Live data from Hacker News

Startup hacked by competitor, gets revenge

fbamastery.com

1–10 of 17 posts

Re: Startup hacked by competitor, gets revenge

#6
post #5

As I understand, the user has the legitimate right to save the data she gets by querying. Just because she automated this process they call her a hacker?

"Hacking" isn't quite the right word, but I'm not sure what the right word for "systematic scraping of a competitor's entire database" is.

Re: Startup hacked by competitor, gets revenge

#7
post #5

As I understand, the user has the legitimate right to save the data she gets by querying. Just because she automated this process they call her a hacker?

"Hacking" isn't quite the right word, but I'm not sure what the right word for "systematic scraping of a competitor's entire database" is.

Crawling.

Re: Startup hacked by competitor, gets revenge

#8
Could this come back to bite Zen Arbitrage in the ass if they get sued for damages caused by providing false data with the intention of sabotaging another company?

I understand why they don't like Textbook Money scraping their database and using it to fuel a competing product (and it is a competing product despite OP's constant insistence that it isn't) but it's not necessarily illegal and I think you could argue in court that the "correct" response would have been to deny service instead of to deliberately mislead.

Re: Startup hacked by competitor, gets revenge

#10
We've found coordinated attempts to scrape our pricing data. As the OP also found, they might have gotten away with it except for being greedy, setting up so many requesters that it affected our site performance and we went to investigate. The trail didn't go directly to a competitor, but to a service that actually specializes in providing price comparison data. Some additional circumstantial evidence led us to believe that they were working on behalf of one of our competitors specifically.

We also had the idea to feed them fake pricing, but in the end our CTO thought it better to just play it straight, so we built a way to identify certain fingerprints of their requests (I don't want to say what, publicly), and blacklist any offending IP addresses for several hours.

Post reply on HN