500M Avira antivirus users introduced to cryptomining
krebsonsecurity.com
krebsonsecurity.com
This is absolutely bonkers. Most users are unlikely to even make back their electricity cost (arguments for space heating can be made, but not in summer), and paying out the minuscule sums is impossible due to transaction fees.
Hoping that somebody will sue this endeavor into oblivion.
There are people who reduce their overall bills by mining for both cryptocurrency and heating with the waste heat (instead of only one or the other). But it needs specific circumstances for that to be worth it, and I'm very sure Symantec is not advertising this concept in the first place.
None of this justifies making tech-illiterate people mine bitcoin for your own gain, of course.
As for longevity? Well, I don't run it at full capacity like that normally. The CPU is still going strong, 8 years in. I replaced the original 690s with a newer card because, better graphics, not that the cards went bad or anything. I have had issues with thermal shutdown due to bad liquid coolers, but no damage to the chips. But, replacing the cooler gets everything back and running again. I'm on my 3rd cooler.
Most of the heat isn't coming out of the CPU itself, but the power supply & the graphics card(s).
Wow, the power supply wastes that much electricity on its own? That seems very inefficient...
The electric heater that earns you money https://heatbit.com/
Crypto is also a hedge against local currencies as various country's, even the greatest nations can become unstable govt's very quickly.
Edit. It makes me wonder as the above has been downvoted, if this is why US cpu/gpu manufacturers are now disabling things that make mining crypto harder like Intel's AVX-512 and nVidia's changes to prevent GPU crypto mining, whilst using global warming as a straw puppet.
What you wrote, who bought who and why, is 100% incorrect. Even company relationships are wrong.
Sole intention part...this is simply made up, conspiracy style. Where do you keep pulling this from?
Get facts first, opinions second, or based on your logic, ideally never.
NortonLifeLock merged with Avast PLC in August 2021, with the combined company retaining the NortonLifeLock name.[2]
The Verge tried out Norton Crypto and found its 15% fee to be much higher than the 1-2% fee typically taken by mining pool operators. The tester broke even after (off-peak) electricity expenses, with NortonLifeLock capturing all of the profits.[3]
[1] https://investor.nortonlifelock.com/About/Investors/press-re...
[2] https://www.zdnet.com/article/nortonlifelock-and-avast-plc-t...
[3] https://www.theverge.com/2022/1/7/22869528/norton-crypto-min...
I stopped using AV software over a decade ago, haven't really encounter a malware so far.
A less technically-inclined person won't know, and will definitely end up exposed to malware. That's just reality for Windows users.
The key argument is that Windows's built-in antivirus is quite solid now. I don't know if (and I don't think that) a modern antivirus provides any -significant- additional protection over what comes with Windows by default.
[0] - https://www.avira.com/en/blog/illicit-mining-software-beware... [1] - https://www.avira.com/en/blog/crypto-miners-coinhive-malware... [2] - https://www.avira.com/en/blog/yes-your-device-can-be-hit-wit...
[1] https://www.instantmarkets.com/view/ID3116232555101294163817...
But now its likely an antitrust violation so that could be fun
It may be opt-in but there is just nothing good in it.
Most antivirus software itself has serious vulnerabilities. Adding cryptomining is the ice on the cake.
"Is Your Antivirus Software Spying on You?" https://restoreprivacy.com/antivirus-privacy/
"How to Compromise the Enterprise Endpoint" https://googleprojectzero.blogspot.com/2016/06/how-to-compro...
"Avast antivirus hole patched after public Project Zero slap" https://www.theregister.com/2015/10/06/google_zero_hacker_re...
"Still paying for antivirus software? Experts say you probably don't need it" https://www.nbcnews.com/tech/security/still-paying-antivirus...
If you're reading this article and thinking that antivirus software is a sensible thing to be running and thus wondering how they could betray users, you need to seriously revamp your computing environment. For most tasks that you need a trustable environment for, you want a modern OS that isn't based around agglomerating random binaries from arbitrary sources, whether that's something Free or just proprietary+curated+isolated (eg Apple/Android). And sure you can still keep MS Windows around for whatever purposes, but since it's no longer handling your sensitive activities you don't have to be hyperactive about the Sisyphean task of "securing" it.
> It looks like you’re running macOS, Linux, or another Unix-like OS. To download Rustup and install Rust, run the following in your terminal, then follow the on-screen instructions. See "Other Installation Methods" if you are on Windows.
> curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
Not having looked at it in a while, it is highly disappointing that Rust specifically has gone down this path on their main fucking page. "Old man yells at cloud", and all that.
IMO I think the future is distributed reproducible builds through Guix/Nix. I've never run Gentoo, but Guix/Nix feel like the best manifestation of software freedom that I've experienced. Mind expanding in the same way as functional programming or Lisp.
And of course none of that addresses the whole issue of source auditing and provenance. Immutable logs like git get us 90% of a foundation, but obviously there is a lot of unexplored territory required to provide actual security guarantees.
curl -L https://nixos.org/nix/install | sh
Unlike guix nix does not even have a way to verify package signatures because "it would hurt the workflow of these using the github webui to push stuff to nixpkgs"
I agree Guix has a much better story on foundational security (cf guix challenge). Nix seems to have more activity. Unfortunately, cancer spreads because it's good at multiplication.
But really my greater point is they're both source distributions revolving around persistent package/system management, which allow one to obtain software while managing the provenance of its code.
I know that many people disagree, and live their entire life on there, but for the same reason most hackers and governments and various "scurity" companies are gathering and hoarding exploits for them.
Sticking to good old desktop almost makes you invisible now days.
pouring_water_bottle_on_head_in_pool.jpeg
Sometimes it may be useful on a Linux machine, I've heard that hosts are being increasingly targeted
/s
And yes, I know there are some exceptions but lawyers are notorious for being tech illiterate
In the US, CFAA? I'm pretty sure that if I put in the fine print "I get to encrypt your files and hold them for ransom" I'd be going to jail too if I did it, fine print or not.
In Germany, I'd consider "theft of electrical energy" and § 263a "computer fraud".
But I really don't think CFAA would apply. They aren't holding anything hostage as far as I can tell. They're just saying something like "yo...since you aren't using your compute cycles we'll put them to work". Shitty and unethical, but still looking for the criminal v. civil part.
The law itself: "knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value, unless the object of the fraud and the thing obtained consists only of the use of the computer and the value of such use is not more than $5,000 in any 1-year period"
Since it explicitly mentions the value of the use of a computer as something that can be illegal to take, the main open question would be whether the $5000 of such use is per computer, or per crime.
Another option would be "(C) intentionally accesses a protected computer without authorization, and as a result of such conduct, causes damage and loss." if the electricity cost can count as "damage and loss".
Is NortonLifelock whatever charging a fee? Or does this refer to gas?
Looking forward to the follow-on story in a couple years about the IRS sending everyone who mined 10¢ a letter.
It seems that NortonLifeLock takes about 15% of whatever gets mined. In addition to that, you'd probably have to use and external service to sell your ETH (an other article I saw mentioned Coinbase as the only place where you can move your ETH from Norton) which Will charge its own fees and then there is the gas fee.
That is fucking infuriating. Imagine if the "my body, my choice" redirected to a "my computer, my choice" idea.
Would be interesting if you could throttle based on home temperature. I would much rather heat with useful computation than with electric heaters.
But why? An electric heat pump will be vastly more efficient.
But you know that it will be enabled by default by the packages they give to OEMs, or "accidentally" in every update or system restart, and will trick less informed or less technical users into enabling it and all sorts of shenanigans like that because that's how these av software companies have been operating for over a decade, at least in the home consumer space.
The only right away to treat these companies is to assume the worst about everything they say and do. Unfortunately they seem to always find a way to do worse than those assumptions. When "they will make a lot of money and/or screw over a lot of users" is the outcome of their statement being a lie, then you should assume their statement is a lie.
Heat pumps, which will pump outside heat inside, are a lot more efficient.
So, "computation for heat" is only useful to the point that it's replacing a space heater or other resistive heat, or is focused in a place resulting other heat use by a lot. So, my computer could be a cost-effective way to keep my feet cozy.
This also presumes that cryptomining is "useful computation".
The imperitive word that person on the forum post you quoted used is "hijacking" not intentionally and knowingly installing mining software.
No need to imagine; that's the central tenet of RMS's ethos and he's been shouting it from the rooftops for decades.