Fighting cryptojacking and doing good things with content security policies
troyhunt.com
troyhunt.com
Essentially you will find there's a whole wild west out there that you don't normally think about.
But I agree, locking down a site with CSP is a great exercise in just how domains get loaded. Especially if you have a marketing team who gets sold on the latest service weekly.
(Given your comment, I suspect your guess is likely to be much closer to reality than the vast majority of even the relatively clueful people here on HN.)
"The website that sent you here has been hacked and may not be safe to use. Please contact the site owner to let them know. Are you the website owner? Click here for a detailed explanation."
It also seems like the modal popup JS doesn't remember if the dialog has already been shown and will appear on every new navigation causing a lot of frustration for visitors. Given the widespread impact this has to users, it feels a bit rushed.
E.g., with your proposed wording, now the website owner gets reported that their website has been compromised, when, in the case of compromised routers discussed in the article, it hasn't.
(I do think some of your suggestions are valid; the article isn't going to be approachable for the average Joe, and if it does pop up that frequently, perhaps that could be improved.)
Explaining the situation to the casual visitor is pretty much pointless as they can't really do anything about it and, as it's not serving anything malicious currently, that's all that's really necessary at this point.
> During our follow-up research on cryptojacking, we discovered that 1.4M MikroTik routers were serving cryptojacking scripts as they were routing Web traffic, geographically focussed on Brazil and Indonesia. It could be that a Vietnamese MikroTik router is still infected and somehow manages to inject the script into that particular (popular) website.
Due to a lack of options for putting signing pubkeys into DNS or something like that, this requires the loaded page itself to be delivered over TLS. Bulk content can rely on subresource integrity, but may need a fall back on TLS to successfully load the content in the presence of MITM. This fallback can likely be done via a small script, either inline or also served via TLS.
Yes and there is https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Na... for that! We just need community to adopt it, and move away from the mess of a system CAs are.
I'm complaining about a lack of support for signing keys. Think IPFS's IPNS (though that goes a bit beyond just signing keys, as it includes DHT-based retrieval with just the key (and notably lacking an address).
Well, IMO, this is the best model. PB it clearly states they run a cryptominer and if you want you can have an adblocker block that and they still allow you to search undisturbed their website. Now compare this with Forbes for example, who have adblocker detection which will not allow you to view the content you want and asks to whitelist them in your adblocker. Except that once you do that they will fill your page with not only their ads but also 3rd party websites ads, which was proved many times in the past were malware. So if there is any name and shame it should be done to Forbes / Bloomberg and the likes, not PB.
The note about securing static sites with https finally painted the picture for me as to why it's a big deal, even for sites that don't send any data to a db!
> Securing the transport layer isn't just about protecting sensitive information, it's also about protecting the integrity of the content
Unfortunately the cryptojacked website gets screwed either way.
Without a CSP policy, it will have its resources cryptojacked, which depletes its resources, and with the CSP policy it will have to process the violation report, which again depletes its resources.
The only solution is to never visit a cryptojack website, if you’ve come to rely on that site for something then that might prove very difficult, and not visiting it could again deplete resources finding a replacement site.
Could happen to anyone on http, there’s just no way to know if you’ll be routed through a hacker router.
Even with https there’s no way to know ahead of time that the site isn’t adding the malicious js, though probably will happen less often than on http.
In a future AR/VR world this is the sort of problem that could get quite horrible.
You really would not want a cryptojacked-sites-all-the-way-down situation to develop.
It’s the wasted resources that worry me.
He knows the script URL and referrer URL of each attempt to invoke the malicious scripts. The URLs of the scripts seem to include the token to configure them to the attacker.
He visited sites in the referrers and looked them up in search only to do tests to convince himself that the pages are clean and the servers aren't conditionally returning the malicious content, etc.
I personally think it sounds like a great way to pay for things without having to sign up for anything and just pay with my electricity bill, but please educate me.
> So, instead of serving ads you put a JavaScript based cryptominer on your victi... sorry - visitors - browsers then whilst they're sitting there reading your content, you're harvesting Monero coin on their machine.
I don't see how this is worse/more evil than ads though? At least the worst that a miner will do is consume some resources, where as conventional ads will consume resources + compromise the privacy of the victim.
Firstly, whatever resources are consumed by ads, resource consumption is not intrinsic to their nature. In other words, the effectiveness of an ad does not depend on how many resources it uses on its target's device.
Furthermore, the resource consumption by ads can be argued to be a real creation of value, in the sense that the advertiser could not make money from running ads on their own devices without any involvement of their targets. Neither is the target being deprived of any profit that they themselves might have wanted. Would the target wish to run their own advertising aimed at themselves on their own browser to promote their own product and/or track their own browsing habits? Of course not.
Compare that to covert cryptomining. The cryptominer could achieve the same result by running the code on their own devices, and paying for the resources consumed. On the other hand, the target is being unknowingly deprived of the profit being generated by the resources that they themselves are paying for but chose not to employ in cryptomining. Would the target like to use X% of their electricity bill, sacrifice Y% of their device's resources, and Z% of its durability lifespan to obtain a certain amount of a cryptocurrency? Maybe.
Also, ads can have negative impacts from the thing that's being advertised if it ends up being a scam, dangerous/fake/misrepresented product or malware.
1) The long-term validity and usefulness of the data they are gathering. A user may be relatively net-savvy regarding the use of private browsing, they may rescind their consent on this or that advertising network to track them, their visiting son or daughter might give their device a "privacy clean-up", or they may be ironically so digitally illiterate that when their phone dies or they forget their passwords they just create a new Google account.
2) The legal risks involved in gathering, and particularly exploiting, non-GDPR (or other local law) compliant data.
With non-consensual cryptocurrency mining, both points become irrelevant. Once it is mined, cryptocurrency is a pure commodity, regardless of legality and the consent or future opinions of the person whose resources were employed to produce it.
I know Coinhive originally started like that, for this Polish imageboard where you explicitly had to allow your CPU to mine in order to get premium account time, as an alternative way to just paying for it outright.
All parts of a page for me, even 1st party, have JS disabled... you'd be surprised, most useful ones work completely fine like that and things load much faster. There's exceptions that do actually need it, and if I trust them, I'll enable 1st-party JS via uMatrix.
Disabling JS and blocking 3rd parties breaks -- and I mean completely, unusably, breaks -- a ton of websites. It's rare I run across a site these days that is strictly 1st party and has nothing else going on. I can't even order a goddamn pizza without enabling four different 3rd party domains.
Sure, you can save your preferences in uMatrix, but when the website updates you're back at square one, or worse, you're overly permissive.
Worst of all, I often have to completely turn off uMatrix for some sites.
While the intent is good, I honestly cannot recommend this approach anymore. It just sucks.