Exploiting Github to Mine Crypto

แชร์
ฝัง
  • เผยแพร่เมื่อ 30 ก.ค. 2024
  • Try out OctoPart 👉 octopart.com/
    Altium 👉 www.altium.com/yt/seytonic
    0:00 Intro
    0:14 Exploiting Github For Crypto Mining
    3:46 Hacker Who’s Death Was Faked: Arrested
    7:33 Ransomware Frames Security Researchers
    10:04 Octopart
    10:40 Outro
    Sources:
    www.bleepingcomputer.com/news...
    sysdig.com/blog/massive-crypt...
    www.bleepingcomputer.com/news...
    github.com/features/actions
    therecord.media/crypto-mining...
    github.blog/2021-04-22-github...
    techcrunch.com/2022/08/25/her...
    therecord.media/github-invest...
    www.bleepingcomputer.com/news...
    www.justice.gov/usao-wdtx/pr/...
    www.theregister.com/2022/10/2...
    krebsonsecurity.com/2022/10/a...
    storage.courtlistener.com/rec...
    / raccoon-stealer-is-bac...
    www.bleepingcomputer.com/news...
    / 1586713979514224643
    ===============================================
    My Website: www.seytonic.com/
    Follow me on TWTR: / seytonic
    Follow me on INSTA: / jhonti
    ===============================================
  • บันเทิง

ความคิดเห็น • 338

  • @phaze7272
    @phaze7272 ปีที่แล้ว +256

    3:00 You can't just validate arbitrary transactions. The point is that you can revert transactions that have already been confirmed by crypto exchanges and thus "double spend" them.

    • @Seytonic
      @Seytonic  ปีที่แล้ว +68

      My bad, thanks for clarifying

    • @ahmedaghadi8281
      @ahmedaghadi8281 ปีที่แล้ว +4

      You can't validate arbitrary transaction even if you own 51% or more?

    • @mega4488
      @mega4488 ปีที่แล้ว +9

      @@ahmedaghadi8281 I'm pretty sure you can yeah I'm confused too

    • @ahmedaghadi8281
      @ahmedaghadi8281 ปีที่แล้ว +3

      @@mega4488 I mean if one own majority of nodes in a blockchain, he/she can hack it. That's what I know.

    • @mega4488
      @mega4488 ปีที่แล้ว +3

      @@ahmedaghadi8281 Thinking about it more, I think you can say "address X paid address Y Z amount" and validate that but you cant make currency appear out of thin air but yeah that would count as an arbitrary transaction no? or actually I'm pretty sure you would need access to their private key to do that so what the op was saying makes sense about only being able to redo transactions

  • @DrMxy
    @DrMxy ปีที่แล้ว +452

    Seems self-destructive for a botnet to allow installation of malware on its computers.

    • @Seytonic
      @Seytonic  ปีที่แล้ว +123

      They usually ban ransomware and other such malware from their “customers”, but it doesn’t stop people from using it anyway

    • @yung-megafone
      @yung-megafone ปีที่แล้ว +22

      The botnet owner (bot-herder) doesn't care, I would assume if they are selling "installs" that they have a fairly large number of computers (bots). The physical owner is the only person actually harmed in the process (Plus I guess the BN owner could lose that system but it's all about money nowadays)
      Seytonic is correct though, due to the possible loss of that bot, they tend to disallow malware installs like this because if the person becomes aware their system is hijacked they will reset and the bot-herder will lose that computer.
      Apologies for the short paragraph, just my .02
      I'll see my way out 🚪🚶‍♂️

    • @xoticxd
      @xoticxd ปีที่แล้ว +3

      Guys anyone suggest me course.. i want to learn botnet please

    • @privateger
      @privateger ปีที่แล้ว +20

      @@xoticxd
      1) It's illegal.
      2) Just asking is already such a massive opsec fail that makes it obvious you'd go to jail within months.

    • @yung-megafone
      @yung-megafone ปีที่แล้ว +6

      @@xoticxd first of all I hope you don't use that username across platforms because as the other person mentioned the process is highly illegal and opsec plays a major role in not getting caught.
      To answer your question though, first you should learn how networks operate and then how to gain access to systems over the air. Best way to start would be to set up a small network of your own and practice hacking into it (this method is completely legal because you own the systems you are attacking. From there you can use your skills to obtain access to other systems that you don't have permission to but as it was already mentioned this is highly illegal and I do not condone illegal behavior.
      Tldr: learn the fundamentals and then practice breaching your own systems. Not only will you gain skills required for offensive cybersecurity, you will also learn how vulnerable your home / test network is and discover methods to patch it.
      Edit: for legality sake I refuse to name specific courses but you are looking for offensive cyber security. If you really want to get skills, join the military and work with them doing cybersecurity. USMC MOS 1711 cybersecurity operations offensive is pretty good, you get top secret clearance which looks amazing on resumes, on top of the title Marine, if you're trying to get a job in this field but obviously you'll be red flagged doing so (both by asking malicious questions such as this one publicly prior to applying and once you have the clearance and have worked in the shop.{because at which point you know everything needed for the most part. Also, you kinda have top secret clearance so they put a spotlight on you}) there are also innumerable private sector firms who use offensive security. Godspeed!

  • @SIMULATAN
    @SIMULATAN ปีที่แล้ว +329

    The mining thing was inevitable, although I pray that they don't limit it because it's a great service when you use it legitimately

    • @Whatthellisthisthing
      @Whatthellisthisthing ปีที่แล้ว +47

      One bad apples spoils the bunch.

    • @FantasmaNaranja
      @FantasmaNaranja ปีที่แล้ว +31

      greedy people always ruin things for others

    • @filip9564
      @filip9564 ปีที่แล้ว +11

      Especially with the 100 000 : 160 ratio

    • @jomarcentermjm
      @jomarcentermjm ปีที่แล้ว

      @@Whatthellisthisthing yup

    • @asdfghyter
      @asdfghyter ปีที่แล้ว +22

      I really wish cryptocurrency didn't exist, for this reason. it's very existence causes immense harm to everyone, both through the wasted electricity and by making free CI tiers infeasible :(

  • @DillyzThe1
    @DillyzThe1 ปีที่แล้ว +119

    "this runs on github actions"
    i saw this coming 5 months ago when setting up workflows for my github game
    i easily & accidentally ran the game on the servers and had to manually terminate it, then talked to my friend about how bad that is in terms of github's VM security and could be easily exploited
    (i ran lime test instead of lime build)

    • @pacomatic9833
      @pacomatic9833 ปีที่แล้ว +4

      lol

    • @ThisNils
      @ThisNils ปีที่แล้ว +4

      well github gives you 2000 minutes for free and they don't really care if you're spending those to mine crypto or for actual CI/CD. so i wouldn't really call that "exploiting". the "exploiting"-part is when you're mass creating accounts to essentially get more minutes per month

  • @theWebmasterify
    @theWebmasterify ปีที่แล้ว +32

    The GH Action vulnerability was known for years, but Microsoft had always ignored it. There was a time where attackers would create PRs to opensource projects and abuse GH actions to try and grab credentials

    • @uziboozy4540
      @uziboozy4540 ปีที่แล้ว +3

      That's actually rather genius

  • @repatch43
    @repatch43 ปีที่แล้ว +18

    To be fair, they never actually said he died, only that he was no longer with them, considering he was in Amsterdam that tracks

  • @guyblack9729
    @guyblack9729 ปีที่แล้ว +31

    So you're telling me that for just 10¢ i can have bonzi buddy installed on some random person's computer?

  • @DiluteOxygen
    @DiluteOxygen ปีที่แล้ว +95

    The Captcha reminds me of this one time I was creating an account for some site and could get through the captcha and realised there was a report button beside the captcha that lets you bypass it by flagging it. Made me think of ways how this could be exploited.
    Edit: I think it was reCaptcha or hCaptcha, unsure

    • @BeamDeam
      @BeamDeam ปีที่แล้ว +4

      Probably hCapture

    • @marc-andreservant201
      @marc-andreservant201 ปีที่แล้ว +22

      I managed to score some GPUs using Playwright during the shortage, on a store that used hCaptcha. The trick is to install Privacy Pass in the instrumented Firefox browser being used. Then you go to another website that uses hCaptcha and they give you trust points for every correct captcha you solve. When the script tries to order a GPU, the hCaptcha service sees your cookie and lets you through without a captcha. This isn't a vulnerability per se, because they obviously intended that behaviour. The problem is when website developers think just including a little script will magically solve their bot problems.

    • @jeffbrownstain
      @jeffbrownstain ปีที่แล้ว +3

      Dang, ur a hacker, harry

  • @sheabrown
    @sheabrown ปีที่แล้ว +16

    They didn't really say that he died, they just said "loss" which is kinda fair given the circumstances

  • @infamyy
    @infamyy ปีที่แล้ว +18

    "The feds accessed it" I wonder how they did that...

    • @Skiman__
      @Skiman__ ปีที่แล้ว +6

      This is the only comment I see about this and idk why it’s not talked about more. This just proves that the three letter agencies have back door access to majority of tech companies. That prism surveillance stuff is after all true. This isn’t a good look for digital privacy which is diminishing day by day

    • @infamyy
      @infamyy ปีที่แล้ว +6

      @@Skiman__ I am a software engineer and have always considered creating systems that allowed for more privacy, but I just know it would be targeted/hacked or I would just be fucked with. Its truly hard to separate ourselves from our online presence and takes a lot of work to pull it off.

    • @Hyperus
      @Hyperus ปีที่แล้ว +4

      I thought so too. The fact that they can see which icloud an email address is connected to and, extending on that, access it is beyond fucked up.
      We are talking about monetary crimes here, the dude isn't even a terrorist and even then it should be a grey area.

    • @GrantGryczan
      @GrantGryczan ปีที่แล้ว +1

      @@Skiman__ It's not backdoor access; it's just a warrant. Companies are legally required to comply and give any data that law enforcement has a warrant for

    • @hydrophilicchristopher9874
      @hydrophilicchristopher9874 ปีที่แล้ว

      @@GrantGryczan They don't even provide warrants. All these companies just willingly give it away when asked for it lmao.

  • @mrhappytroll
    @mrhappytroll ปีที่แล้ว +46

    This channel makes me realize how big of an issue malicious hacking is

    • @DeadVoidzzz999
      @DeadVoidzzz999 ปีที่แล้ว +2

      And it's been ramping up lately too.

  • @Megabobster
    @Megabobster ปีที่แล้ว +4

    my hopium interpretation of that last malware is that someone had a few hundred dollars to burn and wanted to unplug some computers from botnets, maybe give people a hard lesson on security in the process

  • @sansmoraxz
    @sansmoraxz ปีที่แล้ว +37

    Imagine being infected by your own malware when you signed up to spread your malware through botnet forums.

    • @wladefant
      @wladefant ปีที่แล้ว +4

      They would least have the key 🤷‍♂️

  • @juniorjr.
    @juniorjr. ปีที่แล้ว +36

    Big oof for the Raccoon Stealer guy, almost got away with it but his girlfriend ratted him out on Instagram, guess you really can't trust anyone but yourself.

    • @chonkydog6262
      @chonkydog6262 ปีที่แล้ว +15

      I think they were already investigating his online identity before that.

    • @traviskemkeu
      @traviskemkeu ปีที่แล้ว

      Love hurts !

  • @proudpornaddict
    @proudpornaddict ปีที่แล้ว +8

    i don’t think they’re gonna launch a larger mining op for monero - i think they’re mining coins that are easier to mine that they project may increase in value. i also am not sure if they’re trying to gain control of a singular blockchain, either

  • @chrome1157
    @chrome1157 ปีที่แล้ว +12

    I find it odd that botnet owners let others install wiper malware for only a few cents. Those machines are then no longer part of it, so one can‘t sell another install. Keyloggers or other type of info-stealers can be put onto a machine several times, so that the botnet owner also earns more. How does this make sense? Do they charge more for wipers/ransomware?

  • @danhorus
    @danhorus ปีที่แล้ว +5

    9:45 wait, so you are saying people can pay botnet operators to run an executable that warns the victims saying that their machines are infected, or to run anti-malware, or even wipe out the entire botnet by taking the victims offline?

    • @matthewa158
      @matthewa158 ปีที่แล้ว +2

      I imagine these botnets have so many people, they just don't care if a couple thousand go offline. They're getting paid anyways.

  • @VaibhavShewale
    @VaibhavShewale ปีที่แล้ว +1

    damn, a news regarding hackers and other secret stuff!
    guess who got a new sub?

  • @duckph
    @duckph ปีที่แล้ว +19

    Damn there's always some crazy shit every week

  • @byrnesy924
    @byrnesy924 ปีที่แล้ว

    can someone point me to where i can find out about the >51% of mining allowing the miners to validate arbitrary transactions?

  • @amysakalov6915
    @amysakalov6915 ปีที่แล้ว +1

    I would imagine it's called Purple Urchin because the purple sea urchin is responsible for the destruction of kelp forests in California.

  • @AAABr
    @AAABr ปีที่แล้ว

    For a moment i tought "But the spiffing brit does comedy, not the naughties" and then I read the name of the channel, but now I'm invested in the video so win-win for me

  • @4.0.4
    @4.0.4 ปีที่แล้ว +14

    The takeaway here is that audio captchas are a vulnerability in their current form.

    • @sansmoraxz
      @sansmoraxz ปีที่แล้ว +1

      Google researchers a few months from now: Well most blind people do have good hearing, let's add as much random background noise as possible.

    • @mangoesareonsaleatcoles660
      @mangoesareonsaleatcoles660 ปีที่แล้ว +1

      @@sansmoraxz this is already happening with captcha’s, some even do things like “type out the numbers” with audio containing more than just numbers but phrases etc

  • @AreyouEventheLlama
    @AreyouEventheLlama ปีที่แล้ว

    This is cool to watch, nice video!

  • @jonan2199
    @jonan2199 ปีที่แล้ว +1

    the three coins on the 2:56 list I checked all explicitly stated that they are CPU minable. That seems to be the reason they mine them

  • @justinlee8328
    @justinlee8328 ปีที่แล้ว

    wow... that octopart ad is very relevant to me. Wouldn't expect that with this topic of video.

  • @ocelotmadness6287
    @ocelotmadness6287 ปีที่แล้ว +2

    Why was the racoonstealer dev extradited to the states? The US was not an involved country before that bit

    • @nabagaca
      @nabagaca ปีที่แล้ว +2

      I think theoretically, so long as any US computers were hacked by them, the US technically has the power to request extradition.

  • @IrishKingzz
    @IrishKingzz ปีที่แล้ว +2

    Seeing the name ChingLiu gives me so much nostalgia.

  • @GooseWithSaber
    @GooseWithSaber ปีที่แล้ว +1

    Nice video, you just earned a sub

  • @SASTSimon
    @SASTSimon ปีที่แล้ว +2

    I had always guessed it was possible to mine on github actions

  • @boxicool
    @boxicool ปีที่แล้ว

    Holy shit. What a good material!

  • @ruSEXtreme
    @ruSEXtreme ปีที่แล้ว

    9:43 Can someone explain what is meant by "buying installs"

  • @BrutalStrike2
    @BrutalStrike2 ปีที่แล้ว

    What is the website ?

  • @nictibbetts
    @nictibbetts ปีที่แล้ว +1

    Hi, I’m one of the lead developers behind the GitHub crypto test. Thank you for the video.

  • @cyberlord64
    @cyberlord64 ปีที่แล้ว +1

    Heroku could have at least offered a 1 time payment tier account instead of the free tier. Hackers are detected fairly quickly and they rely on recreating new accounts to keep going. The average guy would only pay once and keep using the low tier account for years whike a hacker would have to pay on a daily basis for thousands of new accounts making the process not worth it.

  • @kumiho42
    @kumiho42 ปีที่แล้ว

    Wow great video!!

  • @MUNNAYT
    @MUNNAYT ปีที่แล้ว +1

    I don't recall the last time I mined with actual equipment. I'll continue to use mining services and tech host farms. They are superior.

  • @benjaminb4476
    @benjaminb4476 ปีที่แล้ว +5

    Some CPU coins are basically 1:1 in cost and reward, sometimes being a little profitable. Every $1 "earned" or so, it would realistically cost GitHub $1 if there was enough research done.

  • @chaostrottel_hdaufdutube8144
    @chaostrottel_hdaufdutube8144 ปีที่แล้ว +2

    The german part of the note is also clearly google translated

  • @WistrelChianti
    @WistrelChianti ปีที่แล้ว +1

    Octopart sounds pretty useful. Especially the CAD models...

  • @ben9003
    @ben9003 ปีที่แล้ว +6

    I feel that it would be quite easy to circumvent this through a few requirements such as having valid phone number bound to the account. Many services and even games do this already such as mw2 and overwatch 2 though it would limit a few people who don't have access to valid phone numbers it would help to keep the free service to those who really need and benefit from it still using it.

    • @l0k048
      @l0k048 ปีที่แล้ว

      @@chonchjohnch well, it's a free service. don't use it or pay if you don't want to give personal information

  • @GoodGuyBiker
    @GoodGuyBiker ปีที่แล้ว +1

    wrong tho they are speculative mining because the returns in the short term as the gpu hashrate moves around will cause many of these to increase in value in relation to the hash power. No one going to mine monero on this setup its pure spec baby!

  • @DarkMetaOFFICIAL
    @DarkMetaOFFICIAL ปีที่แล้ว +1

    These are "shit coins."
    VERY PROFESSIONAL, MICHAEL

    • @TehObLiVioUs
      @TehObLiVioUs ปีที่แล้ว +2

      yep that's what crypto knowledable people call useless coins with no market cap

  • @Scootertuner420
    @Scootertuner420 ปีที่แล้ว +1

    I think just requiring a small payment of 20 cents to unlock could resolve that issue

  • @wheezybackports6444
    @wheezybackports6444 ปีที่แล้ว +1

    I'm not sure if they're using Monero Ocean or not to mine the shitcoins and get paid in monero. The coins these guys are mining I don't think are on MO, but they certainly could be since I have not checked the list in a while.

  • @hanro50
    @hanro50 ปีที่แล้ว +2

    It sucks that miscreants are ruining potentially a fantastic service for hobbiest developers for their own selfish gain.

  • @SibaNL
    @SibaNL ปีที่แล้ว

    Ahh yes, notorious hacker fleeing to the Netherlands. Nice move!

  • @Cookiekeks
    @Cookiekeks ปีที่แล้ว +1

    Google has a free cloud shell for every google account too. I wonder if they're absuing this

  • @albiceleste101
    @albiceleste101 ปีที่แล้ว

    5:56 they look like NPCs posed with Daz💀

  • @alrighty6898
    @alrighty6898 ปีที่แล้ว +1

    Is that AWS got rid of their free tier

  • @ifell3
    @ifell3 ปีที่แล้ว +1

    Hang on, is the data dumb email checker going to all the emails adresses on have I been pwned? Only because those checking may be next on the peep list.

  • @ENovaM
    @ENovaM ปีที่แล้ว

    20 years for cyber crimes? That is absolutely redic.

  • @ejonesss
    @ejonesss ปีที่แล้ว +1

    not only are they not getting gpu performance but they are only getting 14 gig ssd performance so they cant do much burst coin (if that is still a thing anymore)
    so either they are buying a bunch of instances or they are not mining on the servers but on the user end and using the servers for the crypto equiv to a bit torrent tracker to coordinate the machines.
    github can defeat purple urchin just by disabling the audio captcha.
    thats what i thought they are mining severe hail intercept team coins
    maybe instead of doing away with free services they could charge for crypto mining operations while giving compiling for free or make it not allowed for mining.
    they could also to help make mining more difficult have intel custom design cpus that dont have the aes support or make the servers run pentium or celeron cpus witch does not support aes.

    • @CZghost
      @CZghost ปีที่แล้ว +1

      The point is crypto mining is already most likely banned on such services, and major cryptocurrencies are even blocked so you can't mine them (Bitcoin, Ethereum, Monero, etc.), but they don't care about it being banned, and they chose those small cryptocurrencies in order to evade the block - and of course a bunch of bot accounts with spoofed IP addresses. Have the CPUs not have AES support is in my opinion actually a bullshit, because first of all, AES is an algorithm and has nothing to do with CPU architecture (they could simply implement it themselves as well), and in some cases you actually need to test out some cryptographic features of your programs, so they have to support it, unless they're willing to lose customers in favour of competition that does support it. CLI integrations and testing environments have to be built so it's possible to test almost anything. Crypto mining might be banned, but legitimate use of cryptography shouldn't.

    • @ejonesss
      @ejonesss ปีที่แล้ว

      @@CZghost is encryption part of compiling?
      if so maybe only allow the cyphers used for compiling encryption and block the others.

  • @Anakin.Skywalker44
    @Anakin.Skywalker44 ปีที่แล้ว +4

    These News Vids are epic ! Keep up the Good work !

  • @savagetheunicorn4555
    @savagetheunicorn4555 ปีที่แล้ว +1

    Oracle clouds services have an algorithm that detects mining and bans the account because its a violation of their aup.

  • @dawre3124
    @dawre3124 ปีที่แล้ว

    can they not make passport varification if you want to sue it for free? they dont have to check most, only if the account is suspicios

  • @OCER
    @OCER ปีที่แล้ว

    You can easily automate signup with Github API, so no need for browser.

  • @the_real_cookiez
    @the_real_cookiez ปีที่แล้ว

    This sucks! I have used Heroku free tier for ~3 years now, hosting one of my project sites on my resume. What chance I clicked on this video to find out I have just 2 weeks to migrate to a new PaaS. Ya'll know any good alternatives out there that still offer a free tier? Github?

  • @tyris-0001
    @tyris-0001 ปีที่แล้ว +4

    Thats a lot of events damn

  • @tuffiek
    @tuffiek ปีที่แล้ว +1

    Isn’t it a simple solution charge 1c per month for the free tier, then the task of the miner is multiplied into credit card fraud

    • @bennybroseph
      @bennybroseph ปีที่แล้ว +1

      You don't even have to do that, you just send a validation request on the card each month to check and see that it's still a valid and active card. I'm pretty positive Apple already does this for their app store. You need a real card even if you're just getting free apps.

  • @herogaca
    @herogaca ปีที่แล้ว

    Video created 9 days ago
    This was possible more than a year ago with free cloud computing like google colab, jupyter and similar cloud notrbooks

  • @edwardseverinsen5598
    @edwardseverinsen5598 ปีที่แล้ว

    Just wait. The dude from Racoon Stealers is gonna be released for cooperating with the NSA to bring down some crime syndicate. Chris Hemsworth will play him in the movie, there will be multiple scenes in which his oiled, toned abs are seen shirtless and he's typing away methodically. After the movie premier he will inevitably launch his own cyber security firm and sail into the sunset.

  • @rampage_sl
    @rampage_sl ปีที่แล้ว +3

    This is why GitLab runners require credit card details even in free tier.

    • @aak8297
      @aak8297 ปีที่แล้ว

      You can get unlimited cc for free and also try to generate the numbers

  • @shahzod6151
    @shahzod6151 ปีที่แล้ว

    Apple be like: We didn't give access to his apple cloud hehe😉

  • @youngblood6926
    @youngblood6926 ปีที่แล้ว

    Never use a email that is connected to anything ever

  • @xariyx9860
    @xariyx9860 ปีที่แล้ว +1

    Crypto miners ale the worst, i had free tier Oracle Cloud (which was quite good) and because of bots they started to randomly terminate accounts i cannot play Minecraft with friend bcs of that :(

  • @kcdiazWTV
    @kcdiazWTV ปีที่แล้ว +1

    They would mine $160 worth of crypto and will $500 to convert it to real money.

  • @anon_y_mousse
    @anon_y_mousse ปีที่แล้ว +3

    That's an amazing story. They could make a movie out of that one guy's life.

  • @SumanRoy.official
    @SumanRoy.official ปีที่แล้ว +1

    Proof of stake is the only way to mitigate this

  • @s-codes14
    @s-codes14 ปีที่แล้ว +1

    Best episode

  • @guestguest8278
    @guestguest8278 ปีที่แล้ว

    Dit is just get a fireship ad on a seytonic video?

  • @zyansheep
    @zyansheep ปีที่แล้ว +10

    2:43 monero is designed to be just as efficient to mine with a cpu as a gpu.

    • @chri-k
      @chri-k ปีที่แล้ว

      now i’m curious. what does it have you do to mine it?

    • @slonkazoid
      @slonkazoid ปีที่แล้ว +4

      monero is designed to be only efficient to mine with a cpu

    • @diablo.the.cheater
      @diablo.the.cheater ปีที่แล้ว +9

      @@chri-k You go to a iron mine, put a raspberry pi there, then you sacrifice a goat and power the raspberry pi with potato batteries, then you mine in github

    • @degenyakuza
      @degenyakuza ปีที่แล้ว

      @@diablo.the.cheater 🤓

    • @dsfs17987
      @dsfs17987 ปีที่แล้ว +3

      @@diablo.the.cheater don't forget the hack involving a blowtorch and some peanut butter to increase efficiency

  • @CrittingOut
    @CrittingOut ปีที่แล้ว +1

    Some points:
    2:16 there is no real "technical definition" (though, I think this is a joke) for coins mined with low profitability. The term "shitcoin" is relative to who is using it. Someone who is "invested" in bitcoin might consider all other cryptocurrencies a "shitcoin". Others might consider shitcoins to be coins that are essentially created to make the founders rich or those that put their efforts into enticing "investors" without actually providing any meaningful protocol features. Some people would consider every cryptocurrency a "shitcoin" for one reason or another. It's a subjective word that frankly sounds stupid.
    2:23 I don't see why you would need a test for this. Monero is mined by CPUs so if the goal is to make money they would just mine monero now instead of testing it on coins that might disappear the next day. The alternative explanation of attacking these low interest coins with a 51% attack seems more likely, though also quite pointless (from a monetary perspective) as there is no way to make a large transaction on a low interest chain since the market cap (and thus underlying assets) is too low in value.
    3:00 this is not true. Controlling 51% of the hashrate does not allow you to "submit arbitrary transactions" as this would imply a breaking of cryptography. Instead, this allows an attacker to "replace" the tail end of the chain with their own, longer chain, essentially voiding transactions made between. For example, an attacker decides on block 5120 that they are going to commit a 51% attack using an excess of hashrate. They silently generate proofs for empty blocks (or whatever they want included, doesn't matter much) and wait to release the chain. Then, on block 5150 or (insert number here) they release their version of the chain with more than 30 blocks, thus causing the consensus to ignore the "real" transactions between block 5120 and 5150 opting instead for the attackers chain containing nothing in-between. This basically reverses everything done between blocks 5120 and 5150 by users. However you will never be able to spend (create a cryptographic proof) for coins your wallet does not own unless the underlying cryptography scheme itself is flawed and allows you to derive private keys from public keys.

    • @MaakaSakuranbo
      @MaakaSakuranbo ปีที่แล้ว

      Isn't the point that you'd insert transactions to your wallet, so now your wallet does own them?

  • @sageosoro1703
    @sageosoro1703 ปีที่แล้ว +1

    How has using github to mine crypto become illegal? That doesn’t make any sense

  • @rayyni7257
    @rayyni7257 ปีที่แล้ว

    It's also possible for creating botnet that u can use to ddos bruh

  • @jim22444
    @jim22444 ปีที่แล้ว +4

    If only bad actors learned about OPSEC... Pretty ironic

  • @rainerzufahl
    @rainerzufahl ปีที่แล้ว +4

    regarding the racoonstealer part: you seem to have glossed over the "the fbi accessed his iCloud account" bit. what do you mean they "accessed it"? isnt that data supposed to be encrypted? protected by apple, if not tim cook himself? dont they advertise with "your data is your data alone" for years now? what the hell happened there???

    • @see_yl
      @see_yl ปีที่แล้ว

      I can only imagine Apple complies with data requests considering fraud, terrorism and such.

    • @Matia.s
      @Matia.s ปีที่แล้ว +3

      hahaha, apple has private keys to decrypt your files

  • @soundrogue4472
    @soundrogue4472 ปีที่แล้ว

    What doesn't make sense is, why not make users wait before they can USE YOUR SERVICE!

  • @Reeces_Pieces
    @Reeces_Pieces ปีที่แล้ว +1

    It's always a gmail account that gets them huh?

  • @cheedozer7391
    @cheedozer7391 ปีที่แล้ว +2

    Love these man! Crazy stuff this week.

  • @neyo231
    @neyo231 ปีที่แล้ว +1

    Damn they gonna ruin free features for the rest of us

  • @PranjayMittal
    @PranjayMittal ปีที่แล้ว +1

    This is why we can't have nice things

  • @gangsterism
    @gangsterism ปีที่แล้ว +2

    simply blacklist all vpn ip addresses from using the vm feature

    • @chri-k
      @chri-k ปีที่แล้ว +9

      this isn’t a good solution. it could work as a temporary fix though.

    • @MaakaSakuranbo
      @MaakaSakuranbo ปีที่แล้ว +1

      and keep blacklisting all new VPN IP Addresses, and Tor, and AWS, and...

  • @SirusStarTV
    @SirusStarTV ปีที่แล้ว

    1:16 there's no longer free tier on Heroku lol

  • @thaphreak
    @thaphreak ปีที่แล้ว +1

    that taiwan is china bit... was meant to throw you off. "oh it must be china" ...prolly not.

  • @green_beard
    @green_beard ปีที่แล้ว +1

    I kinda hate those guys.
    How they have the brain muscle to find such ways and I don't ?!
    wtf ? sucks af to get older, even that I'm not OLD, I'm no more 10 or 14

  • @trixer230
    @trixer230 11 หลายเดือนก่อน

    Purple Urchins are taking over the ocean floor.

  • @hwtw
    @hwtw ปีที่แล้ว +3

    Taiwan Is NOT China BTW

  • @PushyPawn
    @PushyPawn ปีที่แล้ว +2

    The 'Ransom note' is obvious Chinglish.
    The whole thing is written by a native mandarin speaker, the *distinctly Chinese way* bad grammar, is a dead giveaway.

  • @addyhadmelike655
    @addyhadmelike655 ปีที่แล้ว +2

    to be fair, the phrase "no longer with us" is just being misconstrued here

    • @MaakaSakuranbo
      @MaakaSakuranbo ปีที่แล้ว +1

      Eh, it's often a tactful way to say "someone died"

  • @In_swedish_the_jam_means_sylt
    @In_swedish_the_jam_means_sylt 11 หลายเดือนก่อน

    It amazes me how people are on top of everything, any new feature or service and they flock to abuse it 😂 i love it

  • @truegodaries
    @truegodaries ปีที่แล้ว

    How do I request the data that was stolen by Racoon Infostealer? I put in my email and it said my data is in the info law enforcement has.

  • @shareb1t
    @shareb1t ปีที่แล้ว

    i thought feds dont have access to icloud rip

  • @methos1138
    @methos1138 ปีที่แล้ว

    How about a video on how to make your own flipper zero?

  • @onevoltten7352
    @onevoltten7352 ปีที่แล้ว

    It's pretty dumb these services don't just use the Google's reCAPTCHA v2 service instead of their own captcha system, it'd be so simple to implement too.

    • @KeNNyTuber
      @KeNNyTuber ปีที่แล้ว

      reCAPTCHA v2 can be easily resolved by many bots.

  • @melkenhoning158
    @melkenhoning158 ปีที่แล้ว +1

    8:58 What a hilariously obvious false flag. This had to have been done by enthusiastic non-state actors because if that was done by Russia or China, that would be embarrassing, even for their standards.

  • @timovc5340
    @timovc5340 ปีที่แล้ว

    8:55 The german text is almost nonsense :D
    Just translated each word to english without thinking about the grammar differences between languages

  • @MatiEP09
    @MatiEP09 ปีที่แล้ว

    4:48 as far as i know chingliu is safe on thepiratebay

  • @mohamed_musthaq
    @mohamed_musthaq ปีที่แล้ว

    I literally had this idea, why didn’t I do it…..

  • @kalebbruwer
    @kalebbruwer ปีที่แล้ว

    It's pretty funny that this hacker managed to cheat and bribe his way all the way to Amsterdam, but he couldn't convince his girlfriend _not_ to document the trip on Instagram. I'm guessing she didn't know about his career choices, because surely no one is _this_ stupid