New kind of GitHub fraud: how is this happening and how do HN users handle it?

10 pointsposted 12 hours ago
by jph

Item id: 41829089

6 Comments

Teknomancer

12 hours ago

Probably the easiest solution to this problem would be—don't use GitHub.

sky2224

7 hours ago

What good would using other repository services do in this case when someone can still just rip the repo?

skydhash

8 hours ago

I think one of the easiest way is to buy a domain name, create a project pages and links to your real github profile and projects you've participated on. It's harder to spoof domain name.

Anyone else just need to do some due diligence. You don't trust random pages on Facebook, so why should you trust Github profiles either? And I'm not saying to trust your project page, but it's way easier to verify that way. And that's why I like when open source projects have their own website.

romanobro56

11 hours ago

How did you find the fraudster?

jph

11 hours ago

A longtime collaborator emailed me directly to point me to the fake profile. I found the other fake profiles just by fiddling with the last character.