question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

False positives for crypto mining

See original GitHub issue

https://coinhive.com/ and https://cnhv.co/ should not be in the Unified hosts list because it’s not malware neither adware.

Please don’t be like Easy List.

Issue Analytics

  • State:closed
  • Created 6 years ago
  • Comments:11 (7 by maintainers)

github_iconTop GitHub Comments

1reaction
ScriptTigercommented, Dec 16, 2017

@vitorgatti, are the below snippets accurate for the domains you have listed?

https://coinhive.com/: Coinhive offers a JavaScript miner for the Monero Blockchain (Why Monero?) that you can embed in your website. Your users run the miner directly in their Browser and mine XMR for you in turn for an ad-free experience, in-game currency or whatever incentives you can come up with. grant video streaming time; offer files …

https://cnhv.co/: Proof of Work Shortlinks. If you have an URL you’d like to forward your users to, you can create a cnhv.co shortlink to it. The user has to solves a number of hashes (adjustable by you) and is automatically forwarded to the target URL afterwards. Example: cnhv.co/6bk (this just forwards to the Monero article on Wikipedia).

If they are accurate, these are not false positives according to this repository’s current mission statement. If you would like to rebuttal this, can you please contain a link to your current website implementing these scripts which clearly contains or links to a proper terms of use making your users aware of crypto mining occurring on your website and your current policy regarding it? I am sure you can understand our reluctance to allow domains that contain crypto mining scripts since the vast majority of people who implement them don’t come with a terms of use or end-user agreement or any kind of policy or opt-in/opt-out features, which encroaches legalities in many jurisdictions. Google Ads are 100% legal and legitimate, and this repository still chooses to block them because that is part of the mission statement. I hope you can understand our position and I do look forward to hearing your feedback.

1reaction
ScriptTigercommented, Dec 16, 2017

@StevenBlack, have you taken a look at EasyList? At first glance its structure would seem different, but there are also some strong similarities, as well, to your repo in various places.

@vitorgatti, out of curiosity and for clarification, you would not like this list to be like EasyList in what way? I don’t personally have any experience with it, so I am genuinely curious of your thoughts on it. And is this issue at all related to your other recent issues related to your own pool (https://github.com/Snipa22/nodejs-pool/issues/139, https://github.com/Snipa22/nodejs-pool/issues/199, https://github.com/monero-project/monero/issues/2855)? Steven will also want to know how you have verified your listed domains no longer contain mining scripts. And thanks in advance, I hope you understand we just like the list to be as efficient as possible, which requires us to be thorough in some aspects.

Read more comments on GitHub >

github_iconTop Results From Across the Web

A 'false solution'? How crypto mining became the oil industry's ...
Climate experts warn that plans to repurpose waste gas is not a solution, but more like placing a Band-Aid over a gaping wound....
Read more >
Prisma Cloud Compute: Crypto-minor false positive detection
The Prisma Cloud compute is reporting false positive regarding the crypto-minor packages that is expected.
Read more >
IDS detecting Bitcoin Mining activity. - MyZerto
Our reseller has had a look and reports back that it is a false positive. I am curious if anyone else has seen...
Read more >
An In-depth Look into Drive-by Cryptocurrency Mining and Its ...
We discuss how relying on each of these artifacts alone can lead to both false positives and false negatives, and therefore correlate our...
Read more >
What To Know About Cryptocurrency and Scams
Scammers list fake jobs on job sites. They might even send unsolicited job offers related to crypto like jobs helping recruit investors, selling...
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found