You may need permission to execute a script that uses the site viewer's CPU power for mining


byBureau of Land Management

About the script "Use the CPU power of site viewer for mining virtual currency" which is found around September 2017, it is currently executed only by accessing but this type of script in the Chromium Project Changes to the form requiring permission to execute are under consideration.

Google Chrome May Add a Permission to Stop In-Browser Cryptocurrency Miners
https://www.bleepingcomputer.com/news/google/google-chrome-may-add-a-permission-to-stop-in-browser-cryptocurrency-miners/


In September 2017, at the popular torrent site "The Pirate Bay"It is discovered that a script to use for mining virtual currency is embedded without permission of viewer's CPU power.

Subsequently, one of the three largest networks in the US · CBS's pay program distribution service "SHOWTIME"Similar mining code is embeddedIt was found.

At any site, what was being used was a "Coin Hive" script that could receive revenue by providing CPU power for mining.

In response to this trend, Google engineer Ojan Vafai, who is involved in The Chromium Project, an open source web browser development project, said, "In sites that use more than a percentage of CPU over a certain period of time, Saver "mode to positively suppress the task, completely stop the task execution when the" Battery Saver "mode tab turns to the background," Require permission to execute at abnormal trigger " We proposed adding function.

However, Mr. Vafai 's proposal has not been approved yet, and discussion has been repeated.

As a suppression measure of the script, there is a concept of blocking JavaScript code for mining at the browser level via blacklist, but Google reports "Impractical" in the middle of September bug report. Engineer Adam Langley said, "In order not to block fingerprints and computational patterns, only blocking certain script loads will only change the code this time."

In Bleeping Computer, as a "countermeasure" for the time being at Google Chrome "AntiMiner"No Coin"minerBlockThe use of extended functions such as "I will use it."

in Software, Posted by logc_nt