Live data from Hacker News

Tell HN: YC companies scrape GitHub activity, send spam emails to users

news.ycombinator.com

191–200 of 278 posts

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#191
That's nothing. Former/current YC founders are also abusing BookFace.

I did YC and now work at a frontier lab.

I've received multiple spam-style emails from (mostly young) current founders tagging me and all other YC-alum at my place-of-work with the profiles of their friends for internship roles, referrals, etc.. Same girl has done it for like 5 different people.

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#192

Earlier quoted context omitted.

Scrape once, spam forever. I think it's pretty clear you need to use an anonymization scheme in the way commits are handled so that it links back to your github account and the email addresses are kept private. Privacy centric companies like Apple do this for users offering hashed emails, on a per login basis. I'm sure this would not work in a world of scraping, but having that kind of ability to figure out bad actor…

They already do[0] 62114487+david-allison@users.noreply.github.com this includes a unique ID which survives account renames, and the name of the GitHub account at the time. [0] https://docs.github.com/en/account-and-profile/reference/ema...

How does the spammer get through this then?

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#193

Martin from GitHub here. This type of behaviour is explicitly against the GitHub terms of service, when we catch the accounts doing this we can (and do) take action against those accounts including banning the accounts. It's a game of whack-a-mole for sure, and it's not just start-ups that take part in this sketchy behaviour to be honest. I've been plenty of examples in my time across the board. The fundamental natur…

What section of the ToS prohibits this? In other words, what is the thing that is being done that is against the ToS? Looking up the creator of a repo, or the contributors of the repo? I did a quick scan of the ToS and all I could find was D8 that states that autmated access (scraping) used for "AI" applies a reciprocal license that prevents the scraper from restricting GitHub's access to the data (the whole model? t…

It seems like a safe assumption that the big commercial models will have negotiated their own private GitHub terms of service, especially considering their many-digit annual contracts with Azure.

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#194

Martin from GitHub here. This type of behaviour is explicitly against the GitHub terms of service, when we catch the accounts doing this we can (and do) take action against those accounts including banning the accounts. It's a game of whack-a-mole for sure, and it's not just start-ups that take part in this sketchy behaviour to be honest. I've been plenty of examples in my time across the board. The fundamental natur…

Hey, Martin - https://github.com/lucidrains Mind fixing lucidrains account? Something happened without notice or recourse. He's one of, if not the most well known open source AI researchers on the planet, with implementations and explanations of papers and ideas that are wonderful. If you could bring some sanity to that situation and take it out of whatever kafkaesque account purgatory it fell into, you'd be doing th…

Is this mirrored on gitlab or somewhere else? Nobody should trust Github to store all their data

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#195
post #144

YC is a proud investor in Flock, what YC Ethics thing are you talking about?

And, Gecko Security.

Flock is an awful company, but what's the trouble with Gecko security? Are you talking about https://www.gecko.security/ or something else?

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#197

Just got a SPAM email from a Github scraper while reading this thread: From: james@techglobal.website Quick note – your GitHub profile Hi X, I came across your profile on GitHub. Given you're based in the US, I thought it might be relevant to reach out. Profile: I run a technical team (full-stack, cloud, DevOps) that delivers for clients. We're looking to work with an engineer based in the US on client-facing coordin…

I'm curious, what leads you to North Korean from that email? Is it that there's an anonymous team, which has a US "front"?

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#198

Martin from GitHub here. This type of behaviour is explicitly against the GitHub terms of service, when we catch the accounts doing this we can (and do) take action against those accounts including banning the accounts. It's a game of whack-a-mole for sure, and it's not just start-ups that take part in this sketchy behaviour to be honest. I've been plenty of examples in my time across the board. The fundamental natur…

I have reported several spam emails to Github and from what I can tell none has been acted upon.

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#199
post #73

Earlier quoted context omitted.

Why would it be illegal?

i am not sure of anywhere it is illegal . but areas i am familiar with can consider a negative reference to be defamation, thus anyone providing a negative reference should only do so if they are able to defend it (i.e. prove their statement is substantially true, or prove that the statement was honestly believed to be true and published with no malice or reckless disregard). seems risky, at least, to build a whole b…

To be defamation in the US they'd generally need to be false statements of fact.

"John is a bad person, and you shouldn't hire him" wouldn't be defamation.

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#200

I've spent a lot of my career marketing to developers, and spamming their GitHub account might be top 1 or 2 worst marketing tactics you can use. Cold emailing rarely works by itself. Cold emailing developers via emails you pulled from their GitHub accounts? At that point, you're actively harming your brand, and may as well just send them spam diet pill ads.

Wait why? That seems like the high effort and high specificity thing that I'd love to get. You searched for people who do what you need to have done, found me, looked at what I've worked on and determined I'd be a good fit and you reached out? That's the number one way to get me to want to work for you.

"Work for you"? They ain't hiring my friend, they are spamming their product to your inbox, not sending a career opportunity
Post reply on HN