[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Mail]  [Sign-in]  [Setup]  [Help]  [Register] 

Steven Bonnell wants to murder Americans he disagrees with

What the fagots LGBTQ really means

I watched Charlie Kirk get assassinated. This is my experience.

Elon Musk Delivers Stunning Remarks At Historic UK March (Tommy Robinson)

"Transcript: Mrs. Erika Kirk Delivers Public Address: ‘His Movement Will Go On’"

"Victor Davis Hanson to Newsmax: Kirk Slaying Crosses Rubicon"

Rest In Peace Charlie Kirk

Charlotte train murder: Graphic video captures random fatal stabbing of young Ukrainian refugee

Berlin in July 1945 - Probably the best restored film material you'll watch from that time!

Ok this is Funny

Walking Through 1980s Los Angeles: The City That Reinvented Cool

THE ZOMBIES OF AMERICA

THE OLDEST PHOTOS OF NEW YORK YOU'VE NEVER SEEN

John Rich – Calling Out P. Diddy, TVA Scandal, and Joel Osteen | SRS #232

Capablanca Teaches Us The ONLY Chess Opening You'll Ever Need

"How Bruce Springsteen Fooled America"

How ancient Rome was excavated in Italy in the 1920s. Unique rare videos and photos.

Reagan JOKE On The Homeless

The Deleted Wisdom (1776 Report)

Sicko Transfaggots video

The Englund Gambit Checkmate

20 Minutes Of Black DC Residents Supporting Trump's Federal Takeover!

"Virginia Public Schools Deserve This Reckoning"

"'Pack the Bags, We're Going on a Guilt Trip'—the Secret to the Democrats' Success"

"Washington, D.C., Is a Disgrace"

"Trump Orders New 'Highly Accurate' Census Excluding Illegals"

what a freakin' insane asylum

Sorry, CNN, We're Not Going to Stop Talking About the Russian Collusion Hoax

"No Autopsy Can Restore the Democratic Party’s Viability"

RIP Ozzy

"Trump floats 'restriction' for Commanders if they fail to ditch nickname in favor of Redskins return"

"Virginia Governor’s Race Heats Up As Republican Winsome Sears Does a Hard Reboot of Her Campaign"

"We Hate Communism!!"

"Mamdani and the Democratic Schism"

"The 2nd Impeachment: Trump’s Popularity Still Scares Them to Death"

"President Badass"

"Jasmine Crockett's Train Wreck Interview Was a Disaster"

"How Israel Used Spies, Smuggled Drones and AI to Stun and Hobble Iran"

There hasn’T been ... a single updaTe To This siTe --- since I joined.

"This Is Not What Authoritarianism Looks Like"

America Erupts… ICE Raids Takeover The Streets

AC/DC- Riff Raff + Go Down [VH1 Uncut, July 5, 1996]

Why is Peter Schiff calling Bitcoin a ‘giant cult’ and how does this impact market sentiment?

Esso Your Butt Buddy Horseshit jacks off to that shit

"The Addled Activist Mind"

"Don’t Stop with Harvard"

"Does the Biden Cover-Up Have Two Layers?"

"Pete Rose, 'Shoeless' Joe Reinstated by MLB, Eligible for HOF"

"'Major Breakthrough': Here Are the Details on the China Trade Deal"

Freepers Still Love war


Status: Not Logged In; Sign In

Computers-Hacking
See other Computers-Hacking Articles

Title: A surge of sites and apps are exhausting your CPU to mine cryptocurrency
Source: Ars Technica
URL Source: https://arstechnica.com/information ... ur-cpu-to-mine-cryptocurrency/
Published: Oct 31, 2017
Author: Dan Goodin
Post Date: 2017-10-31 11:51:29 by Willie Green
Keywords: None
Views: 1140
Comments: 1

Coinhive harnesses the resources of 500 million people with no questions asked.

The Internet is awash with covert crypto currency miners that bog down computers and even smartphones with computationally intensive math problems called by hacked or ethically questionable sites.

The latest examples came on Monday with the revelation from antivirus provider Trend Micro that at least two Android apps with as many as 50,000 downloads from Google Play were recently caught putting crypto miners inside a hidden browser window. The miners caused phones running the apps to run JavaScript hosted on Coinhive.com, a site that harnesses the CPUs of millions of PCs to mine the Monero crypto currency. In turn, Coinhive gives participating sites a tiny cut of the relatively small proceeds. Google has since removed the apps, which were known as Recitiamo Santo Rosario Free and SafetyNet Wireless App.

Last week, researchers from security firm Sucuri warned that at least 500 websites running the WordPress content management system alone had been hacked to run the Coinhive mining scripts. Sucuri said other Web platforms—including Magento, Joomla, and Drupal—are also being hacked in large numbers to run the Coinhive programming interface.

Earlier this month, political fact-checking site Politifact.com was found hosting Coinhive scripts in a way that exhausted 100 percent of visitors computing resources. A PolitiFact official told Ars the incident occurred when "an unidentified hacker attached a crypto mining script to the PolitiFact code base being stored on a cloud-based server." The code has since been removed and was active only when people had a politifact.com window open in their browser.

Don't look, don't tell

Coinhive presents its service as a way end users can support sites without viewing online ads, which are often criticized for containing malware that surreptitiously infects visitors with ransomware, password stealers, and other malicious wares. And in fairness, the service only consumes 100 percent of a visitor's computing resources when the Coinhive's interfaces are being abused. Still, Coinhive doesn't require third-party sites to tell visitors their computers and electricity are being consumed in exchange for visiting the site. Coinhive has also done nothing to prevent sites from abusing its programming interface in a way that completely drains visitors' resources.

Ad blocker AdGuard recently reported that 220 sites on the Alexa top 100,000 list serve crypto mining scripts to more than 500 million people. In three weeks, AdGuard estimated, the sites generated a collective $43,000. Both AdGuard, antimalware provider Malwarebytes, and a variety of their peers have recently started blocking or restricting access to Coinhive crypto mining. Both AdGuard and Malwarebytes give end users who want to support a site using Coinhive the option of accessing the mining script. In announcing the move, Malwarebytes wrote:

The reason we block Coinhive is because there are site owners who do not ask for their users' permission to start running CPU-gorging applications on their systems. A regular Bitcoin miner could be incredibly simple or a powerhouse, depending on how much computing the user running the miner wants to use. The JavaScript version of a miner allows customization of how much mining to do, per user system, but leaves that up to the site owner, who may want to slow down your computer experience to a crawl.

Coinhive's massive Web audience isn't lost on other companies. Collin Mulliner, a security researcher and developer of TelStop, said he recently received an e-mail from a startup called Medsweb inviting him to integrate a Monero miner into his creation. "If your app is deployed on thousands/millions of devices, you can monetize it with monero mining and earn really huge income," the unsolicited e-mail stated. "We manage all the complexity of backend servers and mining operations and you get a really simple control panel to monitor your hashrate and earnings."

Malwarebytes noted that Coinhive recently introduced authedmine.com, a service that requires third-party sites received explicit permission of end users before using their computers to mine digital coins. But the antimalware provider went on to point out that coinhive.com remains active and continues to require no end-user notice at all. As the recent discovery of the Android apps and the more than 500 hacked websites makes clear, Coinhive continues to turn a blind eye to the abuse of its service in much the way adware providers did in the early 2000s.


Poster Comment:

Post Comment   Private Reply   Ignore Thread  


TopPage UpFull ThreadPage DownBottom/Latest

#1. To: Willie Green (#0) (Edited)

That must be why my twin-Xeon 2GHz, 32GB workstation is currently running at 5% CPU load and 22% memory load with 59 browser tabs open.

One more scare story to sell antivirus stuff.

Hank Rearden  posted on  2017-10-31   14:03:58 ET  Reply   Trace   Private Reply  


TopPage UpFull ThreadPage DownBottom/Latest

[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Mail]  [Sign-in]  [Setup]  [Help]  [Register] 

Please report web page problems, questions and comments to webmaster@libertysflame.com