Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'd be okay with it if choosing to do this on your website wasn't going to obviously incentivize hackers to inject this software maliciously on unsuspecting websites to steal money from unsuspecting users.

The more legit websites do this, the more cryptojacking will wreak havoc on the web.

And for those who say they ask for consent so it's okay, why do the CoinHive people still pay out for versions of the software that don't ask for consent?



choosing to do this on your website wasn't going to obviously incentivize hackers

How does this work? Why would hackers needs this "incentive"?


The less legit it is for a website to mine crypto, the easier it is for adblockers and security to block all such scripts without inconveniencing the user (less tradeoff of usability for security).

But when some sites use it and others doesn't, it makes security complicated and hacks are able to slip through easier.

Also, the more users get used to sites mining on their browsers, the less likely they will be perturbed by and reporting CPU usage spikes (which are used to determine which sites have been hacked by cryptojackers) because they are used to seeing legitimate such spikes from sites they frequent.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: