GitHub investigating crypto-mining campaign abusing its server infrastructure
therecord.media
therecord.media
Could temporarily reduce the population of abusers while we figure out a more sustainable strategy?
If so, I wonder if there is a legit need for running modified GitHub actions from non-collaborators?
Could also subject modified actions coming in via pull requests (from non-collaborators) to heavy resources constraints and timeouts.
The attack vector in the article is not the main way miners try to steal CPU from the GitHub community. It's just an interesting one that the journalist chose to write about.
IIRC, they already treat the .github folder as a special case; you can't push modifications to workflow files with a personal access token. So why not ensure that an action or workflow will only run if it is checked into the base branch?
That wouldn't stop PRs from modifying scripts that the action runs, but the current behavior seems a bit counter-intuitive.
The threat models are probably more like 1. "make sure only the right people run actions" and separately, 2. "make sure authorized events/actions only use the expected capabilities." Both largely fail today.
The issue is that even if you don’t allow changes to the actual action workflow, running tests gives an attacker the ability to run arbitrary code. They just need to add the code they want to run to the tests (e.g. have the tests mine crypto)
from Microsoft*
This speculation is making some people rich, yes. But the amount of externalities is staggering.
Thanks to PoW nobody can provide a free compute anymore without getting owned, and of course the environmental impact of bitcoin alone is worse than when Saddam Hussein set oil wells on fire while retreating.
Let the world burn, and products rot to shit, as long as my HODL portfolio goes up. Cryptocurrency supporters really are sociopaths, worse than any hedge fund manager.
Proof Of Work ?.
A lot of em are already trying to shift to other viable alternative proofs.
Your analogy of calling Cryptocurrency supporters as sociopaths.
sounds similar to insulting Edison because he designed the inefficient incandescent bulbs , which consume waaay more energy compared to LEDs built these days.
How would it sound , if someone insults artificial light , just because of that ? .
Cryptocurrencies are perfectly good ideas/products.
Proof of Work’s viability isn’t.
The hate is aimed in the wrong direction.
for scammers and speculators
You’ll know why it’s a great product/ service Once it’s environmental viability has been figured out .
Hating crypto , because news reporters only show you the scammers and the speculators , is blind hatred.
Crypto has/does much much more , than just act as a form of trading / speculation
Scammers often steal money in dollars too. Speculators often trade currency pairs with dollar in them.
Are you still gonna say people who use the dollar for daily transactions don’t exist ? That dollar is also a good idea only for scammers and speculators ?
I've done many. Order of magnitude better experience than bitcoin, which I've also done.
And without knowing that your bitcoin transaction cost many tonnes of co2 on stolen electricity (~70% of which is based on fossil fuels, per a recent bitcoin energy use study).
It's like building an instant messaging system based on throwing molotov cocktails on your neighbors houses to create smoke signals.
"Works great!"
> try using smart contracts in crypto
Smart contracts is just the dumbest idea yet. Anyone who thinks they're a good idea clearly doesn't know what the actual challenges are in existing contracts. It's not solving these challenges at all, but instead making them much worse.
> Hating crypto , because news reporters only show you the scammers and the speculators , is blind hatred.
Seriously? But that's all there is. To a rounding error.
And for good reason. Aside for committing crimes cryptocurrencies are worse in every single aspect.
> Are you still gonna say people who use the dollar for daily transactions don’t exist ? That dollar is also a good idea only for scammers and speculators ?
What do you think the percentage of dollar transaction that's crime? What do you think is the case for bitcoin?
If someone is willing to fund time spend on researching how to do it safely I would do it.
But I am not aware of anyone willing to fund hundreds of hours on such research. And it includes myself.
> Hating crypto , because news reporters only show you the scammers and the speculators , is blind hatred.
I do not care what 'news' reporters 'report'. I am in contact with several crypto-adjacent messages each week, all of them scammers in in mail inbox, on Telegram, in Discord.
Crypto-adjacent scam spam is over half of ads that managed to reach my on my own computer.
I consider it perfectly good reason to heavily dislike BTC and BTC-adjacent things.
> Crypto has/does much much more , than just act as a form of trading / speculation
Yes, it is also scam platform.
> Are you still gonna say people who use the dollar for daily transactions don’t exist ? That dollar is also a good idea only for scammers and speculators ?
No, because it is untrue. Unlike crypto.
Maybe the cryptocurrency industry needs some environmental regulation thrown at it?
If he designed and sold that in 2021, trying to replace LED lightbulbs, and lying through his teeth to pump up the value of his lightbulbs, well then yes.
Can blockchain people please first come up with a use case, that isn't crime, before saying it's worth using more energy that many countries? (for a rounding error away from 0 number of transactions)
All the enumerated use cases are so naive and uninformed that clearly they've just been invented without knowledge about the field. "Move aside, expert in field, I'll just solve this with technology. No I don't need to hear you describe the issues".
There are lots of things driving for crypto besides speculation though. Suggesting cryptocurrency supporters are sociopaths is quite simplistic, and overlooks the majority who are not involved in anything like this article discusses
Like what? I mean aside from crime.
E.g. the "Venezuela argument" has been debunked, from my reading.
In my own life I've seen employees ask to be paid in bitcoin, because of the large fees involved in getting your salary and transferring it into Brazil.
So… those "fees" are mainly taxes, and not paying them is illegal.
To steal manned argument I guess is that some people actually do want to buy stuff online without a third party knowing who paid whom.
First of all BTC is terrible for that. But second, most people don't care if a third party knows they bought pizza. Especially since the pizza place still knows, and they need to keep records anyway, because tax laws.
Fourth, if they don't keep records then they can just say you didn't pay them. They can say "oh, that was not our wallet, you must have mistyped".
Fifth, if the pizza has poop on it you can't even reverse the charge.
Sixth, every pizza place will now be a money laundering scheme.
This is not what we want as individuals, nor as a society.
But yes, some people do want to buy a pizza online and not have a third party know. It's basically LARPing.
Buying a house or a car anonymously? That was made illegal on purpose.
Buying a big mansion anonymously? Well that's clearly at the very least tax fraud.
Anyway, I truly want to hear about any legit use case for cryptocurrencies that is not just LARPing, because as far as I've seen nobody in the 12 years since bitcoin launched has come up with one that actually makes sense.
> Suggesting cryptocurrency supporters are sociopaths is quite simplistic,
Yeah, it is. It's like the old expression "it's very hard to make someone understand something when their livelihood depends on them not understanding it", or something like that.
https://www.youtube.com/watch?v=hn1VxaMEjRU
But the amount of rationalization from cryptocurrency proponents I do think is sociopathic.
> and overlooks the majority who are not involved in anything like this article discusses
When you're in the mob you're still one of the baddies, even if you're not actually the one murdering.
I do blame every cryptocurrency supporter. They are complicit in making the world worse for their own profits. They have a moral obligation to recognize their supporting role in this, and to stop it.
Cryptocurrency users aren't any more complicit in others using it for illicit activities than people who use cash. And you seem to be equating cryptocurrency with proof of work and bitcoin, which, again, are ignoring the majority of the real-world use cases.
But just to establish what you're saying, do you agree that PoW and BTC in particular is absolutely terrible for the world? Can we establish that?
I just want to make sure you're not selecting the parts I have not addressed in these comments and from there you're dismissing the things I have said.
If you can agree that PoW and BTC are awful, then there's no point in staying on that topic, but we can instead look at other parts. Otherwise it seems like a dishonest rhetorical device.
I don't know what countries you moved between, but what you did could be illegal. Or if not, the law may have not caught up yet, because the laws tend to be on the financial institutions, not the payer and payee. But probably the intention of the law is that it should be illegal.
Maybe. It depends how exactly the bitcoin was transferred.
I'm not a lawyer, but have a look at this: https://www.gov.uk/guidance/how-to-comply-with-eu-payments-r... https://www.gov.uk/guidance/money-laundering-regulations-hig...
That's requirements on payment service providers, so (maybe?) not on you. With a decentralized payment service provider, a case could be made that you are the payment service provider of this transaction, but let's assume not, to not make it simple. Still, it is the intention of this EU law that somebody is, right? That's the world in which the law was written.
If you agree with this, that the intention was that somebody has KYC (Know Your Customer) requirements on your transaction, then as I see it the only remaining argument is that you think KYC laws should not exist.
I hope I've not misrepresented you so far. I honestly want to build a trail from your truly legit and moral transaction to what it means in the larger picture.
If you're against KYC I don't quite know what your argument is (it could be a good one), but they were in fact put in place for a reason. Your honest transfer "under the radar" has the same technical means as the ISIS sympathizer's, and the money laundering mob boss's, or the tax dodging wall street CEO's.
I'll assume that you're not an anarchist-libertarian who considers all government action to be theft, and "money laundering" to be a non-crime.
So… the real question is how do we allow transactions like yours, but not make crime like this be trivial under the same technical means?
So far it's by KYC. And KYC laws and enforcement are not perfect. But baby and bathwater. If your argument is that KYC is inherently bad, then I disagree, but don't make it a distraction while actually making a different point.
And if cryptocurrency is "just like cash", that means that, just like with cash, you legally have to report international money transfers: https://www.mybanktracker.com/money-tips/money/travel-intern...
Do you think anyone has ever done this with bitcoin, or any other cryptocurrency? I assume not, because cryptocurrency people will pick and choose when it's "just like cash" and when it's not. Or they'll claim "it's not in a country, it's in cyberspace". But that's all clearly rationalizing to the point of trolling.
To summarize my point: The reason we can't have nice things, the reason there are fees and taxes on international money transfers, is that this is exactly the place where an uncountable amount of fraud and crime happens. It's not "clever" to go around KYC, it's illegal. (or if not technically illegal, the intent clearly was that it would be)
(I have more points against cryptocurrencies, but bringing up every topic at the same time will just be a big distracted mess. If we've agreed on PoW, and if you agree on KYC, then maybe we can do other arguments too)
And I'm not libertarian (I'm far too socialist), but I do believe that there are problems with the extent to which we are being tracked by governments, especially because I have a lot of issue with various laws around the world (see: criminalizing homosexuality, drugs, sex toys, women driving) I do believe controlling the methods by which people pay for things extends government control, and having more freedom there allows more personal freedom in general. Perhaps surprisingly, I do support paying due taxes (when it's often what funds social services and social programs).
Actually, speaking of money laundering, I learned recently that you can pay taxes on illicit income and the IRS won't have any issue with you. However, I don't trust that this isn't used to track down criminals by criminal agencies. Money laundering allows people to pay their taxes without implicating themselves, so in many ways it's something I support.
I'm not in any way suggesting cryptocurrency is a good way to get around government tracking. Cash might often be better. I don't particularly support KYC, so I'm excited to see the development around decentralized exchanges. And I think painting all "crime" with the same brush is quite reductive. Yesterday's crime is too often tomorrow's activism: Breaking an NDA to expose human right's abuses, using a VPN to browse wikipedia, the list goes on.
But yes, I 100% agree about PoW being problematic, and have frequently posted on HN about how the only way it will be solved is through government intervention. I guess I'm not much of an anarchist either.
And that the trade-off between allowing your transaction and preventing organized crime is why KYC and money laundering laws were created.
I recently did a 6 figure international transfer, and I had to talk to people at the bank, who had to sign off that the source of my funds were fine and I wasn't doing anything shady (nor being defrauded). Just a 15min phone call.
For someone who regularly does this I assume it's streamlined, but it does make sense for the bank to be suspicious on multiple levels when I do the biggest transfer of my life.
They also checked with me to make sure I did basic security precautions like "Did someone contact you and tell you to make this transfer, or did you come up with it yourself? Did someone send you the account number, or did you look it up on a trusted source?".
Sure, part of that was "cover your ass" for the bank's liability to a mistake, but some of it is legally mandated for KYC/ML.
Again, don't take my comments as saying governments or these laws in particular are perfect. I'm saying they are deliberate because something like them is really really a good idea, both for the individual and society as a whole.
But I think it's a red herring to say "some governments criminalize homosexuality, therefore KYC/ML laws are bad or overreaching".
> I don't particularly support KYC
So what's your alternative proposal for preventing / detecting the crime it really does catch?
What's your proposal for forcing banks to not look the other way when drug cartels bank their profits?
Again, I'm not saying it's perfect, but without KYC/ML banks wouldn't even have an obligation to look, and would have no liability when they aid organized crime. Clearly we need to do something? KYC/ML is not flawless, but it also works. So this is not a "We have to do something, this is something" case.
If you take away KYC/ML you have to replace it with something better. Otherwise you're just saying "defund the police" with no plan to replace the police.
So that's KYC/ML.
Taxes.
I guess I brought up taxes a little bit, but it's another chapter in the book on cryptocurrencies.
Right now there is huge tax evasion happening in industries that deal with cash. Taxi drivers are a prime example, but also plumbers, carpenters, etc...
Not everyone, of course, but it's so easy for them. E.g. it's common practice among people felling trees for people that they charge a lot because they need to pay insurance in case the tree falls on something expensive. But when the tree doesn't, they just pocket the whole thing and don't tell the tax man or insurance company.
What if we had the cryptocurrency dystopia, where everyone who wants to can get paid in some ideal cryptocurrency? I bet you HUGE parts of salaries will suddenly go dark, and be tax free.
People earning 6-7 digit salaries would just not declare that at all. It would take a lot of sense of civic duty to hand off 5-6 digits per year if you know you can get away with not doing that. Most people don't have that, and I can admit I'd be super tempted too, if I knew math would protect me perfectly.
The reason people actually pay income tax today is because double entry accounting and the paper trail actually makes it hard to hide salary payments. And paying people in cash is also logistically hard, and even harder if you have to do it fraudulently.
You can do it with low wage workers, but I sure as hell wouldn't want to have to deal with thousands of dollars in my hand every week.
But even then, in many countries it's illegal to pay salaries in cash. Because of the rampant fraud that happens when salaries are in cash.
And why would you want to be paid in cash to hide it from the government? You say you believe in taxes, so the tax man will know your income eventually anyway. So there's no point in hiding it.
Interesting about IRS and theoretically not reporting you. Sounds similar to some places where robbing a bank with a fake gun carries a lighter sentence, so that robbers are incentivized to bring the fake gun instead of the real one, thus reducing harm to innocent bystanders and police.
They got Capone for tax evasion, so it's a charge you don't want. But I suspect if you just declare you bank robbery gains, that's not going to work well for you.
Ex:
- do not run on any event.. unless user authorized for that event. Same for actions.
- separate out policies and users cannot edit policies unless authorized to do that
- do not get physical/logical resources (runners, disk quota, long runs, ...) unless given
- default-deny network outbound with url safe-listing
That way only trusted users can run them, and a bit harder for them to get hurt when there is a surprising action that they run
The next level would probably be something like sandboxing : allow anyone to run an action , but a sandbox mode can autofail if violated, and have explicit imports/exports to lock down for how it gets used.
A lot possible.. but need to invest in the basics first..
Unfortunately, using self-hosted runners to provide additional capabilities not supported by Github-hosted ones is basically impossible (for public repos at least) as you can't restrict a runner to an organization or project. Set up a bare-metal runner and it will receive jobs from random forks.
Only if you've configured the actions correctly. I would bet that there is a high number of repositories on both GitLab and GitHub with misconfigured CI pipelines where someone can submit a PR with `env | curl` to grab any secrets defined as environment variables.
The correct mitigation is to ensure that any "secret" variables are marked as "protected" so they can only run on protected branches that are limited to pushes by maintainers. And you'll still need to make sure the masking works in the logs.
They do support integrating with Vault to access secrets in a CI job, but you need to pay them to use that feature. [1]
[0] https://docs.gitlab.com/ee/ci/variables/#mask-a-cicd-variabl...
logs: `env | base64`
network: `env | gzip | curl`
It should be easy to set most workflows to run sandboxed with almost no capabilities - no secrets access, safelisted network access, safelisted package manager accesses for top 10 langs, etc - so that testing someone's PR isn't scary, and runtime violations make loud noises. The whole 'just disable actions on fork PRs' thing is a great default, but ultimately a figleaf as it's not hard to get someone to run an action.
If you have access to a repository you can customize the script to do whatever you want, but there will always be a trace tracking it back to you.
There is a discussion about ultimate security (access only when asked) Vs the convenience of self-service.
You can still avoid that by having people use a fork model, or triggering CD from an external project with tight access.
Putting a burocratic process between ICs will only limit their throughput as in Jenkins paradigm.
The better advice is don't hire people you can't trust
But seeing the HW situation, energy burn, scammers, infra hijacking, etc. there are so many negatives I'm more and more in favour of making it illegal.
Is it that they are global and decentralized that made them just not take a stance on them, also the same reason it obviously would easily and quickly gain popularity as a global, decentralized MLM-Ponzi structure?
You’re not wrong, Walter.
It may be thin, but it covers most people. Most crypto buyers use fiat exchanges. If those were ruled out, the monetary value of tokens would go down, and with it the mining incentives would lower. It wouldn't be the end of crypto, but it would alleviate many issues (energy, hardware shortage, etc).
PS: I don't think crypto is the only reason for GPU shortage (others being more demand from stay-at-home people, and general semiconductor shortages), but I believe it plays a part.
Then why are only GPUs unavailable?
We can still easily buy CPUs, memory, SSDs, etc.
Because they're harder to build, and there is some serious HPC capacity is being built up right now around the world, which buys these chips buy thousands.
Same entities which hoard Tesla GPUs are not interested in unregistered RAM, consumer SSDs and CPUs. Unfortunately, a run of the mill Tesla is not much different from a GeForce. OTOH, RAM, CPU and SSD for these applications are built from different parts.
Gamers in western countries have to pay slightly higher prices for their high end gaming GPUs. Excuse me while I clutch my pearls!
The cavalier attitude people have about this tech is really disheartening to see.
It may aspire to be/do these things, and that's great, but that’s not the present reality.
What Bitcoin provides is sound money with a fixed predictable supply not at the whims of politicians and fed officials. There is no way to increase the supply of Bitcoin by 23% like we had with the us dollar over the last year
Being "at the whims of politicians and fed officials" seems in practice to provide much better stability than being at the whims of a horde of reddit "investors" (or a cabal of Chinese miners).
Not to mention almost everyone I know who "invests" in crypto does so "at the whims of politicians and fed officials." SEC rulings and the likes.
How many monkey butlers will there be?
> What Bitcoin provides is sound money with a fixed predictable supply not at the whims of politicians and fed officials.
A naturally deflationary currency is such a bad idea that every single country went away from them in a fairly short time period.
This is across the board, not just for high-end cards.
Newegg has a total of one graphics card released in the past 5 years in stock that it sells directly (https://www.newegg.com/p/1DW-001Z-00042), a RX 550 going for $200 (plus $8 shipping) -- the 2GB model launched at a MSRP of $79; I assume the 4GB model's MSRP would be somewhere between that and the $99 MSRP of the RX 560.
The rest of the items for sale are third parties which are often no-name brands/shippers from China (e.g. Yeston which seems to have lackluster reviews about short warranty and sloppy build quality, Corn which has many horror stories about shipping delays or just missing products), and all have similarly drastically hiked prices. Next cheapest card shipped from the US is a 560 at $279+15.
The 550 is by no means a high-end gaming GPU, nor was it when it came out.
No one has a claim on any one product such that they can demand the destruction of something millions of people find value in and that has a market value of a trillion dollars so you can have your GPU return to a price in the past that they found reasonable
I think the root cause is because it's conflated with bitcoin and the PoW system it's built on top of, which is generally considered to be unproductive. Take away PoW, and you remove the incentives for miners to suck up vast amounts of electricity, the supply of graphics cards, probably even infrastructure hijacks to some point.
(And yes, I understand that the graphic card shortage is more strongly tied to Ethereum's ASIC-resistant hash. But that's still a PoW system.)
So it's not fair to look at pure energy used by the Bitcoin network as though its some fungible limited supply that we can just move away from Bitcoin production and move to Texas during the winter storm.
Regarding carbon emission, that's a political problem. If you want to create a tax on carbon, you can do that, although I'd prefer carbon capture tech. But in no way should some governing body try to allocate the validity of carbon emissions based on purpose. That would be no different than central planning where some central authority determines how many X should be produced, when and where. It's been tried and failed.
But look at the point of PoW and the purpose of crypto. Its sound money and has value, and an expense to maintain. Whats the alternative? Create a currency with a trusted central bank, and build an army to defend your organization when someone uses your currency to "fund terrorism"? I imagine there's CO2 emissions w/ maintaining an army as well
The new kind of "geek" in the opposite of the traditional "geek" who was a libertarian / pro freedom.
My guess is that most geeks can't afford to bite the hand that feeds them (google/facebook/twitter...) so they decided to loudly proclaim their allegiance to modern values (environmentalism/social justice/wokeness in general)
> There were leftists among geeks the whole time
Clearly a much smaller proportion.
> The environmentalism and the desire for justice is a genuinely held belief of many scientific oriented people of a humanist bent
Is it not interesting in how this is a new social good, especially for geeks working for large corporations in California?
I believe all behavior is based in self preservation: it would be career suicide for a young googler to be part of the christian right, or pro Trump, or try to pull off a Damore like memo.
So I am not surprise they do not bite the hand that feed. I am only surprised in the convoluted rationalization they engage in, instead of being more honest (at least online where they can be anonymous) and say "I pretend I'm woke because I like my job because I like the money and status it gets me"
The reason why so-called Christians are unpopular is because they are seen as public hypocrites; rather than follow Jesus and condemn praying in public, and instead helping the poor, the widows, and the orphans, they seem to spend their energy seemingly endorsing superstitious racialist ideas that were clearly un-Godly 100 years ago.
Those ideas are horrid and they are rejected because they are horrid. Not because Google is pushing an agenda of the sacredness of all human beings, a mirror of the image of God no matter what history they walked to get here.
And the environmental movement is just the same as the people saying “there is a flood coming from the blocked sewer drain, let’s go unblock it.” The anti-environmentalists are the people saying, naw, don’t worry about it.
So the purpose of cryptocurrency here is to enable people to evade the laws of the society in which they live? Not sure I can regard that as a "legitimate use case".
I do not care about that part, but massive amount of scams around BTC and similar is fueling my growing dislike.
As a moderator on small forum most of the work is blocking cryptocurrency scammers.
The saddest part is that apparently they steal enough money to keep their crime profitable.
What is cash? Paper? Ink? Currency isn't defined by what it's made of.
> there just happen to be transactions on a distributed network, with some people knowing private keys to generate new transactions
Transactions in which digital tokens are exchanged for goods, services, or other currencies, and the recipient of the tokens generally receives no benefit other than the ability to trade those tokens again.
Cryptocurrencies are recognizable by the way they are used.
I have long maintained that cryptocurrencies aren't property: they're speech.
Sadly scammers follow both new and old tech and it takes a while for measure to catch up. That's not necessarily a fault of the tech itself.
I have seen no proof that it solves anything the proponents have been touting for 5+ years now - just examples of increases in negative externalities.
Using money online has an obvious utility.
Donations to people where paypal doesn’t work are also easier.
Those are the only uses cases (for me) I encountered and used though ;)
Therefore, you already have to trust them, in which case you might as well just wire the money the old-fashioned way.
Tor is the only network sufficient enough to thwart malicious state actor's efforts.
It comes closest at least. I’m not sure if it’s more than rumors, but they are persistent that NSA and similar actors can de-anonymyze tor users.
Luckily state actors do not play into any of my threat models.
[0] https://nakedsecurity.sophos.com/2020/06/12/facebook-paid-fo...
"There are financial primitives that cannot exist in traditional finance that I'd call pretty novel. For example flash loans allow uncollateralized loans for millions of dollars[0]. Or take KeeperDAO[1] or Dai[2] or any of the other meta protocols generating returns by providing utility. Also the sheer fact that this is all decentralized/identity-less is already a novel aspect.
[0] https://aave.com/flash-loans/
[1] https://medium.com/keeperdao/a-keepers-guide-to-arbitrage-mi...
that sounds like a massive negative externality to me, not something positive
That's a bad thing, not a good one.
When countries descend into chaos or go full on authoritarian the best option is often to leave, but there might already be capital controls. So what can you take with you? Stocks: good luck if held by a broker in the country. Physical gold or cash: good luck at the border/customs. Foreign accounts: hard to come by for most people even in the first world due to regulations. Any serious amount of money is very hard to move between jurisdictions, especially in times of crisis, through traditional means.
If you believe your host country doesn't own you and you should be able to relocate to wherever you are treated best, Bitcoin can be a good tool if you were unprepared so far (e.g. because you didn't think a crisis could hit _your_ country). This might not be a use case for you today, especially if you are happy with your country and it is stable. But don't discount that the situation of others might differ.
The OP is proposing what is arguably an authoritarian prohibition on an entire class of software.
From the whitepaper:
Loosely speaking, the PoST consists of two phases: an initialization phase (executed once), in which miners “commit” to the data that fills the space S , and an execution phase (executed repeatedly), in which miners prove that they are still storing the data. The time component of the spacetime resource is the elapsed time between successive proofs—if the interval between initialization (or the previous execution phase) and the latest execution phase is T, this proves the miner expended S · T spacetime.
https://drive.google.com/file/d/18I9GPebWqgpvusI1kMnAB9nayBb...
> We provide an initial security analysis of the Chia backbone, showing that as long as at least ≈ 61.5% of the space is controlled by honest parties Chia satisfies basic blockchain security properties.
That seems to be a alarming high threshold for control of the network? So as little as 38.6% can attack the network?
The whole idea of creating artificial digital scarcity by basing it on physical scarcity of resources is just horrible.
It’s a terrible plan and very shortsighted. Making hard drives isn’t free of environmental externalities.
> if that case ever came true, the total energy waste would still remain less than PoW by orders of magnitude.
Yes less ongoing energy use, but it does reward creation and effective waste of hard drive space, which isn't without environmental knock-on effects, both some energy use and for chemical byproducts etc.
This is not an 'extremist rationale', if you give people a direct financial incentive to get as much storage as possible, what do you think would happen?
Making something illegal won't stop it from happening. Just because tech can be used for bad purposes doesn't mean you have to or will have any effectiveness in banning it. See encryption.
It's such a lazy take, ignores the freedom aspect and goes for convenience and feels like a concern troll, honestly.
But in the case of cryptocurrency, putting impediments in the way of exchanging it back and forwards with 'fiat' would significantly impact its appeal and demand. Could they stop it entirely? Probably not. Would it stop most people who only care about the easy profit potential and don't care about the idealogy? Probably.
As others said, the answer here is Proof of Stake, not banning crypto outright.
Just realize what you're asking for.
Proof of work systems, which by design compete on wasting resources, need to internationally outlawed.
If people want cryptocurrencies to keep going, they can get a move on finally fucking migrating to these alternatives systems they tell us are just around the corner. If none of the major networks are able to do so, they shouldn't exist.
If there is a regulatory route towards reducing / eliminating crypto, I would hope that involves restrictions on the fiat / crypto interchange, not restrictions on what kind of math you can do with a computer.
Math will never be outlawed, but as it stands now it is just too speculative. I don’t have an answer, but as it stands [cryptocurrency / NFT] we need to have a lively debate on what we want it to be.
This is so broad I am not sure which laws you reference. Most of the laws I am aware of talk about how bmuch money you must have to be allowed to speculate.
> Math will never be outlawed,
I wish I shared you certainty. We currently have laws about exporting some types of Math (cryptography) and we have lots politicians interested in placing further restrictions on cryptography.
Laws in general should not be unnecessary broad, most countries have that general rule, and while there is certainly another debate to had on privacy and backdoors, it is a different debate. So when a law comes against Crypto, it should be very specific to curb its problems.
Not as bad as completely misrepresenting real world problems, it isn't! :-D
Meanwhile the rest of us get stuck with externalities - huge energy consumption, hardware supply disruptions, hardware waste, compute hijacking, enabling scammers and extortions schemes.
I don't think crypto should be illegal but the institutions enabling it should
I feel the same about PoN[1]-based currencies! Get rid of the Fed and the military!
[1] Proof of nukes.
World would 100% be a better place without bitcoin.
Crypto / blockchain is great, its current implementation is very much lacking.
I realize what I'm asking for. I'm asking for cryptocurrency speculators to actually pay for the externalities they cause.
Because that's the core of the libertarianism they pretend to support. But of course they don't have libertarian values. The only ideal they stand for is them getting richer by burning everyone else to the ground.
Why? They pay for electricity like everyone else, excepting cases where they're already breaking laws.
Just a thought, I'm probably overlooking something.
With credit systems we can have progressive rates i.e food can be a priority while VR and cryto can subsidize carbon neutral transition.
GitHub provides computing resources, for free, to attract users. This is just one of the challenges of that business model. If this is intolerable for GitHub then it's up to them to find a strategy to counter it.
We don't need to ask the government to punish everyone participating in cryptocurrency.
Perhaps we should consider higher-order consequences of doing absolutely nothing. Hypothetically, what happens if free-to-use code collaboration tools are forced out of the market due to rampant abuse and zero regulation? Do we care that there is now a higher barrier of entry to engage in the craft?
Do you want GitHub to start requiring state-issued identification for creating new accounts? That is where this cat-mouse game is going to end up if you allow it to continue naturally.
Don't imagine that GitHub cares about lowering barriers to entry as an end in itself.
It does this as a means to pursue GitHub's business interests.
Detecting them while they are running would be the best approach I guess. Not after the time limit when the damage is already done.
The trick to protections like this is to not tell anyone how they work, and to run them only occasionally. Ie. once a week, ban half of users who are running xmrig.exe. Also include users who signed up with the same email address, phone number or IP address as the detected users and who have a consistently high CPU use - these are probably successful bypasses of your simple process name based filter.
That way bad actors have a very hard time figuring out exactly what your protections are or how they work. If they were to get an immediate ban as soon as they fired up xmrig.exe, then they'd quickly think to rename it or recompile it or run it under wine or a host of other ideas. Yet having a random selection of their accounts banned seemingly at random means they learn nothing.
Obviously you need a process for users accidentally caught in the net to get their accounts reactivated, and if you're a service like githuib you should probably let the user have a grace period to do that before killing their entire business...
These problems are essentially the same, some of the know-how can be easily adapted between them.
No need to link it to the provider. If one provider does things that way, you want to block their method. (And, of course, the odds are overwhelming that the other providers are doing the same thing.)
And doing this will get me a full week's of free mining on half my miners (if I'm the only one in the world pursuing this strategy) or most of my miners if the banning campaign is capped and also hits other abusers? It sounds like a great deal, honestly.
As long as the account sign-up process requires a captcha or phone number for the most spam-like signups, you'll keep their profits low enough to deter most people.
And what if the miner uses it's own crypto lib, and doesn't rely on the OS crypto API?
Most of build actions is not 100% CPU bound
But yeah, abusers are going to abuse
Unless you compile large C/C++ projects on a low core count VM.
GH Action have a timeout of 60min already. A PR with about 5 jobs running for 5 hrs is nothing to gain for the culprit. The repo owner certainly finds out soon enough, and reports it at GitHub to block him. GitHub doesn't even need to start a mass scan for such losers. Azure is such a huge server farm, nobody should care about a few 1hr miners, who get eventually thrown out.
But the easiest mitigation would be up block outbound traffic to the miners IPs. These are well-known.
What makes it worse is that a tax, higher energy or hardware costs, or increased transaction fees only speed up crypotocurrency inflation relative to other currencies. It's hard for me to comprehend, that others don't see the pyramid scheme behind it.
That means network has to pay less in block reward under PoS, so inflation drops to 1% or less.
Eip-1559 upgrade this summer will also start "burning" a portion of fees. Estimates have this around 0.5% - 1.5% deflation.
Combine those features together, and Ethereum should have long term issuance at around 0% indefinitely, while still paying for validators to secure it.
It's a feedback mechanism too... If usage goes down, burn drops, supply inflates slightly, stimulating use, increasing burn again.
The idea is to make an elastic self-securing system.
I don't understand where the pyramid scheme is in that... The money being paid out to validators will by nature barely cover costs (otherwise more people will validate, reducing margins to match). Since anyone can join, and the network punishes correlated misbehavior, that incentivizes decentralization and wide disbursement of block rewards.
---
In the case of topic here, spare CPU cycles will no longer be valuable to exploit under PoS. The valuble qualities will be availability and uptime... Which won't be had by exploring in-broswer mining scripts, or CI exploits.
I have my objections to crypto currencies, but this is not one of them. Most everything we do as humans is a 'waste' if you want to get philosophical.
Blockchain is an interesting technology. It may or may not go anywhere, but there is value in thousands of people 'playing' with it to see what's possible. That is, there is value in exploring the solution space of the Blockchain because there is possibility in finding some local or global efficiency minima. Think of it as a R&D investment that may or may not pay off. Still too early to tell.
Besides, the energy cost of the Blockchains is not and will not be the determining factor in fight against climate change or any other environmental concern. So the last thing you want is government bureaucracies cracking down on it from that angle. Let people explore and play and see where it goes.
Having said that, if crypto mining does start to impact other infrastructure, regulators may have to look at it. And there's precedent for that kind of action. For example, regulators will typically work against silver speculation because silver is also an industrial product and if the price inflates to much, it will have deleterious effects on other industries and the wider economy.
>It's hard for me to comprehend, that others don't see the pyramid scheme behind it.
There is that aspect of it and most recognize it. When crypto intersects money and acts as an investment, it should be regulated because there are a lot of nefarious individuals who are using crypto currencies to swindle money from people. For example, my next door neighbor tried to enlist me to buy into some crypto scheme recently. It took me 5 mins of googling around to see how incredibly risky that 'sure-bet' is [1]. I'm pretty sure he sunk tens of thousands of his money into it and I'm pretty sure he doesn't quite understand what it is that these scammers are offering him (basically he's trading in crypto, that he had to buy, that is popular and therefore relatively liquid - i.e. something you can actually sell - for crypto that is not and has a good chance of collapsing in the near to mid future). Regulations will help in this area.
[1]https://behindmlm.com/mlm-reviews/hypercapital-review-hyperc...
As others have pointed out, there is a lot of waste everywhere. If I lived further up north, I would certainly take advantage of using a compute cluster to heat my house while also generating cash. Yes, there are more efficient ways to heat a house other than 100% electricity, but it is still quite common.
But the point is, although it uses energy, it makes you money as well. And there are plenty of other such similar things. Take the financial markets for instance. It seems prior to 1980, if you wanted to create "wealth", you kind of actually had to do something. You know like found a company, invent something, claim a patent, etc. Since Greenspan cut interest rates in the 1980s, all efforts have gone into hedging against the stock market.
Outside of semi-conductors, very little tech has been invented for a few decades now. Instead, a ton of manpower (and energy) has gone into inventing financial devices to the point where house mortgages end up being sold five or six times through various lenders until they end up in a pool of mortgages that one would buy slices of. And if you were worried about risk, you could then buy "insurance" to hedge against your slices in either direction. I mean that took a lot of energy, and I'm not sure what society got out of it... Of course there is more regulation now, but still, new ETFs are made every month to fit some niche, and stock options and calls... So in other words, we've spent the last 30 years not really inventing anything but just passing a giant ball of money around through various devices.
Edit: and yes I am completely unqualified to make any of these claims. They are opinion, but they seem awfully close to reality.
This is why we can't have nice things.
But yes, it's not completely gone yet.
Mining is one vector of abuse but there are many others when you’re giving free compute to the world. Especially in the radically open way we’re doing it at Replit.
This is inevitable, and I'm sure every CI system has faced this issue.
Very, most explicitly mention mining and an accurate description of it
But its funny because ToS is not a deterrent and I thought you were being sarcastic, instead of inquisitive
Also, edits to the CI script could be made suspect. I never had a first-time contributor on my projects start by making changes to the CI pipeline.
I am pretty sure smart folks at GH thought of this and just deliberating whether to introduce such a breaking flow to maintainers.
The more apparent problem is that CI jobs can execute arbitrary code and are not limited wrt. their execution time. If limited, it would render them useless when used for cryptomining.
What's to stop attackers from making a one-off harmless edit ("forgot a comma in readme") and then, once they're whitelisted, deploying a malicious executable to the CI pipeline.
I think the root issue is that people without write access to your repo can queue arbitrary compute on your dime by simply creating a PR and changing the GitHub workflow files (the definition for GitHub actions). This is even a bigger issue for companies with self-hosted runners who can't use those for public repos as an attacker could file a PR with malicious code and compromise a machine (https://docs.github.com/en/actions/hosting-your-own-runners/...)
One possible solution here is that a maintainer needs to okay any change that changes a workflow file before it runs. Not sure if that introduces other problems...
I see the advantages of having CI configuration right next to the code, but once you start deploying multiple branches or accepting outside contributors, the downsides start to outweigh the benefits.
In-band signaling is always bad
That's not going to work! You want to make sure all the tests that run as part of the CI pass before you merge. What you can do is to make a blanket ban on auto-running the CI pipeline if the CI config was changed till the maintainer clicks Run Actions.
This simple rule change would defeat the purpose of running CI CD on external contributions: I want to see if the tests run and everything is up to my quality standards. I don't want to manually trigger the pipeline, that adds around 5 minute to every PR I receive...
However, as an attacker, I can still execute anything I want. Sure, maybe it's not as convenient as replacing the yml file, but I could embed a script in the tests that will just mine as long as possible.
The point is that you didn't solve anything, you just ruined CI CD
I am sure not every PR you get touches files under '.github/workflows'. Are you sure you were replying to me and not @_fat_santa? It's his approach that ruins CI/CD as far as tests are concerned.
> Sure, maybe it's not as convenient as replacing the yml file, but I could embed a script in the tests that will just mine as long as possible.
Yes, but that slows things down a lot. Now you need to write a fake unit test that spawns a process and that will require to clone a project, get a project to build, writing different code for different programming languages and unit test frameworks...
Also, you would not be able to defeat my runtime timeouts (just added to https://github.com/eclipse/lyo/blob/master/.github/workflows... after reading this post) if GH tarpits CI execution with manual approvals if you touch that config in your PR.
Until it is default-deny for ~all capabilities with say RBAC for enabling, which are basic security principles, they're pretty scary for public repos. It's even scary for private ones as you might want say a contractor or intern to be limited. That they have people publicly dedicated to whackamole response, but seemingly not to security fundamentals (or if they do, not following them / empowered to), is frustrating. Look at the GHA permissions panel and then think like an attacker or defender, it's scary.
The environment variable stuff awhile back was understandable.. but not the big issue. As basically any user can submit a PR that can make current actions that run code (ex: run tests) to run something else by editing the action or code, that means any public user can burn repo $, play in repo-exposed runners (ex: get into corp sandboxes), and if using continuous deployment or service integrations , into their production systems, wherever they publish packages, etc. GitHub is api exposed and git can have commits deleted, so they can even cover most of their tracks. This is SolarWinds all over again, but now a bot can run it automatically on ~everyone!
GHA is both one of my favorite things about GitHub but also been scary. Maybe now that they have access to some. of the best security engineers and researchers in the world, they can fix this...
"Secrets are not passed to workflows that are triggered by a pull request from a fork."
I'm not sure on cathedral vs bazaar. I think it's more like disneyification: instead of handling this stuff, they want it to be a few buttons, and as soon as it's not, it's your problem. Except by nature of the intended use of actions, that's pretty fast. The other side of the spectrum is something like AWS's thrusting of a giant ball of IAM at everyone... but there is plenty of middle ground.
RE:artifactories & repos, github wants you to use those as its part of their monetization strategy -- onramp for a few paid areas + less public internet traffic costs for them. Likewise, as most package managers now have enterprise stewards or b2b investors backing them, the harder / more core parts of the tech is in place for locking down sw deps for most ecosystems.
I was excited when MS bought GitHub primarily because they could accelerate GH to support more of the software dev lifecycle. For the security side, I like they've pushed on auditing, but what could be a massive business for them and boon to the community has instead felt quite slow and small. The dev org is clearly great, just seems lopsided on focus wrt security approach.
If I could wave my wand no build or deploys would need to talk to the internet. We want that all to be deterministic and based on resources we control. But that battle is lost. But white listing software depos and so on seems winnable still.
It also mirrors the “unit tests / CI should be self-contained with network deps mocked” vs “it isn’t tested till it is integration tested” debate. The mock/unit test folks don’t need the network access in CI. Even the clever integration testers can spin up a DB and a local Hadoop cluster during the tests. Only the busy, harried integration testers need the real system to test against during CI. (Disclaimer I have written tests of all three kinds).
Ex: I'd expect the typical inferred public PR CI policy to be no creds/keys, a fixed set of network URL regexes (package deps like https://npm/@trusted_org/\*), upperbounds on CPU/memory/network/disk/etc, and ~no use of internal github APIs. There's probably surprises like `apt-get update`, which in turn is probably addressable with some common special cases. Likewise, for failure modes, as long as no creds are there and resource quotas are in place, most orgs are probably ok to make network read violations be WARN instead of HALT.
That probably covers the 90-99% case when making public PR workflows much safer.
For internal teams and higher-trust actions (CD, issue bots, ...), I'd expect the same but different. Currently, I'm not really sure how to do something like "Add a contractor but keep them away from most things" except by setting up a second repo with just CI. If there was RBAC and policy inference, however, that'd be all of 2 minutes.
If just CPU’s that’s gotta be such a gigantic waste of CPU power for such little crypto.
"GitHub hosts Linux and Windows runners on Standard_DS2_v2 [1] virtual machines in Microsoft Azure"
The only way to have access to a GPU is to use your own self-hosted runner.
0 - https://docs.github.com/en/actions/using-github-hosted-runne...
1 - https://docs.microsoft.com/en-us/azure/virtual-machines/dv2-...
I think if half the effort spent here was spent learning finance, the bad actors would have more money.
Hope they manage to sort it out - and also hope these arseholes doing the damage don't ruin GitHub Actions for the rest of us.
[0] in a discussion about the dangers of running your own CI server. I thought it were sensible if there was a permission config file which specified who can trigger which actions, where the CI uses the permissions of the last ran commit.
It's really strange to me. You would think anyone offering free anything on the internet knows there are people out there who will automate abusing your compute, storage, IPs, any resources you leave exposed.
I've seen someone abuse a password reset form cuz they could advertise using that email addr '+' trick. (realuser+buy_our_scam@example.com). On a platform that didn't even have a million users. If it's free resources, there's no scam too unlikely.
However, it turns out — who would have guessed — people do want to build random PRs, because 99% of PRs aren't jerks trying to mine crypto.
---
Edit: To expand on the 'pull_request_target' event, it was introduced later and defends against running arbitrary unsanctioned workflows. It could have been introduced earlier, and maybe made more prominent, but there's a tradeoff.
GH hosted CI runs use Azure DS2 v2 instances. I'm not sure how GH is billed by Microsoft for compute, but the 3 year reserved pricing is $0.0405/hour.
So all up, that's around $2-4 of TRTL for $23.81 of compute.
Plus there's the real and opportunity cost of needing to assign engineers to try and prevent this from happening.
Anything with its own blockchain and also not popular is basically worthless
The mining rewards over a few months would still be just a fraction of a few million dollar marketcap network
But there are quite a few valuable ones you could get a decent take on, Tellor comes to mind.
https://github.com/Bhargav1912/test_1/pull/2/files
Following the files used reveals the pool and wallet used. The pool lets you look up the stats for this wallet. For this wallet, it says:
> Total Paid: 163000 TRTL - 42.16$
But I guess the culprit is rotating wallets. Judging by the hash rate, the pool estimates a weekly income of 700$. It could be a multiple of this if the culprit uses multiple wallets at once.
<3 Etherpad team