Live data from Hacker News

Tell HN: YC companies scrape GitHub activity, send spam emails to users

news.ycombinator.com

251–260 of 278 posts

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#251
post #144

Earlier quoted context omitted.

And, Gecko Security.

Flock is an awful company, but what's the trouble with Gecko security? Are you talking about https://www.gecko.security/ or something else?

There are documented public disputes about Gecko Security’s conduct when it comes to claiming credit for vulnerability research. For example, FuzzingLabs publicly accused Gecko Security of copying PoCs and submitting CVE reports for vulnerabilities that FuzzingLabs had originally disclosed, and of misdating their posts to make it appear they found them first. Gecko publicly denied intentional wrongdoing, but later updated their attributions to credit the original researchers [1].

That's one example that's already reported online; I also have another related situation that isn't public yet and involves one of my companies.

[1] https://www.bleepingcomputer.com/news/security/security-firm...

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#252

Even worse, I got contacted through YC Jobs (workatastartup.com) with a message that was basically: "Star, fork, and submit PRs to our open-source repo and we'll review you for a contract." I immediately realize it's engagement farming + free labor. I said "No thanks." Got this reply: "(...) I'm looking forward to reviewing your PRs. Feel free to share me any of your questions. (...)" Apparently, no one read my reply…

Yep I got the same message on workatastartup.com from Aden.

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#253
post #172

Earlier quoted context omitted.

GitHub is wholly owned by Microsoft, which has a 3 trillion market cap

When I left, GH was valued at around $40 billion. Above the $8B they were purchased for. Well below $1T that is claimed

Even if they were valued around $100million they would still have more enough resources to solve this problem. Stop excusing companies that hate hiring people and are so greedy they would rather punt this problem to the commons fucking over an entire community that literally enabled them to exist.

Come on here, even Meta hires people in Kenya to look at CP and snuff films to label this stuff. Meta! They literally profited off of a genocide and they still know how to do this.

Excuse after excuse for these greedy companies.

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#254
post #172

Earlier quoted context omitted.

GitHub is wholly owned by Microsoft, which has a 3 trillion market cap

One would expect people on Hacker News to know that a single business division doesn't have direct access to the funds of other business divisions of the same corporation.

One would expect people on HN should know that companies subsidize failing BU all the time with their profitable BUs.

Sorry but why are you making excuses for these insanely greedy companies that don't want to hire people to solve a basic problem?

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#255

Martin from GitHub here. This type of behaviour is explicitly against the GitHub terms of service, when we catch the accounts doing this we can (and do) take action against those accounts including banning the accounts. It's a game of whack-a-mole for sure, and it's not just start-ups that take part in this sketchy behaviour to be honest. I've been plenty of examples in my time across the board. The fundamental natur…

> when we catch the accounts doing this we can (and do) take action against those accounts including banning the accounts. This isn't my experience. I requested that you looked into a spammer in July 2025, you ignored my reply and the account is still active. ---- Thank you so much for the report. We're sorry to hear you're receiving unwanted emails, but it's always a possibility when your public contact information…

>> it's always a possibility when your public contact information is listed on the web

Sounds correct to me

> Please take further action. My email is public with the expectation that the ToS will be enforced.

What magic wand are you expecting they wave that distinguishes people who need your email address for legitimate from those who need it for illicit purposes? Why wouldn't we apply the same to the entire population and lock up criminals before they've committed crimes?

What you're asking is entirely impossible short of mandatory mind reading

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#256

Martin from GitHub here. This type of behaviour is explicitly against the GitHub terms of service, when we catch the accounts doing this we can (and do) take action against those accounts including banning the accounts. It's a game of whack-a-mole for sure, and it's not just start-ups that take part in this sketchy behaviour to be honest. I've been plenty of examples in my time across the board. The fundamental natur…

I’ve made over five reports for this exact spam scenario, and never once have y’all acted on them. I have a hard time believing you ban spam accounts that clearly violate your ToS. I even wrote about a specific example of a YC company spamming me from my GitHub email at https://benword.com/dont-tolerate-unsolicited-spam

How did you connect joe@legitbusiness.com, where spam usually originates from for me (hacked email accounts), to a specific github user account that was used to scrape the data, which microsoft can choose to ban? And that's assuming they believe you're being truthful and not simply angry with the user whom you're reporting

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#257
post #255

Earlier quoted context omitted.

> when we catch the accounts doing this we can (and do) take action against those accounts including banning the accounts. This isn't my experience. I requested that you looked into a spammer in July 2025, you ignored my reply and the account is still active. ---- Thank you so much for the report. We're sorry to hear you're receiving unwanted emails, but it's always a possibility when your public contact information…

>> it's always a possibility when your public contact information is listed on the web Sounds correct to me > Please take further action. My email is public with the expectation that the ToS will be enforced. What magic wand are you expecting they wave that distinguishes people who need your email address for legitimate from those who need it for illicit purposes? Why wouldn't we apply the same to the entire populati…

I provided a spam email chain from a user with a linked GitHub profile, stating that they obtained my email from my GitHub profile.

GP [martinwoodward] states:

> This type of behaviour is explicitly against the GitHub terms of service, when we catch the accounts doing this we can (and do) take action against those accounts including banning the accounts.

But action was not taken, there was no reply to my email to GitHub support.

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#259
post #256

Earlier quoted context omitted.

I’ve made over five reports for this exact spam scenario, and never once have y’all acted on them. I have a hard time believing you ban spam accounts that clearly violate your ToS. I even wrote about a specific example of a YC company spamming me from my GitHub email at https://benword.com/dont-tolerate-unsolicited-spam

How did you connect joe@legitbusiness.com, where spam usually originates from for me (hacked email accounts), to a specific github user account that was used to scrape the data, which microsoft can choose to ban? And that's assuming they believe you're being truthful and not simply angry with the user whom you're reporting

As others have noted, the emails frequently include the sender's actual GitHub username or organization in the body or signature.

Attribution isn't speculative. The DKIM/SPF headers show the messages are authenticated and sent through the company's own mail servers, signed by their domain. These are not spoofed "joe@legitbusiness.com" messages. I include the original headers in every abuse report.

In several cases I've engaged directly. One founder replied to my "stop spamming" email and later sent me a LinkedIn request. When the name in the signature, the GitHub profile, the authenticated sending domain, and the LinkedIn account all align, the hacked-account explanation no longer fits the facts.

Re: Tell HN: YC companies scrape GitHub activity, send spam emails to users

#260

Earlier quoted context omitted.

Don't spammers have an automatic filter to cleanup that?

You'd have thought so, but no, in my experience this works very well. People doing this kind of spamming don't seem to be particularly bright, nor do they seem to spend any time/effort to clean up their scraped database.

I expected the removal of the + in gmail to be at the level of script kiddies. Are spammers even at a lower level?
Post reply on HN