DEV Community

StareBrain
StareBrain

Posted on

The comment that earns your trust, then asks for your email

I spent today doing something unglamorous: replying to threads on Indie Hackers, mostly about things unrelated to StareBrain. In the process, I ended up cataloguing a pattern I wasn't looking for.

The obvious version

Some of it was easy to spot. The same generic comment — "nice work, what's the biggest challenge," "thanks for writing this up, bookmarking it," "what made you pick this stack over the alternatives" — showed up word-for-word from different accounts on completely unrelated posts. One account posted the exact same question three separate times on a single thread within two hours. Multiple accounts used the identical phrase "thanks for writing this up, bookmarking it for later," on different threads, hours apart.

None of this is hard to explain once you see three or four instances of it. Alone, any single one of these comments reads as a real person skimming a post and leaving a quick, friendly reply. That's a completely normal thing for someone to do. The only reason it becomes visible as a pattern is seeing enough of them in the same afternoon — which almost nobody replying to any single thread has a reason to do.

The version that actually worried me

The templated stuff is cheap to write and cheap to ignore. There was a second pattern today that took more effort to produce, and did more damage.

One account left a genuinely sharp, specific, well-informed comment on three separate threads today. Not generic — actual engagement with the details of what each founder had posted, the kind of comment that gets credited by the founder as "best question in the thread." Each time, immediately after that credit landed, the same account pivoted: "could be worth continuing this by email — what's easiest on your side?"

At least one founder — building a consumer app, still in early testing — gave out their real email address and, from what I could see in the thread, sent over actual product and funnel data to a stranger they'd just met in a comment section, on the strength of one good comment.

Why the second version is the harder problem

A low-effort bot comment doesn't ask anything of you. It's noise you can learn to filter. This is a different shape of problem: earn trust with something real and specific, then use that earned trust as a lever to extract something the comment section itself was never going to give — an email, contact info, private data, a direct line to someone outside a space with any of a public thread's implicit accountability.

The unsettling part isn't the tactic. Tactics like this aren't new. It's how good the bait has to be for it to work, and how little that has to do with whether the follow-up request is reasonable. A stranger asking for your email out of nowhere gets ignored. The same stranger asking for your email immediately after demonstrating they actually understood your product, in public, in a way that got visibly credited — that's a much harder ask to decline, and it's harder for exactly the reason that makes it feel safe: the comment was genuinely good.

The part that connects to what I actually build

This is a version of the same problem StareBrain exists to deal with, just running on trust instead of execution. A confirmation screen's whole job is making sure a user actually understands what they're agreeing to before it happens — not just that they saw something, but that what they saw accurately represents what's about to occur. A convincing comment operates the same way: it borrows the credibility of "this person clearly gets it" and spends that credibility on a request that has nothing to do with what earned it.

The self-report problem I keep writing about — a system's own claim about what it did isn't independent evidence that it did it — has a social mirror. A comment that demonstrates real expertise isn't independent evidence that the next thing that account asks for is safe. Those are two separate facts, and it's easy to let the first one quietly vouch for the second.

What I'd actually suggest

Not naming accounts, and not trying to build a detector for this — that's a harder problem than a blog post solves. Just a habit worth having: if a comment is unusually good, and the next message from the same person is a request to move off-platform, treat those as two separate decisions. The quality of the first doesn't transfer to the safety of the second, and the accounts that understand that distinction the least are the ones this tactic is built for.

Top comments (0)