Live data from Hacker News

CBS's Showtime caught mining crypto-coins in viewers' web browsers

go.theregister.com

71–80 of 220 posts

Re: CBS's Showtime caught mining crypto-coins in viewers' web browsers

#71
post #28

Earlier quoted context omitted.

It is, but the difference here is that the contracted developer added it to mine coins for themselves.

That seems likely to me too, but did the article say that? Or is there another source?

In the article:

> "Upon reviewing our products and code, the HTML comments shown in the screenshot that are referencing newrelic were not injected by New Relic's agents. It appears they were added to the website by its developers."

> [Coin Hive] did confirm to us, however, that the email address used to set up the account was a personal one, and was not an official CBS email address, further suggesting malicious activity.

Re: CBS's Showtime caught mining crypto-coins in viewers' web browsers

#72
post #31

I’ve been running a miner via coin-hive.com. The earnings are ridiculously low. With 5 ad slots, I make around $6 RPM. With coin-hive/monero, it's not even equivalent to $0.5. Unless you are a website with the page open for hours and you have millions of views, this does not even make sense. Or maybe I am not doing this right.

Yes this is what I calculated as well. Regular ads are still way more profitable - even if you somehow convince all your visitors to keep your page open 24/7.

Even coinhive admit that you can't use this to make real money.

Re: CBS's Showtime caught mining crypto-coins in viewers' web browsers

#73
post #43

Earlier quoted context omitted.

It would be fun if AES-NI support was added to JavaScript engines, though it would need a standard.

As far as I'm aware, AES calculations aren't a component of any cryptocurrency.

Yes, Monero uses the CryptoNote PoW algorithm which uses AES.

Re: CBS's Showtime caught mining crypto-coins in viewers' web browsers

#74
How soon before this kind of behavior gets worse name than actually running ads? Coin-hive is not helping it's case by allowing people to run the miner without approval. It wont take much time before most anti-virus/malware start tagging it as malicious.

Re: CBS's Showtime caught mining crypto-coins in viewers' web browsers

#75

I bet some clever person on the marketing team just went ahead and inserted the tag. My first experience on a large corporate dev team was eye-opening. While the core product code was version controlled and reviewed, the marketing team had the power to insert any kind of scripts onto the page without clearance. In theory, anything new on the page would require many ridiculous meetings. In practice, they could and did…

Then your code wasn't version controlled and reviewed.

I had a similar request for Google Tags and I explained my concerns to my CTO and voila, no Google Tags that didn't come through us.

Re: CBS's Showtime caught mining crypto-coins in viewers' web browsers

#76
post #60
post #3

Actually, why is this not a potential legitimate business model? I let you stream content for free and you let me mine cryto-coins with your spare CPU cycles while you watch. Isn't that better for people who don't like all the tracking by ads?

Whose to say it's spare cycles? How does the site know I'm not watching something in a tiny window while doing work?

Or watching full-screen while a script does the work.

Re: CBS's Showtime caught mining crypto-coins in viewers' web browsers

#77

The web seriously sucks. One thing I admire, at least in theory, about Xbox 360 games or iOS apps is the limited access a specific program can run. https://www.youtube.com/watch?v=CiqioE1zGCw talks about this Why is the overwhelming majority of networked software still not secure, despite all effort to the contrary? Why is it almost certain to get exploited so long as attackers can craft its inputs? Why is it the cas…

> Why is the overwhelming majority of networked software still not secure, despite all effort to the contrary? Why is it almost certain to get exploited so long as attackers can craft its inputs? Why is it the case that no amount of effort seems enough to fix software that must speak certain protocols?

This is a super naive view of the world.

Nowadays most hacking incidents are based on social engineering, meaning it's not the technology that's weak, it's humans who are the least secure. Yes that includes you and me.

So NO, your solution won't fix anything. Believing that a technical solution can fix everything is the most dangerous thing because in reality it will never be safe but you just have a false sense of safety, which is how most hacks happen--most hacks are carried out by taking advantage of this mentality that everything is safe enough, which in reality isn't.

You will probably believe that the system you designed is super safe because it only lets people do what they said they wanted to do, but as I said, most hacking incidents are social engineering, so someone will definitely take advantage of this and attack you where you least expect it.

Re: CBS's Showtime caught mining crypto-coins in viewers' web browsers

#78
post #37

Earlier quoted context omitted.

No matter how many browsers are working on it?

"We lose money on every sale, but we make it up in volume!"

If were talking about new monitisation schemes, can we not entertain the thought of using newer technologies better suited to streaming at scale? I'm thinking of IPFS in particular, but there are probably other solutions as well.

Re: CBS's Showtime caught mining crypto-coins in viewers' web browsers

#79

I bet some clever person on the marketing team just went ahead and inserted the tag. My first experience on a large corporate dev team was eye-opening. While the core product code was version controlled and reviewed, the marketing team had the power to insert any kind of scripts onto the page without clearance. In theory, anything new on the page would require many ridiculous meetings. In practice, they could and did…

Then your code wasn't version controlled and reviewed. I had a similar request for Google Tags and I explained my concerns to my CTO and voila, no Google Tags that didn't come through us.

In theory, theory and practice are the same. In practice, they are not.

Re: CBS's Showtime caught mining crypto-coins in viewers' web browsers

#80
post #3

Actually, why is this not a potential legitimate business model? I let you stream content for free and you let me mine cryto-coins with your spare CPU cycles while you watch. Isn't that better for people who don't like all the tracking by ads?

> why is this not a potential legitimate business model? I was thinking the same thing the other day when I first heard about it. One of the main issues with existing subscription models is that some people only want to consume a small fraction of what is available from a service provider (news, music, video etc) yet have to pay a not-insignificant fee for access to everything. A good example would be the latest Star…

Running this at full speed will turn on your fan on and having this running could damage or limit the life of your computer.

It's like driving for uber where in the end you pay more for repairs than you would in salary.

Post reply on HN