: FTC v MyLife.com, Inc., and Jeffrey Tinsley (CEO): https://www.ftc.gov/news-events/news/press-releases/2021/12/...

2: https://www.ftc.gov/legal-library/browse/cases-proceedings/b...

3: https://www.youtube.com/watch?v=Hm-ZIiwiN1o&t=8m46s

Post reply on HN