Norton is installing a Cryptocurrency miner called Norton Crypto (NCrypt.exe)
twitter.com
twitter.com
Users are scared into installing this crap and paying recurring payments for it, and then the performance of their computer goes to shit. Developers are given nightmares by having their software misdetected as a virus or broken by the antivirus changing the OS behavior in unexpected ways.
So I have to pay money to subscribe to mine Norton Crypto and then pay a mining fee on top of that? That's amazing. Are they going to partner with QuickBooks so that I can subscribe to that as well and for a low 15% transaction fee they'll handling filing the taxes for me?
They're basically turning their installed user base into a botnet and charging customers money for the pleasure. I hope they get taken to court over it.
Hold up. Does the term "miner" refer to the pool here? Is "allocation" mining?
This can be read as the pool getting 85% of what miner mined, and allocating 15% fee to the miner.
I was always under the impression that Microsoft does not fix or is extremely slow at fixing particular virus-allowing bugs due to their business model of licensing access to system features, you have to access to be able to build an antivirus software.
I don't know Windows internals but I imagine that your usual game or text editor does not have and cannot gain access to kernel, bootloader etc, that AVs have.
However, this is required only for a “proper” kernel driver specifically; kernel code execution can still be accomplished without any signing at all using /dev/kmem-like mechanisms, which Microsoft explicitly does not consider a bug[1].
> or edit your boot config options to put the machine in an insecure state mostly useful for testing.
Or fiddle with undocumented registry settings (used, among other things, to support upgrades from Windows 7 installations with unsigned drivers) and suppress signing checks for your driver even outside of testing mode[2].
> To get it signed you need to pass a basic test suite which MS provides [...].
You also need to register a business entity and cough up upwards of 300 USD/yr for a Microsoft-approved EV code signing cert[3] before that, which is the biggest hurdle for me at least.
I have to say, even if this new Microsoft is not the same as old Microsoft, it sure looks very similar from some angles.
[1] https://github.com/ionescu007/r0ak#is-this-a-bugvulnerabilit...
[2] https://geoffchappell.com/notes/security/whqlsettings/index....
[3] https://docs.microsoft.com/en-us/windows-hardware/drivers/da...
That's bollocks. Unlike Apple which requires Apple's blessing ("entitlement") to access "sensitive" APIs or to load kernel-mode drivers (and is known to randomly grant or deny them), all you need for distribution of a Windows driver is an EV Code sign certificate (from Vista and above) and additionally from Windows 10 onwards to submit the binary to Microsoft for attestation (which likely means they'll run static analysis to check for malware and that's it).
It should not take an experienced programmer more than a couple of weeks to develop the kernel-mode interface of a basic anti-virus/firewall solution that monitors process, registry, file and network access and passes the data to an user-mode analyzer (the latter are the easiest, all you need there is a simple filter driver)... the stuff where it gets tricky is when AV vendors access internal kernel APIs and data structures to check for malware modifications to hide itself. Malware doesn't care much if Microsoft updates something it needs, but AV software should not break down after a kernel upgrade, which is why the stakes for AV vendors are so much higher.
What Microsoft does sell is access to the source code via the Shared Source program [2] - while there is no official program aimed at AV vendors, you can bet that there is a separate program available for the half-dozen major AV vendors there are.
As for "MS is so slow at fixing bugs": the one thing Microsoft cares and what guarantees it the money it makes is backwards compatibility and operating stability. You can take virtually all major Windows 95-era software and it will run unmodified on a modern Windows 10 machine, well over 25 years after its publication - a promise that the Linux kernel upholds but the userland (distributions) does not give a fuck about, and Apple doesn't care much about software written for obsolete platforms at all (see e.g. dropping Rosetta and 32-bit support after the last hardware based on them went obsolete). And unlike Apple, Microsoft has to check all updates in kernel and user land against a literal shitton of hardware combinations and software to make sure no bugs are introduced.
[1]: https://docs.microsoft.com/en-us/windows-hardware/drivers/da...
Though Apple is now moving towards more of a microkernel architecture, where entire classes of what used to be kernel extensions are now userspace processes. VPN services, network filters/firewalls, some but not all device drivers, etc.
Agreed, but that's not a reasonable way to distribute any piece of software to an audience that's not a bunch of hardcore hackers. The easiest way for "old" Intel Macs is to install OpenCore which can inject kexts before the kernel even gets execution, but for M1 I'm completely lost.
So, like, hackintosh an actual mac? Hmmmm.
Personally, I use OpenCore because I run a RX 5500 XT which isn't supported by Apple's EFI (making the bootpicker impossible to use).
I wonder how much modern windows really requires an anti-virus. During the Windows XP days it felt vital, but since then it has felt more like something everyone just does out of caution.
Microsoft has no reason to load crapware along with Defender, they just ship that stuff with Windows itself.
By “love it” I mean I never have to think about it or acknowledge it’s existence.
Which is the exact opposite of how the word “love” is generally used.
But I still love it.
Seems like a normal thing to say to me. :)
It made way more impressed with Defender. I was always told it's inferior, but its sandboxing and heuristics scanning are quite good.
Regarding you being required to use McAfee, I've found it no better than Windows Defender, so I don't know why people pay for it. It doesn't even rate well in detection tests like av-test or av-comparatives.
Heuristics could be used to infer that stuff, so it's not ideal that we have to do it manually.
Also when I want to scan all the video files in a folder I run ffprobe hundreds of times pretty much in parallel and defender will want to inspect each instance of the same ffprobe exe independently, resulting in a 100% cpu usage and slow scan.
I solved the issue by defining folders exclusions but I don’t believe it can be scripted and it is a pain in the ass. All of the above is unwanted behaviour of an antivirus working against me.
EDIT: I have 4 drives on my C machine: Every disk but C is excluded.
- C - as little stuff as possible, does not exclude
- D - programming and misc utilities (everything from browsers to total commander, editors, programming languges is here)
- E - Gaming
- F - network share - media
That said my primary workstation is linux, htat just backup/gaming/windows programming oneand install almost everything else on other drive , that I put in excluded folders in settings.
It is especially important if you are programming in rust or golang, that produce fat binaries, because its scans and uploads them.
TL;DR Kaspersky inadvertently acquired confidential NSA hacking tools from an NSA employee home computer with their AV product installed in it.
It wasn't. I didn't renew the license and uninstalled it.
FFWD a couple years and my best friend upgrades his PC. Threadripper Zen 2, 128GB RAM, 2x NVME RAID 0 for the system, another NVME for stuff and HDDs for backups. System was incredibly sluggish and unresponsive and his extra NVME was sometimes dropping from the list of drives shown by explorer. Uninstalled his Bitdefender and all the issues disappeared.
It's just complete robbery at this point. Malwarebytes is a good product for example and Windows Defender is enough. But the best stuff is disabling all of these and just use script blockers and safe browsing practices and you get to keep all the processing power you paid for.
I run a big open source project and the amount of people that complain to us about BitDefender deleting our software is staggering.
https://www.av-comparatives.org/tests/real-world-protection-...
If we can keep the system up to date, configure the user privileges to lowest possible and grant access only when necessary, take backups as frequently as possible, segregate sensitive networks and most importantly educate the users not to run programs from suspicious sources, most if not all ransomware incident will not happen at all.
How would you prune data, say older than 1yr from the repo in-order to limit repo size?
So I immediately uninstalled their products from all my machines and now the very first thing I do when I receive a new machine is to remove pre-installed antivirus software and disable the damn Windows Defender. M$ now makes it really hard to disable Windows Defender completely...
Unless you plug it right into your company e-mail server or just hide it well enough to keep vulnerably-unadvanced users away - e.g. my elderly mother would hardly disable her antivirus if that required editing the registry or entering a long terminal command.
The “error” message tells the user the machine is being protected by Windows Defender…
For the rest, AV software results in diminishing returns.
Is this still a problem? I thought OSs don't execute stuff from flash drives automatically any more.
Of course, the concept of av is flawed because it takes them a few days to get new signatures out. I'd like to see more avs implement whitelists.
2000s : aid search for extra terrestrials
2010s : help search for cancer cures
2020s : help planet incinerating ponzi grifters (h/t: jwz)
Cancer research: some money
Crypto: more money
You're getting scammed.
I'd love to see the feds arrest a few people there and destroy the company.
Just remember. Don't ever hire someone with recent Norton experience I their resume. I'd sooner fill that gap in with the explanation that I was selling fentanyl laced products on the dark web
This is pretty ridiculous. I worked there and and there is much more going on internally than writing malware-like software. By the time I left they still had pretty decent engineers just trying to find a job in a better company, like me.
These sort of decisions don't come from Software Engineers and management there is known to be pretty shitty.
Also, it's not like they maliciously inserted this thing to mine crypto for Norton itself. Whatever your computer mines is yours (still a bad idea though IMO)
https://community.norton.com/en/blogs/product-service-announ...
It says you're joined to a mining pool. Is this a Norton 360-only mining pool? If so, I'm guessing they have their own hardware participating in the pool as well. And if that's the case, you're helping them mine for blocks just as much as you're helping yourself. But they don't say that anywhere so who knows.
edit: and it also appears that they're taking 15% of whatever you mine.
So they've apparently:
* Set up a Norton-only pool
* Joined all their customers computers to it
* Collect 360 subscription fees to participate
* Collect 15% of everything their customers mine
* Participate in the pool themselves, further benefiting from their customers mining activity
And what happens to the unclaimed/unused wallets that they're holding for their oblivious customers in "the cloud"? If I cared enough about this to read the fine print I bet I'll find that they're reserving the right to empty those after a certain period of inactivity.
For that matter: what happens when Norton gets hacked and loses the cryptocurrency they've been holding for their users?
Users must explicitly agree to a Norton Crypto License and Services Agreement and activate mining before the software starts mining Ethereum. It is unlikely there would be any oblivious customers.
See https://support.norton.com/sp/en/us/home/current/solutions/v...
When I install a pdf reader, I expect a pdf reader and nothing else. When I install anti virus software, that's the only thing I want.
that sentence doesn't exactly inspire confidence lol. So you're saying people are aware of the fact that they're partially writing malware like software and that's.. accepted? That's like an accounting firm saying "don't judge us like that, there's much more going on here than the money laundering"
No, but it is still malicious in the sense that it:
(1) does not inform the user or ask for consent
(2) seemingly does not offer an option to disable it
While I want to apply Occam's razor here, you'd have to assume all of the people that worked on this were negligent or unqualified... when sadly the more likely scenario is that these decisions were most likely intentional.
> (2) seemingly does not offer an option to disable it
Where do you see this? As far as I can tell, it is off by default, and the user must explicitly enable it (consent) to use the miner.
See e.g. https://support.norton.com/sp/en/us/home/current/solutions/v... which mentions a License and Services Agreement that must be accepted before the miner can be used at all, and clearly says the mining status can be toggled between Active and Paused.
(scroll to their follow up posts)
I don't have Norton, so I am unable to test this myself.
No, but the decision to work and continue working there does.
If "the decision to work and continue working there" is a bad one, that makes the decision to leave a better decision, yes? And the person who makes such a decision, a better person. And if you want to hire people who have agency and act with integrity, someone who left Norton is a slightly higher signal than someone who never heard of Norton, isn't it?
They joined in to a root comment reminding people to reject Norton employee resumes, by saying that Norton people who don't get other jobs are morally bad people and programmers are free agents who could get other jobs (by implication they would do so if they were morally good people). Under this worldview, leaving shows moral goodness so hiring them should be encouraged more than hiring a random person. Saying "nuh uh" isn't enough to wriggle out of it.
1. Pick a human at random, you have no information
about their character.
2. Hurting people is bad.
3. It is possible to unknowingly hurt people, which does
not reflect on moral character.
4. Learning that you are hurting people, and then continuing
to do so is morally bad.
5. Learning that you are hurting people, and then stopping
is morally better.
6. Therefore you have more information of good moral character
about someone who has learned that they are hurting people and stopped,
than about the unknown person in 1.
7. It is not reasonable to expect every job seeking person to know
about every company reputation, or the crypto miner management might
ask them to work on at some point in future.
8. Working at a company involves learning a lot more about what they do.
9. Learning that what they do is hurting people, and leaving,
is more evidence of moral goodness than you know about
an unknown random job applicant from an unknown previous employer.
Or, alternately if you don't disagree with any of those, perhaps you disagree with the idea that someone could work for Norton not knowing in advance they would be harming people, so that counts as morally bad. Then you either think "hire morally bad people" or you agree with the root claim "remember don't hire Norton programmers".If so, then you disagree with the parent commenter's "everyone has the freedom to get another job" because if nobody should hire them, they don't have said freedom.
1.Toxic hiring mentality. Unless someone is very high up, it’s just a job to them and they’re just trying to feed their families.
/s
Even if this was not currently criminal, this behavior appears inexcusable. The software engineers building this software lacked the ethical stamina to stand up and say "no" to their masters. They deserve an equal share of the condemnation and consequences for their participation.
Or rather, I would if this wasn't mostly FUD and blown out of proportion. According to other comments it's entirely opt-in.
I mean, that's a valid enough position to have, but I don't feel like you have really thought it through.
And I don't know what kind of standards public defenders in the US have, but over here it's common than an abuse of power by the police force is followed by a wave of resignations.
My point is that if we take a job like a public defender, I think most people agree that the action of what they're doing is a good thing. Providing representation to people who cannot afford a lawyer is (I think) nearly universally regarded as "good". However, they are paid by the US government, who has done its share of very evil things. Does that mean I should condemn a public defender because the entity that signs their paychecks does evil stuff?
Personally, I think the answer is "no". Any sufficiently large entity has its share of bullshit, and I personally do not think that every individual that has ever associated with that entity is guilty-by-association by working with them. You're welcome to disagree, of course, but I would be surprised if everyone you like passes your purity test then.
I see the point that you're getting at, and there's surely the line to be drawn here, and I think it's a question of scale – and the line is placed differently for each individual. I don't have absolutist views on this, and I probably wouldn't feel bad either, as a public defender in the example you bring up. I'd say public defenders are in the clear even if their state-employer also does bad things – since at least some of the things that they do are good and need to be done, like keeping people safe. I wouldn't say the same about Norton since they're one of many and if they went down tomorrow nothing much would really happen.
I don't think it's comparable to the IT industry though. Companies hugely care about their image, and poking holes in that image is an effective – or at least available – way to put pressure on them. Consider how much effort they're making to recruit people, and how heavily they rely on friends recommending their friends. "Your employees will leave and they'll discourage their friends from working with you" will work much better on a tech company than it would on a state that doesn't really compete with anyone else when it comes to public defense.
One's own conscience work similarly in this case. There's a long way to go from "I directly boost profits of a ruthless, replacable corporation" to the "I criticize the society and yet I participate in it" meme.
I always think it's an interesting juxtaposition because although the actions (in this case working for an AV company) are always so far removed from the extreme example, so too are the repercussions.
The "just following orders" soldier, had he refused to carry out his orders, or attempted to flee, would have been shot in the back for desertion. The penalty for following orders, or not following orders, is the same: death (at least in the canonical example).
Whereas with the situation being discussed here, it results in what? Maybe holding out for another job.
In the extreme we expect people to pay the ultimate price to prevent atrocities, which should serve to remind us that, in the everyday, we should engage our moral compass, endure a small hardship, and through that hardship, prevent a small amount injury from being inflicted on the world.
That appears to be opt-in. It's quite plausibly something people interested in crypto might actively want, namely a company they already do business with offering to make all the decisions about coins and wallets and stuff for a small fee. If a YC startup offered this, or it was added to the Dropbox client as an opt-in "let Dropbox make you some cash", people would love it. If Windows 11 or Edge included it, people would hate it. As an opt-in thing it's not a bad idea; not quit-your-job bad and certainly not "just following orders" Nazi trolling bad. It's Norton and AntiVirus's reputation which taint it.
"It is clear that nobody is implying a genocide is underway" - it at least implies that something strongly and obviously bad is underway that anyone with integrity should avoid. And that's not obviously the case either.
[1] https://community.norton.com/en/blogs/product-service-announ...
Most engineers on HN aren't solely developing for non-profits and charities, we're writing software for for-profit entities, and most of the really big for-profit entities are pretty evil (e.g. Google, Facebook, Apple, Microsoft, etc). It's not unreasonable to condemn people for working for these companies, but I think it's important to put into perspective the scale and intent of most of the people working there.
I guess I’m accusing the parent comment of hyperbole more than being “wrong”.
"no regrets" is an important part of this. though it's not quite the precise word i'd like, since your friends could well not regret their choice to stay given the circumstances you outline. what i want is for our culture to fight against antisocial behavior: to encourage the everyday person to give sufficient weight to social impact when making decisions.
"sufficient" is subjective, so as a starting point replace that with "non-zero" and i think we come out ahead: the toxicly selfish (or socially ignorant) are encouraged to behave at least mildly pro-socially, and the friends you mention who tried to leave evidentially gave non-zero weight to their social impacts -- even if they failed -- and would pass such a test.
the world is gray and i don't want a purity test. but that's not a license to ignore our social responsibilities.
I completely understand this sentiment and why you're approaching it this way, but I have to ask - what if the person with recent Norton experience is trying to get away, or got away, from them because they share your views about Norton? Would you just throw away the resume without a second thought, or would you at least be open to hearing about their thoughts working there?
Norton Employee: "I strongly disagree with how Norton operates and the kind of software we are installing. I feel shame. Here's why I would be a strong candidate for your company."
You: "I'd rather not even hear about it. Get rekt."
...?
No one is forcing you to install this stuff, I think Match is a horrible company which takes advantage of people, facilitates scams, on top of outright fraud .
I still recognize skill, if you told me you improved load times on Match.com by 60% I’d be very interested in hiring you. I wouldn’t personally work for any dating app or adult entertainment platform. But I have nothing against those who do.
Odds are no, I agree this is a disgusting tactic, but every company does bad things. If you work at say Starbucks, and some of the beans are being produced unethically, you're not a bad person for making lattes.
This would make it so the people there would be essentially forced to stay there?
It would, of course, also provide an incentive against beginning to work there, but, I still think other rules would better further your goals.
The fact is though that the easiest way for these companies to go bust is for them to lose all their competent employees. If someone working at Norton can't get a job anywhere else, no matter how good their qualifications, because they're on your blacklist, they're going to stick with Norton. That keeps Norton alive.
It's much better to accept that people are fallible, they make mistakes, and sometimes you join a company in good faith only for management to pivot, or the company to get acquired and questionable judgements to be made. It's important that developers and other employees at these companies are given an off-ramp when they decide the paycheck is no longer worth it.
Q: Will I be able to adjust the settings thresholds, or will Norton decide that?
A: For now, Norton will manage the settings. We are continuing to build capabilities and could potentially make the settings adjustable for you in the future.
Like, I know ~1.5m people still pay for AOL [1] but this is criminal.
[1]https://www.cnbc.com/2021/05/03/aol-1point5-million-people-s...
> Once earned, they can track their earnings in their Norton Crypto Wallet, which is stored in the cloud so it cannot be lost due to hard drive failure.
From https://community.norton.com/en/blogs/product-service-announ...
So your "earnings", meager as they likely will be, aren't even properly given to you.
Not to mention it seems unlikely that a consumer-grade machine is going to earn enough from its share of mining to cover the energy costs. At this point you have to have some kind of extra-cheap energy source to be able to compete in mining. Although some people (e.g. me) have a flat-rate electricity bill with their apartment, so maybe some could take some advantage.
> What platforms can I transfer the crypto to?
> Norton Crypto supports transfers of Ethereum from your digital wallet to Coinbase.
[1] https://community.norton.com/en/blogs/product-service-announ...
If it's bundled it's not really optional, is it?
This is beyond a scam at this point. Is that why closed-source anti-virus software is a scam as well since they can install any sort of malware when they want to or allow it to run without doing anything?
The anti-virus is the virus.
https://www.bleepingcomputer.com/news/cryptocurrency/hands-o...
+ It's opt-in
+ It's easy to use
- 36 hours of running it did not result in a "single penny" (see review for details, may have changed now)
- Uses 100% of the GPU capacity when the GPU is ~idle, with no way of adjusting the mining rate
- 15% mining fee
Edit: It would actually be nice if the PSU (and all of the various subsystems, like the GPU) were required to measure the power usage and report it to the OS. I'm sure one of those ATX pins could be repurposed to include signalling, somehow.
[1] from: https://community.norton.com/en/blogs/product-service-announ...
NortonLifeLock reported 21M customers in 2021, with 60% using Norton 360 (presumably the rest are using their identity theft products?) so let's call that 12.6 million computers (ignoring multi-computer licenses for simplicity.) You're not going to mine any Ethereum on a CPU, so let's assume we only care about GPUs. Let's say that 20% of users have a PC with a GPU suitable for mining any ETH at all, and within that 20% they have an average of 6GB graphics cards. The internet claims that a 6GB graphics card will average around 26 MH/s for Ethereum, which would have earned $38 in the last month of mining. Assuming Norton gets 25% of users to activate this (which seems high to me) we have around (25% of users activated)*($38 worth of ETH mined/month per gaming PC)*(20% of all PCs are gaming PCs)*(15% Norton pool fees)*(12.6M installed Norton copies) = 0.25*38*0.2*0.15*12.6 = $3.6 million per month, or $43.2 million in profit per year. If they enabled this for everyone I imagine they could easily get into the hundreds of millions of dollars of pure profit per year range.
However, mining on a mid-range graphics card typically isn't profitable once you factor in electricity and the decreased lifespan of the graphics card. So while this is making huge profits for Norton, it's likely costing the users money if they enable it. At $0.10/kWh and 15% pool fees, you're negative on the majority of gaming PCs, and deeply negative on every single non-gaming PC.
Pretty scummy move.
Norton keeps 15% of all Ethereum mining proceeds and "pays" the remainder into a users "Norton Crypto Wallet" which is hosted by Norton. It should be noted that the Norton Crypto Wallet cannot be used to make Ethereum transactions, but can only be used to transfer value to a Coinbase account once a certain minimum threshold of value is accrued. The Norton crypto mining and Norton Crypto Wallet are effectively a gift card system where the money can be withdrawn, but not unless a certain balance is available. It should also be noted that the Norton Crypto mining software is reportedly very difficult to uninstall, requiring administrative level privileges, and even then reports indicate effective removal is difficult.
[0]https://youtu.be/h92Jy94UxTg
[1] https://money.cnn.com/2014/01/07/technology/security/intel-m...
I've been on the Net for 27 years and this one of the best videos I've ever seen.
RIP John McAfee. You were a legend.
In the mid-1980s, PC Tools[0] was a worthy competitor to Norton.
Though I guess if it's a shortcut you don't see the actual filename too often. :)
A few months later they fell to a ransomware attack. The name of somebody they didn't know very well but recognized the name of had shown up with an attachment. I wondered if the AV product would have caught it.
Source: am NLOK employee.
Source: https://community.norton.com/en/blogs/product-service-announ...
https://community.norton.com/en/blogs/product-service-announ...
Norton AntiVirus now includes an Ethereum crypto miner that has several problems including deceptive rewards program and difficulty in uninstalling it.
Norton keeps 15% of all Ethereum mining proceeds and "pays" the remainder into a users "Norton Crypto Wallet" which is hosted by Norton. It should be noted that the Norton Crypto Wallet cannot be used to make Ethereum transactions, but can only be used to transfer value to a Coinbase account once a certain minimum threshold of value is accrued. The Norton crypto mining and Norton Crypto Wallet are effectively a gift card system where the money can be withdrawn, but not unless a certain balance is available. It should also be noted that the Norton Crypto mining software is reportedly very difficult to uninstall, requiring administrative level privileges, and even then reports indicate effective removal is difficult.
Kryptex.org comes to mind. The other month when BTC was at $60+k they were offering an exchange rate of low $50k. Basically a ~17% discount on the rate. That is a big fee, especially when you then ask to be cashed out to some other method they then charge 10-20% for (like USD bank transfers, etc).
Best bet is to install something like T-Rex miner, hook it to some pool and forget about it once you learn the 1 line bat file you need.
If you're stealing someone else's CPU cycles and you have a large enough base of PCs, it can be profitable.
> https://community.norton.com/en/blogs/product-service-announ...
As if AV software doesn't slow down PCs enough as it is, they thought adding a crypto-miner would be a good idea to finish the job and turn them into fully rated space-heaters.
At the risk of violating the site guidelines, I suggest you actually read the article instead of responding to what you assume it says.
I'd suggest you follow the site guidelines as well and comment to add value.
I've been running Linux or Mac since then, and due to their lower userbase there tends to be fewer viruses (as far as I understand it), but I would have to assume that Windows has gotten more secure and less virusey than it was 11 years ago? I don't think anyone I know even uses antivirus anymore. Maybe I'm mistaken.
All that said, I've thought Norton Antivirus was a bloated piece of shit piece of software even when computer viruses were a problem for me. I guess them installing a crypto miner is just further proof of that.
You can however "pause" the mining forever while keeping everything installed which is what support will suggest if you ask.
Just to clarify because this sentence sounds a bit misleading -- according to https://support.norton.com/sp/en/us/home/current/solutions/v... the cryptocurrency miner is off by default, so if you haven't turned it on, then there's no need to pause it if you don't want it running.
The support page doesn't have any definition of "opt-in". It simply says that users need to click under "Turn your PC's idle time to cash" and then accept a "License and Services Agreement" before they can access the "Norton Crypto dashboard" and enable "mining during idle time". I would consider that opt-in given that the user has to perform multiple steps before they can even enable the miner, and given that there isn't any suggestion to enable this by default during the installation process. If you don't consider that "opt-in", then please explain.
There seems to be a mob here that has been misled to think that the cryptocurrency miner is enabled by default and runs on every Norton user's computer in the background, whereas in reality it IS installed by default (as in the binary takes up storage space on the user's hard drive), but can only be enabled with multiple steps including agreeing to a separate services agreement that is dedicated to the Norton Crypto product.
(I still think it's dumb to bundle a crypto miner with an anti-virus product. But all this talk about it running without the user's consent is nonsense.)
This is a crappy thing to add to an antivirus program but there is no indication its enabled by default.
Yeah, it makes the software bloated, but if its not mining by default this is overhyped.
Source: am NLOK employee.
(yes I'm poking at apple for anyone who might be wondering)
https://community.norton.com/en/blogs/product-service-announ...
Their demographic is people who don't know better, and this whole thing reeks of illegal consumer exploitation.
(disclaimer: numbers totally made up, but I'm sure the average Norton user's computer isn't mining profitably)
If a virus is on your system it is already too late for the tool to do anything.
Cryptocurrency is cancer. It doesn't scale, it can't scale, it's becoming a huge unsustainable environmental disgrace, and it's the #1 reason why certain hardware is harder to find and overpriced, followed by energy, of which we have plenty but decided to waste it in mining farms.
Here are some numbers, just look at the trend: from 77 TWh to 204 TWh in one single year.
https://digiconomist.net/bitcoin-energy-consumption/
https://www.businessinsider.com/bitcoin-mining-electricity-u...
Now just picture what will be like 5 years from now with possibly one PWh of miners worldwide pumping heat in the atmosphere 24/7, and energy prices skyrocketing because it will always be allocated to this task, therefore demand will always be higher than offer. Seriously, WTF!
Of course I expect downvotes from users with vested interest in cryptocurrencies, however I politely ask others to reply with "You're wrong because ..." followed by a believable explanation. I want to be proven wrong on this.
As to your question - crypto is the new form of cash, different form every other forms we have known before. One exciting property is the relative independence from any particular economical or political system. Blockchain in general has potential to replace all middleman from lots of transactions. Think of property, fundraising, stocks, trade (especially overseas), etc. Specific implementations can be regulated by government(s), the point is to replace bookkeepers with machines.
Yeah, yeah, yeah, we've heard this like thousands of times. And yet crypto isn't being used like cash. Everyone is encouraged to "hodl" their crypto not spend it. It's being pushed as an inflation hedge like gold. Even most crypto folks don't seem to be pushing the "it's a new form of cash" narrative anymore.
The middlemen are now the core developers and the whales that own majority of the asset. Are you voting for the ETH merge? Or are you just along for the ride? You still pay fees to transact, I hardly see a practical difference.
One thing you're wrong about is that cryptocurrencies are in general mined using electricity and specialized hardware. Bitcoin is the biggest outlier in that respect, with its plans to continue their mining program permanently. Ethereum has the software to end their mining program (the "beacon chain"), which is currently finalized in spec and running alongside the original chain as they finish testing it before final release later this year (the "merge" event).
I always feel the need to nitpick here, as it's a common misconception that "most" cryptocurrencies are an environmental disgrace. Bitcoin is an environmental disgrace, Ethereum you could say is an environmental disgrace until they shut off mining later this year, but since the vast majority of cryptocurrencies don't use mining at all, it makes the most sense to target the ones that do rather than throwing the entire space under the bus.
I also disagree that cryptocurrency can't scale, as I'm intimately familiar with the work being done with transaction execution verification by zero knowledge proof (especially Ethereum's zero knowledge rollups), but that's a discussion for another time.
I'm also aware that I am in a comment thread about a company doing something very scammy in regards to crypto, so please try to distance my explanation from the disapproval we share towards Norton. Obviously I am not trying to defend Norton here.
> Bitcoin is an environmental disgrace, Ethereum you could say is an environmental disgrace until they shut off mining later this year, but since the vast majority of cryptocurrencies don't use mining at all
Can you please elaborate on that? If that's the case then I've to read a bit more on the subject as I thought every cryptocurrency required powerful hardware (GPUs or ASICs) under intensive load, which of course translates in huge power demands. The graph showing an almost 3x factor increase in power consumption in just one year looks worrying to me, however if you say there are other environment friendly means, that makes the matter interesting. What are however the chances that we can correct that factor in a immediate future?
Definitely not the case. That's the case for Proof of Work cryptocurrencies, but the vast majority of cryptocurrencies now are not Proof of Work but Proof of Stake. The only real stragglers are Bitcoin and Ethereum.
With Proof of Work, the chain's energy usage has nothing to do with load. It's literally because they couldn't figure out how to get the chain to work properly without making people burn large amounts of energy as a byproduct. Even when the chain is empty and nobody is sending transactions, that energy still needs to be constantly burned to maintain a Proof of Work cryptocurrency. Proof of Stake research (an alternative consensus mechanism that doesn't require this energy burn) wouldn't be complete and ready for production systems until many years later.
> The graph showing an almost 3x factor increase in power consumption in just one year looks worrying to me, however if you say there are other environment friendly means, that makes the matter interesting.
That's a graph of Bitcoin, the only top crypto that uses Proof of Work with no plans to transition away from it. So I think environmentalists should be focused on Bitcoin, not cryptocurrency in general.
- Aggressively mining crypto consumes enough system resources that most users would notice it and uninstall the software. (Norton may have an edge here because users are used to Norton making their systems performance worse)
- Even aggressive mining produces very little on the vast majority of systems (really need gaming GPU to make any money). CPU mining hasn't been economically profitable for nearly a decade: Norton probably makes <$0.001 per day on the median machine. Managing a network of chromebooks cryptomining would probably be unprofitable for Norton even if only accounting for the cost to Nortons systems. Norton's only hope of making profits from this is from the "whales" with the best machines.
- Multiple programs mining on the same system would split the rewards, drawing down value of such a system even further (unless they use tricks to monopolize system resources in a way that would make it even more noticeable to users).