6 ms·
Who and what is Coinhive?
- pandasun 9y agoDon't you need a ridiculous amount of visitors for it actually to be profitable?
- lost_my_pwd 9y ago"But according to Troy Mursch, a security expert who spends much of his time tracking Coinhive and other instances of “cryptojacking,” killing the key doesn’t do anything to stop Coinhive’s code from continuing to mine Monero on a hacked site. Once a key is invalidated, Mursch said, Coinhive keeps 100 percent of the cryptocurrency mined by sites tied to that account from then on." This is where I think Coinhive ethically crosses the line; perhaps legally, too. The mining scripts should stop when contacting Coinhive and determining that the specified key/ID has been disabled due to complaints or fraud.
- mtve 9y agoJust to continue the quote from the article: Reached for comment about this apparent conflict of interest, Coinhive replied with a highly technical response, claiming the organization is working on a fix to correct that conflict. “We have developed Coinhive under the assumption that site keys are immutable,” Coinhive wrote in an email to KrebsOnSecurity. “This is evident by the fact that a site key can not be deleted by a user. This assumption greatly simplified our initial development. We can cache site keys on our WebSocket servers instead of reloading them from the database for every new client. We’re working on a mechanism [to] propagate the invalidation of a key to our WebSocket servers.”
- calibas 9y agoMeaning they'll "fix" it when they're forced to, but in the meantime they'll make a nice profit off the "broken" code.
- smokeyj 9y agoYou could just point the miner at another pool and keep 100% of the shares. Cutting out CoinHive is trivially simple. I really don't get the problem though. Someone's website is hacked and points to coinhive, and we want coinhive to fix it? This is why we can't have nice things.
- s73v3r_ 9y agoWe want Coinhive to not benefit from it.
- smokeyj 9y agoBrowser mining is basically worthless. If they're running a pool then they have to pay server usage to validate low value shares. I'm not sure CoinHive is even economically viable. Meanwhile, Google - the multi billion dollar public company, is the one distributing this script through online ads..
- duskwuff 9y agoThey also need to take more effective steps to allow them to claw back coins which were mined by bad actors. IIRC, they currently rake funds every few hours, allowing those bad actors to get away with most of the coins they mine before they get caught.
- beiller 9y agoI have also tried making a coinhive clone. Sparechange. We fully investigate any complaints and ban API keys immediately after investigation. The only reason to keep mining with a known bad key is greed. also edit - we are working on a way for site owners to validate their site via a DNS entry or something, and only allow keys to mine on validated sites. We want to make this space less scummy!
- berkes 9y agoThanks for plugging here. I researched the space for an article (featured on HN frontpage) a few months ago, but did not come across SpareChange. Back then I found coinhive to be the "only properly implemented authed" system, so I used that as an example. I'll wait how CoinHive comes out of this sh*tstorm and decide if I'll change my example to yours instead. Also good to see there is (i) more improvement possible, (ii) ongoing investigation and (iii) competition in this space. Keep it strong, ignore the haters.
- spectaclepiece 9y agoFound Dr. Matthias Moench to be the real gem in this story. Here is the translated version of the Die Welt article: https://translate.googleusercontent.com/translate_c?depth=1&hl=en&nv=1&rurl=translate.google.com&sl=auto&sp=nmt4&tl=en&u=https://www.welt.de/wirtschaft/article135077209/Viagra-ist-fuer-Gangster-heute-lukrativer-als-Kokain.html&xid=25657,15700022,15700043,15700105,15700124,15700126,15700149,15700168,15700186,15700201&usg=ALkJrhj30tQD5O_BVoUt00qDsfxMLHZhPg https://translate.googleusercontent.com/translate_c?depth=1&...
- hopfog 9y agoWhen Coinhive was released I was really intrigued and imagined a lot of cool way of doing micropayments. I even built a multiplayer game where you had to mine in order to get in-game credits (you can find the URL in my comment history), which was fairly well received by the players. It was a proof-of-concept and when I saw that it worked I started building a proper version of it. However, soon thereafter rogue actors started using Coinhive for malicious things and I'm now at a point where I don't feel like continuing on the game. I still think it's a cool concept and my game is very clearly opt-in where I explain what will happen when you press "Start mining". It feels like "this is why we can't have nice things" is applicable here.
- oelmekki 9y agoAgreed, I initially felt good about coinhive too. I just wanted it to allow to rate limit cpu consumption, it would have been a great alternative to advertisement. Maybe someone will come later with a idea to make this while preventing abuses (maybe browsers could built it in as a mean of payment?).
- Ajedi32 9y ago> I just wanted it to allow to rate limit cpu consumption Can't it already do that? The demo miner on their website has controls for "CPU Usage Percentage" and "Number of cores used".
- oelmekki 9y agoNice, thanks for letting me know - I haven't check it for ages. There is definitely a proper use possible of this, then :)
- tmpmov 9y agoYou may find it less palatable, but I could totally see the 'free to play' games going down the road of cryptocurrency mining. As your project did before, you could tie the mining with in game currency. If the underlying block chain is actively traded you could even scale the game currency with real currency in some way... 0.0001 cent is a gold coin for example. Payment that way would seem fairly above board, especially if you clearly tell the player about the taxing system -- this could then be your funding.
- ballenf 9y agoHas anyone found attempts to deobfuscate the coinhive source code? Maybe my google-fu needs improvement... I found a github page that provides a proxy to the coinhive allowing the user to keep 100% of the profit, but it doesn't even link to the coinhive code that I could see. (https://github.com/cazala/coin-hive-stratum https://github.com/cazala/coin-hive-stratum) Also found this, https://jonathanmh.com/testing-coin-hive-crowd-source-monero-mining/ https://jonathanmh.com/testing-coin-hive-crowd-source-monero.... Interesting but no source code.
- hopfog 9y agoThe actual miner is using WebAssembly so I don't know if it's even possible to deobfuscate in a sensible manner.
- berkes 9y agoI've tried to reverse engineer it, but failed. The best place to start, IMO, is the communication between client-server over a websocket. It is binary, but shows some interesting data and keys as in key-names, from key-value, not crypto-keys). My idea was to make an API-rate limiter, where a client has to submit a list of calculated hashes (PoW) with each request and so protect the API against bots, scrapers and other (D)DoS attacks. Bad idea, because the data that has to be transfered (in Headers) is going to huge, megabytes, if you want to make even a few cents on a million-hits-per-day API.
- beiller 9y agoI have a branch of https://github.com/tpruvot/cpuminer-multi https://github.com/tpruvot/cpuminer-multi, which I am working on tidying up and pushing to Github. It has a bash script that instead of GCC / Clang, compiles to WASM. Any Clang compilable software can compile to WASM theoretically. Only supports cryptonight hashing at the moment.
- TravelTechGuy 9y ago”For roughly a week in January, Coinhive was found hidden inside of YouTube advertisements (via Google’s DoubleClick platform)”. I’m shocked, and very surprised to hear that malware code is disseminated through innocent ads put out there by a user-loving, “do no evil” company. /s Now, can we please finally conclude that an ad blocker in your browser is mandatory?
- bronson 9y agoSure! Do no evil, right? https://www.theverge.com/2018/2/14/17011266/google-chrome-ad-blocker-features https://www.theverge.com/2018/2/14/17011266/google-chrome-ad...
- TaylorGood 9y agoWhy is Coinhive seemingly the sole option for this tool? If it's just code, what is to stop a different group of devs to replicate the process?
- astrodust 9y agoPeople are lazy.
- realPubkey 9y agoThe pr0gramm.com-admins spend the whole day banning users that upload screenshots of this article to the platform.
- shanapu 9y agoI posted a screen but was not banned, I get an PM from admin nicly asked to not publish a screen again before the site and coin-hive will give out their own statements.
- lawl 9y agoI mean, doxxing Gamb wasn't really necessary, he was always very paranoid about being doxxed, and users of the site know what happened to cha0s when he was doxxed. So i understand that they want to think a bit about how to handle this situation. I've complained about krebs being an asshole before on HN and this pretty much confirms it. What exactly did doxxing people contribute to this story? Edit: This might actually be the final straw that breaks the camels back and pr0gramm will go down. So thanks for that, Krebs. I wonder if Brian knows that Krebs means cancer in german. It's somehow fitting.
- lawl 9y agoCan't edit anymore, but: Yup, I pretty much predicted Gambs official statement. They really don't like the doxxing. They posted an official statement and asked nicely to not post their private info on the website as everyone can google it now. And if shit get's out of hand with their private data in the public now they'll shut down the website. Edit: Oh, they also said they've never banned anyone for posting the screenshot but asked them nicely to wait for the statement.
- uhmwhat 9y agoPrivate information? If it was so private, how was Krabs able to get it all off of domains they registered? Answer: It was never private, and just nobody bothered to connect the dots before now.
- pietroglyph 9y agoIt's unfortunate that Coinhive has given this type of monetization a bad reputation; at least their shady practices make it that much easier for a competitor to enter this space. I hope that someone can come along with a transparent mining script that has an expidient abuse resolution process, and no tracking. Hopefully that's enough to overcome the stigma now associated with this type of monetization. I would certainly prefer that to regular ads.
- banachtarski 9y agoYou'd prefer lower battery life and worsened browser performance?
- Psilidae 9y agoThat's also a description of ads.
- pietroglyph 9y agoAds are also visually intrusive and incentivize tracking.
- banachtarski 9y agoI think solving hashes ad nauseum while the page is loaded (and beyond due to service workers) is well beyond a typical ad in terms of resource consumption.
- beiller 9y agoShamelessly plugging sparechange.io we take abuse seriously. Just create a ticket on our site, we require proof of site ownership (place file / DNS txt record) and abusive API key is banned (all websocket traffic becomes HTTP Unauthorized so no mining).
- hippich 9y agoJust a heads up - we, Hashcash.io, working on V2 of our product which will incorporate some bits discussed here: mining and currency and micropayments with new blockchain and PoW approach. We applied to YC18 summer batch, but either way we are going to launch it, it will just depend how soon. If you are interested - leave an email on website :)
- usernam33 9y agoHere is a followup post to the article. https://news.ycombinator.com/item?id=16696865 https://news.ycombinator.com/item?id=16696865