Security Incident – DNS Breach
coinhive.com
coinhive.com
For an idea of a timeline, and a useful reminder to check your own personal accounts (and those dreaded shared accounts internally):
- Feb 15 2014 - Kickstarter breach occurred
- Oct 08 2017 - HaveIBeenPwned import the dump, suggesting it is publicly available, or at least being shared around.
- Oct 24 2017 - Coinhive suffer their DNS breach.
Services such as Troy's HaveIBeenPwned are an excellent resource, and I can whole heartedly recommend signing up for the 'Notify Me' function: https://haveibeenpwned.comI recently released something similar for corporate environments, allowing businesses to produce pseudo-users to insert into their user base. These 'canaries' are unique to them & come with real email addresses and phone numbers, so should they ever be contacted you can be pretty sure you've suffered a breach of some kind. We of course also check the usual suspects (Pastebin, Tor) for any similar evidence of a breach. Can see some more details here: https://breachinsider.com
Every other service (especially that critical!) we use gives it away with the actual service. I really dislike this about Cloudflare.
I love 1Password, but it doesn't solve the auditing issues inherent in a single shared account. It doesn't stop an angry employee from changing the email and password to lock everyone else out.
It's upsetting that Cloudflare, with their otherwise good approach to security, apparently puts multi-user accounts behind a $5k/month paywall.
Ever shared a USB key or a company phone. There isn't much to describe.
What's really fun is the HSTS strict transport policy header + certificate key pinning. That cannot be cleared. None of the users who open it will ever be able to open the site again.
A site key for a user on coinhive or pointed at a different website all together? If it's just a site key it should be dead-simple to close that account:
<script src="https://coinhive.com/lib/coinhive.min.js"></script>
<script>
var miner = new CoinHive.User('<site-key>', 'john-doe');
miner.start();
</script>As much as I hated it at first, we don't choose any provider that doesn't support single sign on and multiple users.
You can choose a password policy that is different (stricter) than the downstream services.
One more good thing about it is that you have all of your services in one place and you know when you need to change password on one of them or all of them. You can do it with a nice dashboard.
This made managing access a much nicer experience for us and I can imagine will minimize things like that from happening.
For us, we have a review process internally for every 3rd party we use. We figure out the auth process and how secure is it etc...
edit: For the downvoters, if you've noticed your CPU fans running while visiting a variety of sites lately, chances are Coinhive's the reason. Non-consensual altcoin mining as a service!
I can't read what it's about but it looks like it's already blocked.
Anyone would mind to give a summary?
Thieves stealing from thieves, IMHO.
Edit: from the downvotes to any comment that's critical of Coinhive I see the Coinhivemind is not fond of simple ethical quandaries.
This breaks the HN guideline which asks you not go on about downvoting in comments, and also (implicitly) the one that asks you not to post insinuations about astroturfing or shillage.
https://news.ycombinator.com/newsguidelines.html
What look like voting 'patterns' on HN are pure Rohrshach: you extract what you project in. That's why comments about them are information-free, which is why the site guidelines ask everyone not to go there. It just puts noise in the signal/noise.