12 ms·
Tell HN: Startups harvesting GitHub commit emails for marketing purposes
I recently received an starting like this:
> Hi fouric,
> I found your email from one of your GitHub repository while checking for a solution.
> Being in the software engineering industry, I am reaching out for your valuable inputs on our product called "Language Lens" [...]
The email attached to my GitHub account isn't exposed in my profile - the only way this individual would have gotten my email from GitHub would have been too scrape my commit messages.
Needless to say, I didn't request or consent to this.
All y'all might want to make sure that the email attached to your commits is something you're not afraid to receive spam like this at.
- franciscop 4y agoThis has been happening for a while, and I guess the solution is the same as always? Mark them as SPAM on your email provider, and hopefully the rest of us won't even receive it. Now if you are in Europe/related, you could try to go the GDPR way, which TBH I don't know at all what it entails here.
- DiabloD3 4y agoFun fact: Anyone who spams my private, other private, or business email address is going to find their domain name and IP range submitted to the various spam blackhole lists. Let's call this "Github roulette".
- NotHiring2 4y agoCan you help add this spammer/scammer to those lists? https://news.ycombinator.com/item?id=30871398 https://news.ycombinator.com/item?id=30871398
- ttyprintk 4y agoIt might also come from PGP-signed commits, since emails associated with keys are public knowledge. Fairly easy way to filter for good programmers, if you ask me.
- arjvik 4y agoYou're saying the presence of PGP-signed commits is correlated with programmer skill? I have never signed my commits because I see absolutely no reason to (my repositories are all small personal projects that nobody uses), and I haven't gotten around to setting up a proper key management workflow with my password manager. Maybe I need to start signing them!
- 0des 4y agoI sign mine because though I do not wish to be contacted, I want to be able to verify that what I published came from the online identity I am using at that time for that project. I don't share keys, I don't want to be contacted, I also don't want to be impersonated, which is easy in Git
- ttyprintk 4y agoVery good point: the best reason to sign is to prevent impersonation. This design decision in git is widespread among other commercial implementations, like Microsoft TFS.
- encryptluks2 4y agoYou can create a key specifically for GitHub and use your no-reply address on the key. That is what I do.
- ttyprintk 4y agoI guess I’m willing to accept emails out of the blue to my GitHub address, so long as they’re encrypted. Must be annoying to some people, but I’ll never know.
- ttyprintk 4y agoLet’s forget the word “correlated”. Commits might be signed because an organization expects it, and the kinds of projects with that policy might be rather serious (as opposed to frivolous), and serious projects might have rather senior devs. I’m not saying anything about the type I error, just type II error.
- slenk 4y agoThere are tools out there that facilitate this: https://github.com/paulirish/github-email https://github.com/paulirish/github-email
- LunaSea 4y agoDeveloped by a Googler, surprise, surprise.
- 0des 4y agoOh you done did it now
- ls_waiting 4y agoThe about section is: "Get a GitHub user's email. "smiley sunglasses face emoji" Use this responsibly." Is the smiley face for the first sentence? (look how cool and clever I was to find this data) Or the second sentence? (lets all have a laugh that there's actually a responsible usage for this data.)
- renewiltord 4y agoGoogler: Produce some amount of code Anti-Googler: Produce prodigious amounts of comments on the Internet about Google and approximately zero code
- rhizome 4y agoPro-Googler: changes the subject to attack critics
- renewiltord 4y agoHaha, I’m not pro-Google (read my past comments). Just tired of the repetitive nonsense here.
- angrais 4y agoThe real concern should be: Developed as an npm package. I mean, really? It's a shell script wrapped as a package to gain traction. What has the state of the Dev world become, indeed ...
- Stampo00 4y agoGithub provides an email address for every user to obscure their real email address as well as filtering to reject commits that use your real email address. Unfortunately, you must opt in to use this. https://docs.github.com/en/account-and-profile/setting-up-and-managing-your-github-user-account/managing-email-preferences/setting-your-commit-email-address https://docs.github.com/en/account-and-profile/setting-up-an...
- jart 4y agoAnd it makes me so unhappy to see them polluting my commit logs. I won't work with people on open source and run their code on my computer unless I know who they are. Getting recruiter spam is a good problem to have.
- sodality2 4y ago>I won't work with people on open source and run their code on my computer unless I know who they are. I can make a free email very easily. Having a "real" gmail in the logs means nothing. >Getting recruiter spam is a good problem to have. Easy for you to say. Not everyone wants that. Sign up for your own recruiters then...
- deleted 4y ago[deleted]
- 0des 4y agoMaybe some day you reconsider. Some of us just don't want to be bothered but don't mind sharing. Check my other reply for context.
- deleted 4y ago[deleted]
- vvillena 4y agoRelying on the commit log email for checking someone's identity is probably a really bad idea. Public-key signed commits are the better tool for that.
- sshine 4y agoI do get offended when I receive unsolicited email, but only because the ads are always so bad.
- jasonlotito 4y agoIt's interesting because years ago, I remember people saying this was one of the perks of doing open source. You'd have your email address in the code and people would reach out to you for these various things. Times have changed.
- fxtentacle 4y agoYes, the expectation nowadays is that every free open source project comes with professional 24/7 support.
- jasonlotito 4y agoThat’s not a new thing. That’s been going on for decades. I also wasn’t even referring to support, but job offers.
- 0des 4y agoGrey beard here, lemme toss out my 2 cents. I use bogus emails like no-reply@localhost. I quite literally don't give a single care in the world what someone wants to say to me, or why. I'd rather select the times when I accept inbound comms. This is a big reason I do not carry a phone, and use one maybe once a month to organize the next cycle with my coconspirators. I don't dislike people at all, but to contact me after the effort is taken to not be contacted is rude. I wish there were a license that could be used seriously that consists of: This is forkware Don't bother me I'm a nice guy and enjoy sharing. Let's take doritos as an example. I'll share my doritos with you, but I'm not interested in the pleasantries like your analysis of why modern doritos are terrible little crunchy cardboard chunks that mouthfuck your tastebuds into submission. I even don't want to know about the ones I agree with, like how a modern mountain dew most deliciously compliments the retro doritos if you can still find them. I don't mind if you use my code, I don't care if you take my name off it, or put it on, or write it on your arm, I don't care. Go sell it to facebook if that makes your day. If I change my mind I'll put a license on the next version, but I haven't reached that point yet, so the obese and overbearing MIT license it is, until then. But know this: Don't you even think about contacting me for anything. I am not a business, I have a fondness for the idea that the byproduct of my struggles may help a stranger without my knowledge. I prefer to live while littering artifacts of what I make so that maybe someone else stuck in the same spot can get some relief. Why do people think that for me to give away some code I now have to have a support staff of one? You've got the entire game fucked up. Don't @ me.
- deleted 4y ago[deleted]
- stevebmark 4y agoThis isn't news, recruiters have been doing this for years. You can tell what languages and technologies people know from their commits. It's a great idea for recruiting companies. Your Github commit email is public, there's not much to consent to.
- ghoomketu 4y agoThis is quite common unfortunately and has been used by billion dollar companies like Airbnb to get traction(1). Back in the days this was just plain old spamming but nowadays it is called growth hacking Craigslist growth hack —very early on, anyone who listed on Airbnb could cross-list on Craigslist with one click, Airbnb helped by filling out all Craigslists forms with a ‘bot.’ The hack required some technical gnarl to perform, but it was perfect for this early stage. The team also appeared to look for all listings of vacation properties being listed on Craigslist, and emailed the owners to list also on Airbnb. Yes, it’s spam. But yes, it worked. (1) https://www.linkedin.com/pulse/20140918020352-142089-airbnb-s-growth-hacking-story https://www.linkedin.com/pulse/20140918020352-142089-airbnb-...
- 0des 4y agoWhy is every growth hacker I meet IRL an ex-SEO guy who is convinced I want to buy their NFT bs?
- chad_strategic 4y agoWhat's worse an SEO black magic or NFT nonsense?
- neilv 4y ago> The team also appeared to look for all listings of vacation properties being listed on Craigslist, and emailed the owners to list also on Airbnb. Yes, it’s spam. But yes, it worked. That was arguably expressly disallowed on CraigsList since very early on. (Post pages would have a checkbox for whether people could contact you for other purposes, and displayed/scraped posts would indicate how the poster answered. I don't see how "growth hackers" could've missed that.) CL was built on a Californian flavor of warm-fuzzy, and it was a shame to see Californian-style startups then abuse that. (Well, when CL grew mainstream, the anonymity and hookups attracted sketchiness, but was another corruption.)
- scrose 4y agoFunnily enough, Airbnb also expressly stated that you were not allowed to scrape their listings early on and went to (moderate) lengths to make it difficult to do so, even when they were breaking, and/or empowering people, to break the laws in given areas. Everyone wants to keep their data secret, but no one wants to respect others wishes.
- dpedu 4y agoSpammers have been harvesting email addresses written on the web in plain text since the dawn of the web. We've all seen older websites where the author obfuscates their email address like "author [at] domain.com" or "my email is firstname at my domain" or even use an image in place of actual text. I could say that my email is my hacker news username for both the name and domain, on the dot io TLD. A bot couldn't scrape that, but you could figure it out.
- nanidin 4y agoAnecdatapoint: I publish my email address in plaintext on my website and I receive very little spam. People are way overthinking the impact of putting their email addresses out there.
- dustyharddrive 4y agoA lot of these spammers start with a repo’s stargazer list, so I’ve been slowly unstarring everything — if enough people do this GitHub will have to fight at least that kind of scraping. I recommend making a special email alias for git you can rotate, or at least send to a folder you don’t check often. Does anyone here think an open source blocklist for domains associated with this developer-targeted spam would be useful?
- zhfliz 4y agoit's impossible for github to block this. you just need to do a git clone and you get all the email addresses in the commit history of a repository. unless you're talking about your publicly displayed email address (visible to logged-in users), which I believe is not shown by default and can be disabled easily.
- dustyharddrive 4y agoI’m talking about a genre of emails where the targets are those who’ve simply starred a GitHub repo. Even if they get the actual email addresses from a git log or off-platform, they’re still abusing the GitHub API (or screen-scraping) to discover users to spam in the first place. It is possible for GitHub to guard those list pages with captchas and use reports to catch API abusers.
- newaccount74 4y agoI think it's nice that people have their real email in git commits. Gives it a personal touch when you are looking through commit logs. Some clients even display gravatar profile photos... I understand and respect that some people may prefer to stay anonymous. But if you are hiding your email just to fight spam, I don't think it's worth it. I prefer being easily reachable and dealing with a few spam emails that get through the filter.
- worik 4y agoIf you are committing to a github repository, then you are not hard to reach.
- ibash 4y agoYou’d be surprised, a few times I’ve had to resort to using commit emails to reach someone because their contact information wasn’t anywhere else. I’m not spamming, and I’ve never gotten a negative response. It’s just that some people don’t think about setting up a personal site / publishing contact info.
- deleted 4y ago[deleted]
- thenerdhead 4y agoReport them as spam so their email provider loses reputation and they get warned to stop these practices.
- m_ke 4y agoSeems like for me they have moved on from emails to phone calls. I get 2-3 daily calls from people who claim they're calling me because I didn't reply to their email pitch.
- paradite 4y agoYour email is public on your GitHub profile: https://github.com/fouric https://github.com/fouric And it's the same one in one of the commits: https://github.com/fouric/lightning-cd/commit/db619ad363227ea8fc423787c6bc9193bdbe32fa.patch https://github.com/fouric/lightning-cd/commit/db619ad363227e... Anyway, do you have a problem with people reaching out to you via email that you leave in the commit, or specifically automated scraping of email from commits? I think the former is fine and by design.
- moffkalast 4y agoI wonder why emails on commits was ever mandated, instead of just the username. At least they didn't demand a phone number and address, the dimwits.
- remram 4y agoGit was created with a mailing-list workflow in mind, e.g. the way the Linux kernel works. That's why we have git format-patch, git am, git send-email, and that's why there is an email field in commit authorship metadata. You can always put something else there (e.g. GitHub's anonymized addresses) or leave it empty.
- encryptluks2 4y agoGitHub uses it to associate signed commits with your user. Not sure why they can't just verify the GPG key on your account though. I think it is fair to say to them the more personal data you share the better.
- forgotpwd16 4y agoGitHub allows you to use username@users.noreply.github.com as commit email and even has an option to block push commits utilizing your actual email.
- encryptluks2 4y agoYes, but they shouldn't need any email for commits.
- deleted 4y ago[deleted]
- renewiltord 4y agoYep, and I think it’s perfectly reasonable. I’m always happy to receive email on my GitHub for this reason. If enough people mark as spam it’ll go to spam for everyone else so it’s pretty self-correcting.
- leros 4y agoThis has been going on for a while. GitHub has been programmatically scraped by multiple companies that feed into databases that feed into other databases. Lots of companies are scraping data and lots of companies are buying, aggregating, and selling data to each other.
- mherrmann 4y agoAnd now even more startups will do it. However, as others have pointed out, GitHub offers a way to anonymize your email address.
- C4K3 4y agoThis has been going on for a long time. There was a company called geekedin that scraped data off public git repositories (among other things) and who then had their database leaked back in 2016. https://www.troyhunt.com/8-million-github-profiles-were-leaked-from-geekedins-mongodb-heres-how-to-see-yours/ https://www.troyhunt.com/8-million-github-profiles-were-leak...
- forgotmypw17 4y agoI wish GitHub would allow me to specify additional emails for the activity graph, because mine looks pretty much empty because there's no way I'm going to put my email address into my commits.
- _8j50 4y agoDoesn't everyone else fake their git email?
- zeta0134 4y agoSay I don't care about the sanctity of my commit history, and wish to scrub my personal email from all of my public repositories. How would I go about doing this without losing the commits themselves?
- xahrepap 4y agoI’ve found scripts online to help me change the committer on entire repos when I realized I had used the wrong config. Something like the answer here: https://stackoverflow.com/questions/2919878/git-rewrite-previous-commit-usernames-and-emails https://stackoverflow.com/questions/2919878/git-rewrite-prev... Then you have to force push. Note, you will still have the same number of commits in the same order with the same diffs, but they will be new commit ids. You’re “rewriting” your history. Which in the case you outline is perfectly fine. But note, anyone who’s pulled down the branches you’re changing will need to reset rather than pull your changes otherwise git will attempt to MERGE the new history with the old one.
- Arubis 4y agoYou’d have to rewrite the commit history for each of those repos and force push those changes. https://github.com/newren/git-filter-repo https://github.com/newren/git-filter-repo would be a decent starting point.
- nabaraz 4y agoI was getting quite a lot of spams too. So, I ended up creating a brand new email address and rewriting name and email with: git filter-branch -f --env-filter \ "GIT_AUTHOR_NAME='Newname'; GIT_AUTHOR_EMAIL='newemail'; \ GIT_COMMITTER_NAME='committed-name'; GIT_COMMITTER_EMAIL='committed-email';" HEAD
- throwaway892238 4y agoYou need to ask GitHub support to reindex your repo or the old address may still show up on the contributors page
- ffhhj 4y agoIs there an email address that would make a spammer get in trouble? They might call the Github "police" on themselves.
- throwaway892238 4y agoStartups (and scammers) also harvest e-mails from HN and phish them. I posted a unique e-mail address here once and haven't stopped getting all kinds of scams and spam to it.
- nanidin 4y agoYour email address is an address that you published in the commit, and you published it in a public place. You can’t really fault someone for trying to get in contact with you via an address you published in a public place. The message they sent you sounds like a consulting opportunity waiting to happen!
- vorpalhex 4y agoSpam is spam. Making a commit is not authorization to spam me.
- pc86 4y agoPublishing an email address publicly could reasonably be seen as consent to receive email at that address. GitHub, including commits and those messages, is mostly public (unless you make the repo private, which is free). There are many, many other free and paid alternatives to GitHub. I agree with you that spam is spam but at the same time the pearl clutching around "omg commit messages" is kind of silly.
- vorpalhex 4y agoIf an individual contacts me - "Hey, I saw your commit and was wondering if you could explain X..." - that is fine. That is in the realm of normal human communication. No problem. If you add my email to your business marketing list and start sending me your "unsolicited bulk commercial mail" then I'm going to: 1. Never do businsss with your company 2. CC your legal and abuse addresses 3. Contact your mail provider and file an abuse notification The FTC has a wonderful guide on this topic that I encourage you to read.
- remram 4y agoFortunately there is a CAN-SPAM act which means we don't have to rely on what the sender or the community thinks is reasonable. Advertisement of a commercial product or anything on a website operated for commercial purposes requires "express consent to receive the message, either in response to a clear and conspicuous request or at the recipient's own initiative". Pretty far from "putting it in a public space", then.
- SergeAx 4y agoI got an email like this, even better - praising my "contribution" to repo of a single .go file. Letter was from company with Rails and React on their stack. I wrote a sarcastic reply and reported it as spam, but company's founder contacted me on LinkedIn to continue the conversation. I am worried that people like him will eventually destroy all the communication channels thousands of people were building for years.