A recruiter used the GitHub API to pull my email address out of Git commits
twitter.com
twitter.com
Of course recruiters search public information.
Learn to live with it.
If your outrage threshold is this low then you’re going to spent all your life in a state of outrage.
It’s nit even interesting let alone important.
Information in github, far from being surrounded by an invisible force field of integrity protection, is actually prime hunting territory for recruiters and any recruiter who doesn’t mine it probably needs to explain to their boss why they’re doing such a bad job.
The recruiter in question, far from being apologetic should have said “yes of course I got your email from GitHub so what?”
The guy recommends avoiding this recruiter. I recommend you use this recruiter as they clearly display basic competence at the task of recruiting.
It seems to me that most good developers would ignore such spam—I get so much of this noise that I pay it no attention whatsoever.
If this is the best recruiters can do, then they can apparently provide no real value to the process.
Of course recruiters are incapable of sound ethical judgement. Part of living with people who have poor ethics is enacting rules which force them to conform or be excluded.
If your ability to care about rules is this low, then you're going to spend all of your life in a state of imminent lawlessness.
Your typos are honestly more interesting than anything else; your message isn't important, just wrong and at the top of the page.
I hope that you are ready to explain CCPA to your boss. I won't accuse you of doing a bad job, though.
The recruiter in question, like all recruiters, is to be avoided when possible. Avoid rent-seeking and grifting.
[0] https://help.github.com/en/articles/github-terms-of-service#...
I used this method years ago, albeit manually. I didn't have much luck though as it's akin to cold calling.
I found it much easier to pay a job and let the interested candidates come to you.
Spam is defined as “unsolicited bulk email”.
Https://spamhaus.org/consumer/definition
It’s a one off, not hulk, so recruiters emailing developer emails found on GitHub isn’t spamming.
Nor is the email address being sold in this case so that aspect of GitHub terms is not being violated.
So in fact you’re wrong and it’s perfectly legitimate for recruiters to use email addresses from GitHub and email them asking about jobs.
More commonly, unsolicited/unwanted commercial email, see, e.g.:
The UBE (unsolicited, bulk, email) definition is the one used by most blocklists and filters and ISP AUPs.
No, it's not
> because B2B where there's an existing business relationship are normally excluded from spam laws.
That's not just B2B, but that's part of the definition of “unsolicited”, it doesn't make the commercial part is a red-herring, either in general or in the context of this thread, which did not involve either a pre-existing business relationship or, since you unnecessarily called it out as relevant, a B2B interaction.
> The UBE (unsolicited, bulk, email) definition is the one used by most blocklists and filters
That's because “bulk”, unlike “commercial”, is easily detectable. (And also because because bulk has the most impact, because, bulk.)
> and ISP AUPs.
Virtually all ISP AUPs include prohibition on unlawful use which includes violations of laws concerning unsolicited commercial email.
Notice he said "(they) used the GitHub API to pull my email address", and GitHub API can be used to massively fetch these kind of information for automatic spamming.
Imagine one day you wake up in the morning by few dozens of automatic recruit emails inviting you for a job which don't fit your profile even a bit, will you be happy? This happened to me few times and I'm not very happy about it.
I agreed GitHub shouldn't take the blame because you can hide your email in the account setting, but I don't think he shouldn't be pissed off by the company who was spamming him.
Yes it is, you put it there.
https://github.com/garybernhardt/dotfiles/blob/master/.mutt/...
I fail to see the dramatic issue here. FWIW, I once got a very good (unsolicited) job offer after putting code on the web, more than a decade before github even existed.
They're not asking to be spammed, but risking it. Laws will punish offenders, but not free you from your personal responsibility to protect what's worth something to you.
> Backlash like this article is warranted and required to change this defeatist attitude.
I'm sure it will lead to harsher punishment for spammers who exploit one's stupidly putting their personal information on the web and then complaining about bad people seeing and using it, while we're not even punishing corporations whose data leaks due to incompetence are putting even those at risk who do not exhibit such gross negligence with their personal info.
If you’re a high profile person or are particularly guarding of your personal communication, I think it’s your responsibility to maintain separate public and private email addresses. You should only be making commits to open source projects with an email address that you intend to be public. It’s literally there so that people can email you about the commit.
Meanwhile in West Virginia, wages are deflating, working-age unemployment is the 3rd highest in the nation and the opioid crisis rages on.
But yes, it is terrible to work in one of the fastest growing, highest paying sectors of the economy—growing so fast that recruiters will go to such extreme lengths to fight for a chance at giving you even more money.
Sometimes I think we could use a little perspective.
I get that email is how the kernel-devs do it. But IMO it's inappropriate for the version-control software to link a particular communication mechanism. Sure you can use a fake email address, and many of us do. Finally github has a feature to use their own no-reply email addresses, but it's a kludge.
git config --global user.email no@email.invalid
And git happily accepts the value, yet the result is not useful to anyone (https://en.wikipedia.org/wiki/.invalid).Or, just edit your .gitconfig by hand after adding an email and change the value there to whatever you want.
Still, it seems inappropriately opinionated for git to tie in and require an identifier on a specific communication mode, even if we can come up with fake emails. And I dislike the extra bits of reduced anonymity (eg "correlate pseudonyms by which fake email they all use")
I think most of the "you didn't know email is easily readable in your commits" are responding to "try and hide your email address". This is kinda tough, since you need to know how each program you use works well enough to know what's public or not. (Or you need a way to have disposable email addresses).
I think another is "adjust expectations and response". I think if your starting assumption is that an email address is public, or that your email address will receive garbage, then it's easier to mark it as spam, complain on social media, and get over it.
What's the mechanism by which an email address found on a public website shouldn't be used to send email? Who decided on this social policy? I've been on the internet with email since about 1995 and this is the first time I've heard it suggested that public information shouldn't be "used" without permission. (And before you go off on a doxing tirade, let me address this: "using" someone's published physical address would be mailing them something - visiting them in person unannounced and/or republishing their address is definitely against social contract and might even be illegal.)
So what's the supposed social contract here? You found an email address but you're not allowed to email to it without permission? How do you get permission?
Further, how would these articles of GDPR apply in this case? GitHub makes no representations about keeping your public data private. Please also suggest interpretation of specific parts of these articles that cover the recruiter collecting and making use of public information.
View any commit of the user on GitHub and add ".patch" to the end of the URL. Done.
https://github.blog/2017-04-11-private-emails-now-more-priva...
Email address is in your public git commits.
Your email address is on the web.
Also known as ongoing spam from spammers once they scrape your email address or pull it from an API in violation of that API's terms of service.
Don't forget the bonus invisible tracking image and CAN-SPAM-YOU compliant unsubscribe link at the bottom in gray text to make it harder to see.
However, I haven't had to do this for years now though, for the absolute worst of the worst obnoxious spammers who won't take no for an answer I set a filter to auto-forward their crap to the entire company of the spammer. The spam stops immediately, every time I've done this.
Back when I first created a GitHub profile, I started getting emails to an email that I don't usually give out. This eventually led me to GitHub after some mentioned seeing my profile which led to me improving my Git knowledge and finding out how they did it.