Live data from Hacker News

New Skype malware spreading at 2,000 clicks per hour to mine Bitcoins

thenextweb.com

41–50 of 51 posts

Re: New Skype malware spreading at 2,000 clicks per hour to mine Bitcoins

#41
post #37

Earlier quoted context omitted.

That'd be an interesting advertising alternative that could be good for both parties. In exchange for content, you give the website X CPU cycles (or GPU I guess). It could be built into the browser so that you'd have really efficient mining techniques. Clients (with beefier computers) could choose to give more cycles to their favorite sites. I'm not sure if you could provide comparable amounts of revenue. I guess tim…

What if you were, say, Facebook, and had lots of visitors, good time-on-site metrics and you were still searching for ways to grow revenue? Might it make sense? Seems like their entire userbase could combine to mine quite a few bitcoins.. But I'm not a miner, so perhaps I'm wrong? A quick search turned up a Fast Company article that claims ( http://www.fastcompany.com/3005269/facebooks-daily-mobile-us... ) 618 millio…

Remember that the bitcoin network adjusts itself to try to only have about 25 bitcoin per 10 minutes mined. So if you were to jump into the pool with loads of cpu power you'd get a few bitcoin for a whole, then it'd adjust to be harder, raise the bar, and you're back with the same generation rate

Re: New Skype malware spreading at 2,000 clicks per hour to mine Bitcoins

#42
post #7

Malware Bitcoin-miners, hmm? I don't like Skype as a vector... what if you could put it in the browser instead? Which leads me to a less malware-y idea: write a JavaScript/Flash/similar component that mines bitcoins in a web browser. Put it on your site instead of ads. Has anyone beat me to it?

Mining bitcoin on a CPU these days is like digging for gold with a garden shovel. Once upon a time it may have worked, but today it's basically useless (even if you do it on a million computers at once).

[deleted]

Re: New Skype malware spreading at 2,000 clicks per hour to mine Bitcoins

#43
post #20
post #4

Re the conclusion: to protect yourself, don't run an OS that will silently install software just because you clicked on a blue link in a program published by the OS vendor. Steve Ballmer should be jailed as an accessory for allowing this.

With a malware name like "Trojan.Win32.Jorik.IRCbot.xkt" - implying a Windows vector - I can't see why someone would downvote you for that comment. I've got Skype on my *nix box, so do the downvoters assume that my system is also vulnerable to this malware?

There's no indication anywhere in the descriptions of this malware - on Kaspersky's blog or elsewhere - that it is exploiting any new or unique Windows-specific vulnerabilities. It could easily just be a downloadable executable that people are stupid enough to run. Social engineering works great. If your goal is simply to get a malicious executable onto as many machines as possible, Win32 is the obvious target to choose.

You've got Skype on your *nix box: Are you certain it's NOT vulnerable to malware? Obviously a Win32 executable isn't going to run on Linux, but if there's a hole in Skype what's stopping the bug responsible for that hole from causing a similar problem on Linux or OS X?

At this point no facts have been published to describe the nature of the malware in depth, so it's stupid to assume that it's dependent on some platform-specific exploit. On the other hand, it relies on clicking a link, so hopefully you're smart enough not to click shortened URLs sent by friends on Skype, no matter what OS you're running!

Re: New Skype malware spreading at 2,000 clicks per hour to mine Bitcoins

#44
post #38

A keylogger would be more lucrative than a bitcoin miner.

[IANAL] A bitcoin miner sidesteps "unauthorized access to information", taking advantage only of the the compute resources. I'm not sure if that makes any real difference in the eyes of the law, though.

Re: New Skype malware spreading at 2,000 clicks per hour to mine Bitcoins

#45

Malware Bitcoin-miners, hmm? I don't like Skype as a vector... what if you could put it in the browser instead? Which leads me to a less malware-y idea: write a JavaScript/Flash/similar component that mines bitcoins in a web browser. Put it on your site instead of ads. Has anyone beat me to it?

Once upon a time, when java applets were exciting, fresh, and new, I wrote an applet which calculated digits of PI and used CGI to post them to my server.

Visitors would watch animations, whilst I "stole" their CPU time.

That must have been 96/97 or so.

Re: New Skype malware spreading at 2,000 clicks per hour to mine Bitcoins

#47
post #32

Malware Bitcoin-miners, hmm? I don't like Skype as a vector... what if you could put it in the browser instead? Which leads me to a less malware-y idea: write a JavaScript/Flash/similar component that mines bitcoins in a web browser. Put it on your site instead of ads. Has anyone beat me to it?

Why do you think the browser would be a better vector than Skype?

I didn't say it's better. I just like it more.

Re: New Skype malware spreading at 2,000 clicks per hour to mine Bitcoins

#48
post #41
post #37

Earlier quoted context omitted.

What if you were, say, Facebook, and had lots of visitors, good time-on-site metrics and you were still searching for ways to grow revenue? Might it make sense? Seems like their entire userbase could combine to mine quite a few bitcoins.. But I'm not a miner, so perhaps I'm wrong? A quick search turned up a Fast Company article that claims ( http://www.fastcompany.com/3005269/facebooks-daily-mobile-us... ) 618 millio…

Remember that the bitcoin network adjusts itself to try to only have about 25 bitcoin per 10 minutes mined. So if you were to jump into the pool with loads of cpu power you'd get a few bitcoin for a whole, then it'd adjust to be harder, raise the bar, and you're back with the same generation rate

Yes, but you'd be getting more of the pie. The pie remains the same size, granted, but you can still make quite a lot from owning a significant portion of the processing power.

Re: New Skype malware spreading at 2,000 clicks per hour to mine Bitcoins

#49

Malware Bitcoin-miners, hmm? I don't like Skype as a vector... what if you could put it in the browser instead? Which leads me to a less malware-y idea: write a JavaScript/Flash/similar component that mines bitcoins in a web browser. Put it on your site instead of ads. Has anyone beat me to it?

That'd be an interesting advertising alternative that could be good for both parties. In exchange for content, you give the website X CPU cycles (or GPU I guess). It could be built into the browser so that you'd have really efficient mining techniques. Clients (with beefier computers) could choose to give more cycles to their favorite sites. I'm not sure if you could provide comparable amounts of revenue. I guess tim…

A ton of companies have tried to monetize spare cpu cycles. The problem is that you can't do anything valuable with them. Most problems aren't trivially scalable, you have to assume malicious users so that means you need to essentially double efforts, and third parties aren't comfortable sending data through the system.

Re: New Skype malware spreading at 2,000 clicks per hour to mine Bitcoins

#50
post #46
post #15

Earlier quoted context omitted.

Wouldn't work. The right API calls aren't exposed. You would need something like webCL.

People did GPGPU before the likes of OpenCL and CUDA.

well yes... just not from a browser.
Post reply on HN