krinkle,
@krinkle@fosstodon.org avatar

Cryptominer Leverages Free GitHub CI

It's kind of obvious, given:

  • overpriced cloud server renting (GCP, AWS, ..),
  • increasingly heavy software ("just run these docker containers!"),
  • promise of free crypto "money".

People will use "Free" cloud hosting via Travis/GitHub/Circle and other CIs to run the most compute possible, triggered via random empty commits and such. This is the new normal.

https://sysdig.com/blog/massive-cryptomining-operation-github-actions/

LucasWerkmeister,
@LucasWerkmeister@wikis.world avatar

@krinkle Cryptocurrency has amazing “utility” in turning stolen CPU time into money. I mean, what would those scammers do in a world without cryptocurrency? Run BOINC?

krinkle,
@krinkle@fosstodon.org avatar

I've been wondering what it would take to create a decent Linux REPL on a webpage, backed by ephemeral "free" CI.

The page would need start with doing something that CI can react to. Could be OAth to comment on a GitHub issue, which count as CI events these days. The build would start by "finding" the waiting user, eg edit the comment, which the web page would poll, and then establish a web socket for the rest.

You'd want an asymmetric key so that only the initiator can talk to that build.

😄

  • All
  • Subscribed
  • Moderated
  • Favorites
  • infosec
  • slotface
  • kavyap
  • everett
  • Durango
  • osvaldo12
  • rosin
  • thenastyranch
  • DreamBathrooms
  • mdbf
  • magazineikmin
  • InstantRegret
  • Youngstown
  • ngwrru68w68
  • anitta
  • megavids
  • normalnudes
  • ethstaker
  • cisconetworking
  • tacticalgear
  • khanakhh
  • cubers
  • GTA5RPClips
  • provamag3
  • modclub
  • Leos
  • tester
  • JUstTest
  • lostlight
  • All magazines