Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So...doesn't this mean their website will start getting flagged as malware? Many security companies flag CoinHive as malware...


yes it's likely that these domains end up on some list.

E.g.:

   $ curl -s https://raw.githubusercontent.com/ZeroDot1/CoinBlockerLists/master/hosts|grep salon.com
   0.0.0.0 worker.salon.com


Yikes, you'd think a media company would be smarter than to use a software that returns hundreds of articles about malware as the top results of a google search for its name.


Salon is well known for some poor quality journalism/blogging. Not surprised to see that is reflected in their management/technology descions.


I had never really read anything from this site before and just searched it in Google News. Wow, you weren't wrong. And I'm probably THE target audience for that site (unabashedly leftist). It's very trashy.


Why would they care? They make money off of the ads, if you use an ad blocker, you just run up their server costs. Don't think they care.


Because your site showing up in other news outlets under a title like "Salon Magazine running cryptojacking malware on users" is terrible publicity.

I get that they are using the version which asks for consent, but why even take the risk of associating yourself with such a shady piece of software? If you make money of ads, you'd think you wouldn't want to do things that might scare away your users.


The software (script) itself is not malicious, it's the way it's used in a lot of cases. It's similar to how torrents are usually used for piracy, but has some legitimate uses.


Yes, I know that. But public perception doesn't really see it this way. It's more like torrent == bad && malware == bad


Many media companies doesn't think longer than their nose. Only thinks about money but not the impact the decisions they make.


CoinHive provides two miners: one which runs without asking the user, and one which requires explicit consent from the user.

The version requiring explicit consent is being used on the Salon website, and isn't currently being blocked by AdBlockers/malware detectors.


It is being blocked as some other commenters showed.

I think the company needs to shut down shop and provide their explicit consent miner under a different name because as long as anyone looking up your company's name can only ever find articles about your company providing malware, you won't be very successful.


It did. The new consent based miner is on and served from authedmine.com


I don't think you understood. The name "CoinHive" is essentially synonymous with cryptojacking. A name change and a refusal to pay out to anyone using the version which does not ask the user are probably good steps for them to take (but obviously they won't do either because $$$)




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: