Show HN: No Coin – A browser extension to block coin miners
github.com
github.com
And what do I see here? That before it even started people are fighting it.
Found this solution better than ads and infinetely loading ad-tech JS files.
So, yeah, relying on advertisers to not piss off users is a bit much given their business model relies on interrupting your attention.
More like: "Is this user's battery below 50% and discharging? If not, he'll probably not even notice this."
The reason is simple: whatever cruft the site decides to only serve to high-end users is the cruft I'm very much not interested in seeing.
And because I'm definitely not alone in this thinking, those APIs will be failures for anything other than getting additional bits for tracking and profiling people.
And like a sibling comment says, if this catches on, most web sites will do both, i.e. ads + client-side mining.
One nice day publishing industry will no longer be an industry but a group of non-profits, which won't have to sell stuff, and publish way more objective and high-quality stuff.
edit: grammar
There's no such thing as Adblock for video streams on Twitch anymore; the ads are burned into the stream, so you can't block them. (Hopefully YouTube won't switch to the same tech.)
Is that picking your pocket just for watching a video steam? If not, why is a video steam materially different from consuming a website?
Source? Adblock seems to work fine.
It's clearly the future of ad delivery. If you burn ads into video, you can't block them short of doing some kind of realtime detection against the video frames.
It absolutely sucks because the pause button has become a "play ad" button. There's no way to temporarily pause anymore without showing an ad. Hopefully they won't realize they can do the same thing for the mute button.
I still can't reproduce any of this though, I get 0 ads on any of the streams I clicked through.
EDIT: To fix stop/start you of course need to keep buffering the video.
Tune in to Vinesauce (https://twitch.tv/vinesauce) tonight at around 9PM-10PM PST. In addition to being a fun Sunday stream, you'll be able to see first hand what the new ad delivery system is like.
This instantly brought me back to the 2003/2004 Computer Magazine articles with customized TiVo Setups or homebrewed alternatives entirely running on a media center PC.
I still have the hacked Tivo with its network card actually, down in the basement. Hasn't been used for probably going on a decade, but I loved that thing to death while it lasted.
Sounds like you might've been the first to ask!
I'm going to throw my solution in the ring for HN's consideration - https://Datajoy.us/fupm.html: lets make paying for content so simple that both you and the domain owner can happily set it up and let it do its thing behind the scenes as you surf the web.
Right now, it is being trialed for blogs and other top level domain content providers. First payments will be made Oct 1st.
If there's interest, I can resubmit it as a new Show HN thread.
There are other types of consensus mechanisms, like proof-of-stake, that are much more energy efficient, with their own set of pros and cons. They should, and will, exist; but there will still always be at least one proof-of-waste blockchain. Waste is the gold-standard of expense.
The environment issue is a societal one. We need to move to clean energy, and we are.
1. PoW based on waste which has massive negative externalities is abusive. Power generation generally has large negative externalities. Bitcoin kills.
2. PoS is just another type of PoW - people will compete to earn the PoS rewards up until they are "burning" 0.99 worth of potential ETH they could have earned (with stocks or bonds for example) for every 1 ETH they earn through PoW. The difference is, PoS has nearly 0 negative externalities and is funded entirely through capital which was created out of thin air, namely, ETH. The capital required to fund BTC's PoW comes externally. So switching to PoW is a capital-creating act and naturally increases the value of the currency & network.
PoW is disgusting.
There are many things that cost the environment much more than Bitcoin, that are much less useful (almost everything?), where is the resistance to those.
Basically if you use resources to build a machine that does something, or just burn the equivalent amount of resources to achieve the same thing, it's about the same.
Cruise ships probably harm the environment significantly more than Bitcoin, are you mad at them?
Any idiot can come up with the idea of competitively burning electricity to secure a source of truth. But it ignores what happens in x years time.
There is no efficiency that can ever be gained. It's a chart of value and lost energy forever extending up and to the right.
Every business model has trade-offs, and no model guarantees income.
Wouldn't justify wasting energy and compromising user privacy, as the current model does, but that's why capitalism has to go.
Seems to me, before it even started, people started abusing it. (e.g. by just keeping it running through the whole session)
If you want to invent some acceptable method of compensation for the web, you should make sure that both sides have power to negotiate a fair price.
With ads and tracking, it seems to be all or nothing: Either unreasonably high prices (perpetual tracking and potential malware for a 5 minute article) or unreasonably low (use an adblocker and get it free)
The "proof of work" payment method seems to have the same problem.
Solution is the last word to use, there is no problem first off and malware is not how you would solve this fantasy of a "problem".
Or, use their site, but the end user always dictate the code that runs on their own machine. If the server don't wish for a user to skimp the mining, make them submit the proof of work result first, then serve the content.
They make the choice whether to serve it or not.
The cost isn't what hardware does the most work. It's what time was spent creating the content. Of course they have the choice whether to serve it or not, but don't mistake the hours put into writing an article with the milliseconds used to serve a request. You're not (not) paying for the latter.
I am, to the extent their server responds to open protocols on the public Internet. It's up to them, not me, to configure what their server sends when. This is literally how the Internet works.
If you think consuming content online without paying anything for it isn't a problem, you're wrong and it's not even debatable [1]. I'm not saying this is a good solution. I'm just pointing out it's not a "fantasy" of a problem.
The onus is on the site to not serve up content if they don't trust that I'm running their code as-is at full speed. Nothing about the design of the Web says that servers should trust unauthenticated clients or that clients should prioritize the server's wishes over those of the user. Server operators have no standing to complain when a user agent ignores the server's request for the user agent to do something that is against the user's interests.
If you want to put restrictions on how your site is meant to be used, use appropriate protocol means. Like, respond with 402, or simply don't serve content until I pay you / agree to display ads / agree to run your cryptocoin miners / whatever.
Ads, and sneaky cryptocoin mining scripts, are underhand attempts at having a cake and eating it too. Because they know people don't like to pay, they choose to pretend they're free, while at the same time bleeding the visitors for small amounts of indirect money (in attention => time, or computing resources => electricity).
I mean... I get where you're coming from, and I agree that I don't like it either - but I'm curious what the "right" solution is.
I think it's clear that people, on average, hate to pay. They hate to let go of money, and will put up with a surprising amount of bullshit as long as they aren't giving someone else a cent. So what's the winning solution here? Your 402 example is wishful thinking at best, imo.
So far, the only thing I can imagine is some type of system that's built into internet providers. A monetary sharing scheme, based on traffic or viewing receipts, etc. Something to pass revenue via meaningful metrics, and not 402s (which i think are wishful) or crypto mining.
With that said, that seems difficult. Though I do wonder what will happen to these crypto models once they become popular. Suddenly farms will up the hash rate and lower income for site providers. A view will steadily decrease in revenue as hash rate goes up, which will seem to promote longer crypto times. They'll want you to read longer, or wait ~60s before turning to page 2, or etc. All to inch out some extra seconds of crypto time.
Weird world we live in.
My proposed solution is bit unpopular, but it goes like this: just have people pay actual money. Now, this would cause a lot of the present Internet to disappear, and I say good riddance. Here is why.
The Internet is mostly made of two kinds of people: 1) those who publish stuff pro bono, as a hobby or a service to their fellow Internet citizens, and 2) those who publish stuff in order to earn money. If we switched to ad-free, direct-payment-required Internet, here's what I believe would happen:
- People posting stuff pro bono will still post stuff pro bono, still paying the costs out of their own wallets. That content will mostly remain, and will remain free.
- Businesses that also publish something will start treating publishing as a marketing expense, and that content will also remain free.
- The rest of money-earners will try to switch to a subscription model. Those providing actual value will succeed, and people will pay for their publishing directly. As for the rest, there will be carnage, and they'll disappear from the Internet, no longer profitable. Because this literally affects the most worthless (from consumer's POV) kind of publishing, we'll all be better off without it, and the people involved will have an opportunity to find a more socially useful way of earning a living.
- The adtech industry will collapse, which would be a huge win for freedom and privacy on-line.
Now there's one bad side of this solution that comes to my mind: this privileges people with money to spare. Currently, even though we are drowning in sewage that masquerades as content, people without any spending money (like e.g. teenagers) can access disproportionately big amount of quality information (after they sift through the refuse, of course). I know I personally benefited from that when I was younger. I don't know how to handle this particular case; but overall, I still feel the tradeoff is worth it.
Tech like IPFS could make the world a very interesting place.
What you just said: "Here's what I would do: I would make a perfect world. How? That's for you to figure out."
How would you get rid of ads? If you can't answer that, the best you can do is write a fiction book.
Like I already said, I'm fine with it if they're transparent about what they're doing. Miners should not run by default, they should get the user's permission first. If they refuse, don't serve the site.
As long as someone is upfront about the whole thing, I would honestly not mind. It feels like an improvement over the current status quo.
In fact, since CPU cycles are so easy to give away, I'd probably end up doing so more readily than having to pull out my wallet and run through the hassle of registration and payment.
"Figure out" how? If mining didn't eat lots of power and CPU cycles, it would be useless as proof-of-work and BitCoin couldn't exist. It is literally impossible to do useful amounts of mining in a way that doesn't slow down the mining device and drain its battery.
One use case that they have in their demo is micro payments to access web sites: https://demo.taler.net/en/
Ha, I really dig the implication that people are impetuous brats for not wanting this to run on their computers. The audacity..!
https://coin-hive.com/lib/coinhive.min.js
...to their custom block-list instead, no need for an extension.Regarding the custom list for an adblocker, as said in other comments, the idea was to keep it separate from adblocking. Coin mining in the browser is a different issue. Where ads are tracking you and visually interfering with your browsing experience, coin mining, if abused, is eating your computer ressources resulting in slow downs (from high CPU usage) and excessive power consumption. You might be OK with that and not with ads, or vice versa. Or you might just want to keep ads blocked entirely and just enable the coin mining script for a minute to pass a Captcha. That's why I believe having a separate extension is useful.
Can you please share your email to make you the owner of it?
I wonder why CoinHive isn't using WebGL for this.
> [...] There are solutions to run the Cryptonight algorithm on a GPU instead, but the benefit is about 2x, not 10000x like for other algorithms used by Bitcoin or Ethereum. This makes Cryptonight a nice target for JavaScript and the Browser. [...] Our miner uses WebAssembly and runs with about 65% of the performance of a native Miner. [...]
On the other hand, WebGPU looks exactly like the kind of technology that would make web-based GPU-enabled bitcoin mining realistic.
I assumed this whole notion of browser mining as a replacement for ads was just a laugh, but maybe not. Are there coins where it can actually make a noticeable amount of money?
edit: of course because the majority of users have integrated gpus, cpu mining will typically be faster.
Once they have the next generation off the production line, they take the used previous generation, box them up and ship them off to their customers, and then plug the new generation into their mining pools.
If we could trust ASIC manufacturers to not sit on the best hardware, you might be right. However, for the moment everyone can get their hands on CPUs and GPUs of roughly the same power, while easily accessible ASICs are several orders of magnitude slower than the current state of the art.
If you have cheap (or free) power, it's absolutely profitable.
EDIT: I see you meant CPU mining, not mining in general. My mistake!
I don't think we've reached that point yet. An iPhone doesn't last a single day if you use it the whole time, it would barely last for hours mining constantly.
Though I agree this monetization tactic doesn't work on mobile
1. My operating costs are more than $9/month. I don't know where you got that presumed feature but it's wrong.
2. There's nothing to implement. You include a library and a few lines of code to start it and you're done.
3. How would not doing something that could potentially make me money, even if only a little bit, save me money? That makes zero sense.
You don't need to spend hundreds of dollars on AWS.
Anyway, I'd be very interested in hearing how a card game simulator requires more than 8gb of memory and a decent cpu.
I'm also genuinely curious what kind of card game has such intensive server requirements because I just don't see it. Maybe you have a legitimate need to contribute to global warming, it just seems unlikely to me.
By the way, users will instantly close your game if you cause their cpu fans to spin up to 100%
Good luck with your doomed project :)
You'd have a better argument if the TechCrunch homepage didn't use 50% of my CPU just to render all the ads.
Of course inefficient ads are also horrible.
Of course, if it was a viable strategy, wouldn't some malware authors write the malware to do this instead of ransoming files? Has that been tried? Is it a thing?
There are malwares that mine crypto currencies, usually while the machine is idle as to not alert the user that something is up with their machine. However these profits are also quite low since you're using mostly low end machines.
Crypto lockers are of course way more evil, but they function just as well on low quality hardware so I can understand why malware authors do it.
If we're talking about a server for a card game you can just get a cheapo dedicated server and you'll be fine. Get a user or two to donate once a month and you will even run a profit. Or skip that Starbucks once a month.
It is being offered as an option, not being stolen.
> Get a user or two to donate once a month and you will even run a profit. Or skip that Starbucks once a month.
I want to make millions of dollars so that I can build schools for children, why are you limiting the value of my effort and creation?
It's a decentralized uncensorable poker game with no rake that makes money from light client-side mining of relatively cpu efficient coins - you don't think I can build a single school from that?
This makes sense, since the entire idea of crypto currency mining is to use CPU cycles to mine the crypto currency. While ads is just some basic tracking and graphics.
That's a huge "if"; it's my understanding that most cryptocurrencies are currently only efficient with ASICs.
How would you negotiate prices if your customers are not even aware how much they are paying?
https://github.com/gorhill/uBlock/wiki/How-to-whitelist-a-we...
People seems allergic to browser extensions this days. I also get the "why is this an extension and not a filter?" on a non ad-related extension.
That's why I'm skeptical of new browser extensions for things that the ones I have can already cover.
Doesn't mean everybody else has to feel like that (e.g. I honestly hadn't considered someone might want to install this but not a generic configurable blocker - even if you aren't aggressively blocking ads uBlock would be useful for me)
Extensions are also vectors for adware and malware so it's better to trust established extensions, and questioning an extension whose behvior could be trivially accomplished without is a reasonable concern to raise.
There are blockers which can use lists, some of those lists might contain ad domains, some of those lists might contain miner domains.
Using a different addon for exactly the same purpose but for different content is the worst kind of separation of concerns.
Ad blockers have their own issues, including trust about maintainers intentions.
I want to know more about this. Are they seeking any kind of consent from the users, or even disclosing it to the users? If not, I have serious doubts about the legality of this behavior.
In terms of specifics, maybe not anything criminal (though a prosecutor could try the CFAA), but on the civil side tort law trespass theories, maybe also unjust enrichment theories, would be well worth a try for a plaintiff's lawyer.
But really, I'm thinking in terms of more abstract legal ideas that could use some caselaw development to flesh out---the notion that there's an implied license to use resources on a user's computer to an ordinary extent and for an ordinary purpose---and grabbing onto those resources for this kind of extraordinary purposes without prior notice violates that license in just the same kind of way that (eg) triggering a more conventional malware download would. If you buy that theory (and I tentatively do), then there are lots of concrete legal doctrines to hook it to.
World of Warcraft and other games (apparently Windows 10 too) have used P2P (torrent-like) patch systems in the past, where after you downloaded a content update, you also distribute it to other users. AFAIK this was opt-out rather than opt-in. I think that falls under the same category of using the users' computer for an extraordinary purpose.
It's worth noting that this isn't exactly a new idea - some MIT students had a project a couple of years ago that was basically that, except they tried to turn it into a startup. The viability of it was questionable back then as well.
https://en.wikipedia.org/wiki/Parasitic_computing
But it's a bit strange that the same broad concept can include subtle things where the indirect result of an activity is a computation that someone else wanted you to make, along with explicit cases where someone asks your device to run a full-fledged applet and it does so (to someone else's benefit).
I'd love to explore this idea in a more reasonable, less-sketchy, opt-in way, but I'm only just getting started with crypto and I'm not sure what factors go into estimating potential costs/returns yet.
(In the thread for the original Show HN for the code behind this: https://news.ycombinator.com/item?id=15246145 )
the only thing new is known organizations trying to do it for revenues.
chrome.webRequest.onBeforeRequest.addListener(details => {
// ...
// Is domain white listed
if (isDomainWhitelisted(domains[details.tabId])) {
return { cancel: false };
}
return { cancel: true };
}, { urls: blacklistedUrls }, ['blocking']);
It's kind of sad how much boilerplate is required to write a simple extension. I wonder if there's a framework for saving labor while building cross-compatible browser extensions. Then again, maybe the world doesn't need yet another JavaScript framework.Also when taking the problem with battery life into consideration, if the website notifies you that it does this you're free to find another website.
Some way to detect that a non-visible page or service worker is using excessive CPU time or GPU assets would be useful.
How long until porn sites start doing mining in the background?
How long have porn sites being doing mining in the background ?
Remember that porn sites are always the front line of innovation on the web, some are probably already doing it
Often stated, rarely with any actual support.
This is why we can't have nice things.
If you want the results of the mining it makes more sense to run yourself with a native miner than run on the browser.
This coinhive thing only makes sense [to run on a browser] because they're exploiting the resources (hardware and electricity) from the visitors.
edit: I see that Coinhive pays only for solved hashes, so there is no way to "harm" them, and for website owner it makes no difference if hashes are not computed at all or invalid results are submitted.
The point of proof-of-work algorithms is to be hard to compute but easy to verify.
As a simplified example, a proof-of-work might be to take some input and find a corresponding salt that leads to a sha256 with 10 leading zeros. The user works hard to find that salt (the proof-of-work) using some brute force search, but the server easily verifies that the proof is correct because checking a sha256 is easy.
So the proof is verifiable by the definition of the algorithm.
Coin mining uses a lot of resources, which costs you electricity and responsiveness (I’d guess).
Without disclosure/client choice it could slow down someone's computer and and be portrayed as malicious ("If they can mine potentially valuable coins while I'm on the site, what else could they be doing while serving my browser content?")
They are used because the coins that are mined can be sold and the money used to pay for hosting and food.
Mining makes the battery die quicker.
They are mining to make money so they can buy food.
A silly man pays the bad man money for the tiny baby numbers they find in your phone when they mine it.
You can still watch Frozen. The battery isn't dead yet.
- A website author can include a script for their _users_ to mine coins for the website author, which effectively distributes work across many machines you don't own.
- This means, instead of mining on just your own machine, you're effectively mining across N machines (however many users you have) as long as they have your website open (at a ~60% efficiency rate according to other comments).
- This is great for the website author, as it's very little effort on their behalf for a small profit, and affects each individual user less than the whole.
Why someone would want to block coin miners:
- Mining is very CPU intensive, which can slow down the browser for users.
- Increased CPU usage can also lead to higher electricity bills
- Increased CPU usage can also lead to lower battery life
- Someone might also not want to benefit the owner of a website they're visiting, especially if it's at any cost to them (electricity bills, battery, cpu, etc)
It is a very early version of the extension, improvements are on their way.