8M GitHub profiles were leaked from GeekedIn's MongoDB
troyhunt.com
troyhunt.com
My initial reaction was that I had absolutely no idea that this site even existed. While this is publicly facing data, it might explain some situations that I experience, such as people sending me generic recruitment emails to my old email address (the one leaked here, that hasn't been on my GitHub page for months now) filled with the name of the GitHub repository with the most stars and telling me how they liked my code in that repository (even though the most popular one on my profile is not software-related at all).
Mini ask HN to those whose email address is public on GitHub: How frequently do you get these kinds of recruitment emails?
But for those who care, the best solution would be if GitHub didn't show emails in their webui or APIs -- you have to clone the repo to get the information. That makes it prohibitively expensive to scrape every repo on GitHub (so you'd have to narrow down what repos you're interested in).
Even though a simple two character change to pandoc is my only Haskell experience...
To hijack your comment for my own follow-up question. I'm in the EU (Netherlands). Many of these mails are clearly mass E-Mails with just my name as a template sent by some US-based company, they'll include an unsubscribe link for future E-Mails, but aren't unsolicited mass-marketing E-Mails like these illegal in the EU, and if so would it be worthwhile reporting them, and who to?
What made the most positive difference was deleting my LinkedIn account, I was getting way more spam there (via its own messaging system, not via email) that was very unpleasant.
I'm actively contributing to popular projects, have more than a dozen of followers, and my email is public but I have never received any recruitment emails. It's a pity.
I wish they were useful, but most of them are automated and when you follow up, you usually get greeted by an email stating that they're looking for someone with completely different background than you have.
You might be lucky not to receive them. I feel like, if I were looking for a job, I would have more luck with "Who wants to be hired" threads posted here on a monthly basis.
I didn't use it, and probably won't any time soon, but once I start looking for a job, I feel like my chances are much higher with that thread than with the emails I get from people who purchased the services this company is offering.
Also, people using GitHub should know better than to call this a leak. If it was public on GitHub, it's public on the internet.
Far more frequently though, I get emails from people asking interesting questions either about one of my projects or about something they're doing that is similar to one of my projects. I consider the (very low) cost of recruiter spam to be a price worth paying to enable those other interactions.
But my resume is public, my email is my screenname@gmail so it's not like anyone has a hard time guessing who I am.
I also recently graduated from Berkeley - so I have no doubt that with a simple search things could rank me as being possibly looking for a job. Then again, there's no way in hell I'm a "Senior Blah Blah", so I would guess a decent amount of the emails I get have been from scraping. (I always gave real recruiters a better email address.)
But then I created a github organization and moved the repositories beneath that instead of under my own login - and at that point the mails ceased, immediately.
I wonder if the crawlers just assumed "Organisation == Company". It was an unexpected benefit anyway.
The only downside is those online sites where they rank your popularity/skills in different languages now only consider my personal repositories and I'm not longer in the top 5% of C++ coders. I can live with that!
It is a site that crawls open-source code hosting sites (e.g. github and bitbucket)
and creates profiles of open-source projects and open-source developers.
Those profiles include things like technologies used by a developer on open source
projects (e.g. Scala/Java, .NET, Clojure, Python, etc), libraries and frameworks
(e.g. Hibernate, Spring, JQuery, bootstraps, etc.), on many cases locations of
the developer, and even when a developer used a particular
technology (for Open Source projects)
[0] "I'm creating www.geekedin.net" https://www.linkedin.com/pulse/im-creating-wwwgeekedinnet-er...Is it even possible for the service to comply with the data protection directive? It's necessary to obtain consent before processing personal data, but that's not the case here.
Even though I use a password manager and unique passwords, I still get the shills whenever I see an email from the HIBP domain.
It's just something that makes me feel uncomfortable, even though I know that the breach is specific to a site that I have never used frequently and doesn't affect any of my other profiles.
You don't want to know about protocol -2...
Yes, I reused my Gmail password in $pwnd_service. Bad idea.
Fortunately Google managed to detect the unusual activity and lock them out, but maybe others aren't that lucky. That event led me to finally use a password manager and stop reusing passwords everywhere.
What an afternoon, trying to change password from all services I could remember. Can you remember all services you signed up for with your email? Cause I definitely didn't.
Quite a humbling experience.
You might also want to check your browser settings to see which domains have saved cookies, saved passwords, or the "never save passwords on this domain" flag.
The more in-depth metrics are also things you can scrape from GitHub. If you aren't comfortable with these metrics being calculated about your public actions, then you probably shouldn't have signed up for a "social coding" site.
I received an email from haveibeenpwned.com about this, but I don't see how this makes sense, given that no information was revealed that users hadn't consented to reveal.
As I write this, it occurs to me that there's not a foolproof way to verify an email in the developer's GitHub repos belongs to the same developer. GitHub user janedoe may or may not be the same person that made a commit w/ the email address jane@doe.com.
But if it's available on the internet, it becomes a different thing entirely. Rather than being track-downable for specific purposes, you become harvestable for mass purposes.
Merely being known is sometimes the first step in being victimized, and these kinds of things make being known easier and more frequent.
Exactly. If $INTERNET_DATA_HARVESTER had to pay someone to watch whenever it wanted to see what I did on the internet, it would cost them a lot of money, so they would only watch if they had a reasonable suspicion of profit. Even at starvation wages of $2/day, that's $700/yr/person, which would bankrupt the major data harvesters. Even if Facebook only paid each starving person to stumble over to the DMV one day a year, it would cost them $42 billion to monitor their users.
The problem is the email they used is not publicly facing in my Github account, but it _is_ the login email that I use for Github. I never got the "Have I Been Pwned" email, but this is very concerning to me, I keep this email very private.
Coincidence?
git shortlog -s -e
You might find that they were using their school e-mail back then for example.Also if you clone all their repositories and everything else they have contributed to you might find an occasional commit in which they accidentally used for example the e-mail they have at work.
Back then we crawled all public github repos and took a look at all the commits so any email you've used for making commits with git and pushed to GitHub is public.
The analysis is somewhat legit. The email is ofc automated but it was quite high quality. I left on March this year so things may have changed an awful lot.
EDIT: By high quality I mean they give you all the possible details of the offer. Again, this might have changed.
If you are unhappy with them feel free to rant on Twitter mentioning them and they'll get back to you very quickly.
They boast on their FAQ page that they are "different from a recruiter", and the contact person wrote "We have analyzed your open source contributions on Github and think that you could be a good fit for [web backend programmer]". The thing is, they sent me an e-mail to the address that is present in just one repository and has nothing to do with web at all.
Then, when I asked what repositories have they looked at, what caught their eye, and why do they think I would like the position, the contact person sent me a lengthy e-mail about how their recruitment process looks like, not addressing my questions at all.
All in all, they just sent me some e-mail templates filled after trivial keyword matching, which I find funny, because they claim they are so much better than "regular recruiters".
Though, to be honest, they did give the offer details upfront, without me asking about that.
They appear to be building recruiting profiles of github users based on their public GH profile and commit info.
But I'm still nervous about it, because now I'm known by another party, and they know where I've been compromised and with what email. HIBP is probably good people, but they can be breached too. It's why it's taken me this long to convince myself to try it.
_Edit_: Just checked my leaked info. Either Troy's service or geekedin didn't scrape the data properly, because it shows up my very tiny secondary account I'd made long back for some github specific testing (that required a second account)
EDIT: I basically re-subscribed, and once I re-verified the address, I got the button.
Or, even protect things like my Bank Accounts, Utility accounts etc. against spear phishing attacks?
I really should have abused the github email bug further to do something more fun with scrapers.
Well... their databases way. It's not 'the rails way'.
The "created_at": "2012-06-07T06:10:07Z" also gives it away.
i.e., my profile is here: https://api.github.com/users/diziet
Also, numerical profile ids in URLs are more of a SQL thing rather than rails.
The users/1 doesn't take you to the user with id=1, it takes you to the user with username=1, which is very different. For example you can see my github profile on this api by doing
https://api.github.com/users/cvoege
The link you gave there is to the person with the username 1.
Second of all you can't see my email since it's not publicly available on github, and most people's aren't as far as I know.
Third of all incremental integer ids isn't the "rails way", this would be decided by the database and has nothing to do really with rails or whatever framework you use.
The data is not hacked and therefore you are legally entitled to expose via your HIPD service. When I mentioned that the IPs were exposed they were taken down in less than a couple of minutes. Yet 18 minutes after you replied saying that you contacted "someone" to take them down. Clever way to get on the front page of hacker news. Right out of the politics of fear playbook :) Have we been pwned?? Yes we have.
Traffic whore.
"One of the key projects I'm involved in today is Have I been pwned? (HIBP), a free service that aggregates data breaches and helps people establish if they've been impacted by malicious activity on the web. As well as being a useful service for the community, HIBP has given me an avenue to ship code that runs at scale on Microsoft's Azure cloud platform, one of the best ways we have of standing up services on the web today."