uTorrent Quietly Installs Cryptocurrency Miner 275
New submitter Eloking sends news that uTorrent, a popular BitTorrent client, is silently installing cryptocurrency mining software for many users.
[uTorrent] brings in revenue through in-app advertising and also presents users with “offers” to try out third-party software when installed or updated. These offers are usually not placed on users’ machines without consent, but this week many users began complaining about a “rogue” offer being silently installed. The complaints mention the Epic Scale tool, a piece of software that generates revenue through cryptocurrency mining. To do so, it uses the host computer’s CPU cycles. ... The sudden increase in complaints over the past two days suggests that something went wrong with the install and update process. Several users specifically say that they were vigilant, but instead of a popup asking for permission the Epic Scale offer was added silently.
Why uTorrent? (Score:5, Informative)
For something as important and risky as BitTorrent, why would you use a proprietary client?
Re:Why uTorrent? (Score:5, Insightful)
It used to be great. It did exactly what you needed it to do and no more. Now it is a bloated mess like Azureus/Vuse. Now when I load UTorrent, my Windows machine slows down so much it is unusable. It loads gigabytes of ads per day. I have ISDN at home right now, and if you let it run 24/7, you can still download a surprising amount of files. That is except with the new version of uTorrent. It makes the ads a higher priority than BitTorrent so your files take days or weeks longer than they should.
Re:Why uTorrent? (Score:5, Informative)
Exactly. It was great but not anymore. Either use an old version that had no advertising or switch to something else like qBittorent.
Re: (Score:3)
Exactly this. The best version was the last one before they were bought out. I still use 2.2, that version had NO advertising, and was written well before the cryptocurrencies came around.
Re:Why uTorrent? (Score:5, Interesting)
Wow. I was a little skeptical, but my download speed nearly doubled after downgrading to 2.2.
http://www.oldversion.com/windows/download/utorrent-2-2-23071 [oldversion.com]
How is this post a troll? (Score:4, Interesting)
Torrent used to be great. It had over 100 million users and was the most popular client for years. I remember the first version fit on a floppy, and you could xcopy install it. It was awesome. I did a test of different BitTorrent clients for a PC magazine, and Torrent won easily when it came to download speeds. It beat Vuze, as the poster I'm replying to mentioned, by more than 30%.
It was small and fast. It did everything you need. Now it is bloated and too slow to leave running when using your computer. Also, it wastes tens of megabytes of bandwidth per day downloading animated ads plus it uses so much CPU to show the ads that it overheats my new Dell laptop. The guy above exaggerated with this gigabytes claim.
So why was this guy marked a Troll? He is correct. Do we have a Torrent fanboi with mod points?
Re: (Score:2, Insightful)
Wow /. dropped the mu. Add a mu before Torrent everywhere in my post. Why doesn't /. understand Unicode in 2015? This is sad.
Re: (Score:3, Insightful)
Do you really want a Slashdot full of Zalgo, emojis, and Japanese character art?
Re:How is this post a troll? (Score:5, Funny)
Unicode on Slashdot (5:erocS) (Score:5, Interesting)
Why doesn't /. understand Unicode in 2015?
Past abuse of bidirectional override control characters to spoof comment scores. Details [slashdot.org]
Re: (Score:2)
Why are you using any version above 2.2.1?
That was the last real version.
Re: (Score:2)
Why are you using any version above 2.2.1?
Came here to say exactly this.
After seeing what version 3 looked like on a friend's computer (code isn't the only thing that got bloated with crap) and reading about the hassle people were having with advertising, user-hostile admins, and finally seeing uTorrent get bought out, I'm glad I never bothered to update past 2.2.1. Some private trackers even block 3.x.
I've also heard good things about Deluge, so if I'm ever forced into updating I'll probably give that a try.
Re:Why uTorrent? (Score:4, Informative)
Re:Why uTorrent? (Score:5, Informative)
Ads? What ads? Am I the only one who messes with settings?
Options->Preferences->Advanced
offers.left_rail_offer_enabled=false
offers.sponsored_torrent_offer_enabled=false
I'm sure you should change these settings at your own risk. But it was worth the risk to me.
Re: (Score:3)
Re:Why uTorrent? (Score:5, Informative)
Ads? What ads? Am I the only one who messes with settings?
Options->Preferences->Advanced
offers.left_rail_offer_enabled=false
offers.sponsored_torrent_offer_enabled=false
I'm sure you should change these settings at your own risk. But it was worth the risk to me.
Ads I could deal with (disabling). The problem is going to upgrade to a new version (when offered), you have to be extremely careful when installing to disable all the shitware. What broke it for me was missing the checkbox for conduit once. Conduit hijacks your home page and search engine, and is very difficult to remove. That was it. I stopped using uTorrent after that. Currently I use qBittorrent.
It's irritating enough to deal with the useless bundled shitware during installation, it's even more irritating to have to carefully opt out of everything when installing an upgrade. Adobe Flash / Reader, and Java are bad at that as well.
Re: (Score:3)
you downloaded utorrent from cnet. utorrent doesn't install conduit. Stop with the bullshit,
uTorrent, at least at some point in time, did offer Conduit with the installer from their website. Here is a post from a moderator on the uTorrent Forum:
http://forum.utorrent.com/topi... [utorrent.com]
We are among many products that support the production and distribution of our free software through advertising. In cases where an advertisement is for an installed product, our requirements include: 1) The user must accept the offer; 2) The user must be able to easily revert to a state prior to the offer install. We also offer a premium product as an ad-free option.
You may have inadvertently accepted an offer from one of our partners during your installation of BitTorrent/uTorrent or when updating to the latest version of our clients. If that’s the case, don't worry - here are some easy instructions for reverting to your original settings.
PC Users
If your home page and default search was changed to Bing you have Conduit Search Protect. If it changed to Yahoo then you have installed software from Spigot. See the instructions below based on which search engine you are seeing.
Conduit Search Protect
Conduit Search Protect is one of the offers PC users can receive. To remove Conduit Search Protect and revert to your original settings, follow these steps.
In the Windows control panel, go to uninstall a program. Look for “Search Protect” by Conduit and select Uninstall.
When the uninstall dialog box appears, simply check the “Go back to my original home page and default search settings” box at the bottom, and then click Uninstall.
Your default search engines will revert to their original settings.
Spigot
First, go into the Windows Control Panel and select UnInstall a Program or Add/Remove Programs. Locate and uninstall Spigot Search Protect. Then revert each affected browser back to your desired homepage and search engine settings with the following steps.
Chrome
In Chrome you can set the default search engine, home page, and new tab behavior on the Chrome Settings page. For more info, see these links:
Set your default search engine
Set your homepage
Set startup preferences (including new tab behavior)
Firefox
Set your Home Page
Set your New Tab page
To change the default search engine in Firefox, simply click the icon next to the search box and choose your desired site.
Internet Explorer
The method for changing your settings will vary depending on your current version of Internet Explorer. Follow these links to view instructions on Microsoft’s site.
Change your Home Page (you can select your version of IE via the tab to the right of the page)
Change your default Search Engine
Change your New Tab settings
Mac Users
Mac users can revert to their original settings by uninstalling the Searchme extension from each affected browser and then resetting the homepage manually. For more info, please view these detailed instructions.
Safari
Under Safari’s Preferences menu, select Extensions.
Locate the Searchme extension and select Uninstall.
Go back to the General Preferences tab and select the Default Search Engine and Homepage you would like to use.
Chrome
Under the Window menu, select Extensions.
Locate Searchme and click the corresponding trash can icon.
Once the extension has been removed, open the Chrome menu and select Preferences.
On the settings page that appears, select the homepage and default search provider you would like to use.
Firefox
Under Firefox’s Tools menu, select Add-Ons.
When the Add-Ons page opens, click Extensions.
Remove the Searchme extension.
To revert your search engine, simply click the search engine icon next to the search box and select the provider you wish to use.
To revert your default home page, open the Firefox menu, select Preferences, and select the General tab. Here you can select the home page you would like to use.
Deluge (Score:2, Informative)
Try Deluge. It is everything uTorrent used to be.
Re: (Score:3)
Deluge likes to use random ports
Edit->preferences->Network, uncheck "Use Random Ports" and it will let you specify a port range, old-school style.
Re:Why uTorrent? (Score:5, Informative)
I saw the writing on the wall years back. I posted an bug in the official bug forum, and the thread got locked in less than 5 minutes with a complaint that I didn't search. Except I did search. The first line of my post was even, "I searched, and while I found a similar bug, this one is actually different," and went on to explain why. Mine dealt with default column sorting (column A ascending, column B descending), theirs dealt with default column order (changing columns A, B, C to B, A, C). There was no similar request. It was locked so fast, the mod couldn't have actually paid attention to it. Alright, that's kind of stupid, but whatever.
About half an hour later, I was in a post and made a comment on a different bug. This one was about interface layout, but it seemed to me like there was confusion going on about what the bug was, so I made an image with arrows describing the issue rather well (IMO) since I was able to replicate it. 5 minutes later, my post was deleted and my account was banned. No reason given.
Contribute to community? Get told to fuck off. I've never encountered such blatant hostility to your own community before, and knew immediately that whatever uTorrent was doing wasn't worth my time. I was so irritated that I uninstalled uTorrent immediately and a found another client even though at the time they were all significantly worse (I started with Transmission, when was just getting popular on OS X, then Deluge, still in beta, then eventually qBittorrent where I've stayed since 1.x days). I didn't even wait for my current torrents to finish downloading or seeding. I have never and will never use any software from that company ever again under any circumstances. They're below Oracle. They're below Symantec. They're below Pearson. I'd install BonziBuddy before uTorrent. It's been a secret pleasure of mine watching those fuckers crash and burn over the last several years.
Re: (Score:3)
It's stable as hell, offers a guaranteed bit rate (albeit not that fast by modern standards), and is available just about anywhere in the USA. Mind you, what's a full T1: One form of it is 24(?) ISDN lines bonded together. I was on a 128k ISDN when I lived with the 'folks, as there was no DSL/Cable/Whatever. I torrented the hell out of that connection. Sure, it took some serious time to pull down a .iso of a movie. But it worked. It *always* worked.
Re: (Score:3)
For something as important and risky as BitTorrent, why would you use a proprietary client?
Glad I ditched it in favour of Tixati months ago.
Re:Why uTorrent? (Score:5, Interesting)
Kicks uTorrent's butt in every way.
If you are too lazy to switch to a better client after it becomes rubbish then YOU are the problem, not them.
Choice is only meaningful if you can and will exercise it....
Re: (Score:2)
Re: (Score:2)
JK.
Re: (Score:2)
I run transmission on my WD MyBook Live hard drive (it's got a linux variant on it), and connect to it using the desktop client. I cue up whatever I want it to DL, then I can power off my desktop, and let the hard drive (network attached) DL the torrents. My XBMC client(s) just serve the content up from there. No bloatware, no ads, no hassles.
Worth it? (Score:5, Insightful)
Re: (Score:2, Insightful)
At scale, a world wide army of CPU's will easily crush an ASICs. Mining is about number of hashes per second, one system is slow, an army of misappropriated systems will be very fast.
Re: (Score:3)
At scale, a world wide army of CPU's will easily crush an ASICs
A million CPUs can crush a single ASIC, yes, but people are running warehouses full of ASICs.
Re: (Score:2, Insightful)
A million CPUs can crush a single ASIC, yes, but people are running warehouses full of ASICs.
And if they're paying for the space, and the electricity, my army of stolen mining machines is still more profitable. "Anything stolen is pure profit."
Re: (Score:3)
Depends on how much work was involved, and how big your army is.
Re: (Score:2)
Re: (Score:3)
Re: (Score:2, Informative)
After the suggestions that Tor was owned by the government, and the attacks against the Pirate (Bay) community, I'm rather surprised there's still an army of people running torrent clients.
Do not confuse the Tor network with Torrents. They are not related.
Re: (Score:2, Insightful)
The conclusion of your reasoning isn't to be "surprised", but to deduce that they're probably mining a cryptocurrency other than bitcoin.
Re: (Score:2)
Re: (Score:3)
It would still be worth mining bitcoins, if somebody else was paying for the electricity.
Re: (Score:3)
Re: (Score:2)
parent anonymous poster should be upvoted - GP makes an assumption that it's mining Bitcoins, and not some altcoin.
I don't think anybody's analyzed it yet just what coin, if any, it mines - the list of things it's associated with include other potential for monetization.
Another piece of software to uninstall (Score:5, Insightful)
Time to abandon utorrent. In fact, time to abandon all software who's owners bundle in adware/malware/anything-other-than-the-program-the-user-is-trying-to-install.
The only way this practice will stop is if users refuse to download and use software that does this.
Re:Another piece of software to uninstall (Score:5, Funny)
If only we have software that we could trust, that we could see the code. And that when one vendor starts doing this, we'd be free for forking the project and making one without the bundled spyware. We could even come up with a license that protects this code, and ensures that everyone that forks the project has to respect the liberties of the user in the same way.
Ohh well, I guess one can just dream
Re: (Score:3)
That's necessary, but not sufficient. Even Free Software can get bundled with malware if you don't obtain it from a reputable source (e.g., the first-party website or your Linux distro's package management tool). Even previously-reputable download sites like Sourceforge have been guilty of bundling shit.
Re: (Score:3)
Re: (Score:2)
Re: (Score:2)
No, the time to abandon uTorrent was when they started showing ActiveX ads. That was a while ago. I've been using Transmission running on my DroboFS ever since (which considering that was where most of my downloads were going in the first place ended up simplifying things).
uTorrent is just the latest piece of software that started off pretty awesome, and was ruined by greed.
Re: (Score:3, Informative)
Re:Another piece of software to uninstall (Score:4, Informative)
Re:Another piece of software to uninstall (Score:5, Interesting)
I can live with that.
Re: (Score:2)
Re: (Score:2)
Time to abandon utorrent. In fact, time to abandon all software who's owners bundle in adware/malware/anything-other-than-the-program-the-user-is-trying-to-install.
The only way this practice will stop is if users refuse to download and use software that does this.
Wrong.
The only way this practice will stop is if users stop demanding every damn thing for free and actually come off their wallets and pay for the damn software.
It is up to the cheap-ass customer to decide whether that is through incessant ad revenue or a one-time charge.
Deluge, Another piece of software to install (Score:2)
Deluge is a good option. I find it to be everything uTorrent used to be.
Re: (Score:2)
Re: (Score:2)
I've been using qbittorrent for the last year and I like it over deluge myself.
Re: (Score:2)
does anyone use the most current version? (Score:4, Interesting)
A couple of years ago uTorrent started installing adware with their software as well, and everyone either bailed or went back to v2.2.1. So why would anyone be using the most current version of uTorrent anyway?
Re:does anyone use the most current version? (Score:5, Interesting)
people new to torrenting and need a client might look at old links (there are many on the internet) and go and install the very pretty looking uTorrent, and of course they'll want the latest version.
Frankly, I ditched it when they started getting shitty with the adware, I moved to qbitorrent which doesn't look too dissimilar from uTorrent and all is good now.
Re: (Score:2)
Seconded, I switched to qBittorrent as well; even before utorrent got truly awful:
c++ so no dependency on Java; but does require python if you want to use its built in search.
Opensource / GPLv2+
So hopefully much less likely to end up the mess that utorrent became.
Re: (Score:2)
Re: (Score:2)
A couple of years ago uTorrent started installing adware with their software as well, and everyone either bailed or went back to v2.2.1. So why would anyone be using the most current version of uTorrent anyway?
Laziness, in my case. I've just upgraded with each new version, no crapware has been installed and the ads... I don't spend any time in the uTorrent UI, I don't understand how they make money. I launch torrents and is gone, occasionally I check if something done but it's just open -> scoll list -> yes, launch file or no, oh well. I literally can't remember any product or service they've had an advertisement for. Before that I used Azureus Vuze, but it turned into such a horrible mess. I'm sure there's
Go back to utorrent 2.2.1 (Score:5, Interesting)
Re:Go back to utorrent 2.2.1 (Score:4, Informative)
Why would you suggest PIG DISGUSTING closed source software when there are so many quality open-source solutions, including:
Deluge
QBittorrent
Transmission
Re: (Score:2, Troll)
Re: (Score:2)
Because he's not RMS and probably doesn't have a problem with closed source software, like most of the world.
And here I thought it was because he showered regularly...
Re: (Score:2)
Re: (Score:2)
It seems that you can install utorrent without the extra crap now simply by declining each offer one by one. But you still get obnoxious ads.
The Bittorrent 7.9.2 client looks the same as utorrent, it tried to foist some crap on me a couple of days back - there was no way to decline the crap and continue so I exited the update installation, now it's saying there's no update.
Re: (Score:2)
I just installed the latest Bittorrent yesterday. It installed spyware without asking me, which my Trend Micro virus scanner immediately alerted on. I would not recommend installing Bittorrent to anyone.
Re: (Score:2)
Utorrent and Bittorrent clients are both owned by Bittorent inc, they are essentially the same by the looks of it.
Re: (Score:2)
qBittorrent wipes the floor with it anyway.
Re:Go back to utorrent 2.2.1 (Score:4)
would you go so far as to say it whips the llama's ass? or not quite that far?
But why though? Math time! (Score:2)
Re: (Score:2)
One i5-2400 does 14MH/sec, so 150 million of them can do 2100 TH/sec, which would be $6000/day.
Re: (Score:2)
Re: (Score:2)
https://alloscomp.com/bitcoin/... [alloscomp.com] says $6000/day for 2100 TH/sec.
I agree that the installed number is going to be much less than 150 million though. Just pointing out that the math is way off.
Re: (Score:3)
It's something like a 100:1 loss on electricity at $0.11/KWH by the way.
except they aren't paying for the electricity, so it's all profit. even if they are only making $100, that's still pretty great. considering they probably spent a week hacking together existing software ... and after that it's zero expenditure and all profit (except what they are paying bittorrent).
Re: (Score:2)
Of course, when it's your vict^H^H^H^Husers paying for the electricity and not you, you really don't need to care what it costs.
Crap Reports (Score:3, Informative)
Re: (Score:2)
Definition of "Silent" (Score:2)
As far as these companies are concerned, not a single piece of punctuation dropped any old place in the middle of there 50 paragraph EULA is 'silent.' See? It's written right there in plain english!
As far as user behavior goes, silent has a very different meaning.
Betanews is so heavily riding the tip of the VC backed new tech industry that they are clearly not going to go against any sort of new fangled tech-oriented revenue generating schemes.
Re: (Score:2)
I'm not sure "betanews" is the most credible source out there
Hah. Says the guy on Slashdot. :P
Alternatives are available... (Score:5, Informative)
When they started pulling this crap I switched to something else that apes the older, simpler, cleaner versions: http://www.qbittorrent.org/ [qbittorrent.org]
Re: (Score:2)
I've been using miniget, but it has no features other than being small and downloading torrents. It is really small, though.
Re: (Score:3)
qbittorrent is a great switch from utorrent. As it looks almost the same, without the crap. I switched my girlfriend torrent tool to qbittorent, and she didn't notice any real difference except for the lack of ads.
I've been using this for years (Score:2)
It's great.
Surprised they thought they could get away with it (Score:2)
With so many people using laptops these days, all the sudden additional heat, blowing fans and lack of battery life would become immediately obvious.
You just can't hide CPU-bound processes on machines these days and expect people not to notice. Especially people who are into torrents!
Re: (Score:3)
There are ways to hide a program so that increased CPU life would not be noticed:
1: Wait for the MSI install/upgrade mechanism to be used, then start using the CPU after it completes. The program installed will get the blame.
2: Ramp it up over a period of time, so the user gets used to his MBA eating its battery in two hours.
3: Wait until the laptop is plugged in and the screensaver is on, and hit it.
It eventually will be caught, but there are ways to keep all but the more astute people from noticing.
I
Why is uTorrent so popular still? (Score:4, Informative)
I've been using qBittorent [qbittorrent.org] for a couple years and it gives me all the relevant functionality without the mess as well as Transmission QT [sourceforge.net] for Windows and Deluge [deluge-torrent.org], I can see no reason to use uTorrent when it's been shown repeatedly to be scum-ware.
only one reason why uTorrent is still popular (Score:4, Informative)
...because it's popular.
Older versions could fit on a floppy disk, and didn't require an Installshield Wizard. Now, it's not at Vuze levels of bloatedness (though Vuze beats to a different drum and has a pretty nice "content store" for Creative Commons content and similar), but it's gotten big and annoying. Transmission works on Windows (...and OSX...and *nix...and plenty of routers and NASes...) and is nice if you don't need RSS feeds. QBittorrent does RSS and is simple to use. Deluge, while being a bit awkward, does a good job. if you're into a super-configurable ecosystem, rTorrent has 101 plugins and browser based frontends, but can also run exclusively from the CLI if that's your thing. The list goes on and on, but utorrent seems to be coasting on inertia, nothing more, nothing less.
The interesting thing is that a similar "we'll borrow some unused CPU cycles" method of revenue generation caused a huge mess with Digsby, an IM client that was great and had a pretty good following until that point. Then again, with most technical folks opting for one of the plentiful alternatives to utorrent, I don't see this being a major impact.
Re: (Score:2)
I have seen several people point out this "fits on a floppy" thing. I don't get this, please explain. The reason for using bittorrent is to download large amounts of data as fast as possible, why would it matter if the install is 1.44MB or 10MB?
If you are already intending to download CD or DVD sized files, why would it matter how big the installer is?
Re: (Score:2)
The 10 MB file is not the problem, the problem is that if everything useful can fit in 1.44MB, then 86.66% of the installer is for things you don't want.
Any Linux torrent clients that support proxies? (Score:2)
I'd run my torrents exclusively on one of my Linux boxes, but none of the clients support proxies. WTF?
It doesn't matter what I'm downloading.... I'm not hanging my ass out there for potential DMCA abusers to hand out subpoenas.
Re: (Score:2)
Well, looks like qBitTorrent supports the proxy service.
I would consider using VPN, but I already have a proxy service and setting up VPN to only run for the torrent on a (relatively) headless Linux box introduces some complications, like being able to administer it over the web.
I understand the reasoning that removed proxy support from the more popular torrent clients a while back, even if it was incredibly and mindblowingly dumb and naive.
Re: (Score:2)
Try "Deluge". Supports proxies, is cross platform, and supports RSS.
gave up on local torrenting years ago (Score:4, Informative)
Just another reason to have a seedbox for all of your torrent needs.
Installed it... then uninstalled it. (Score:2)
A lot of good it will do them (Score:2)
to mine my 6 year old atom "powered" netbook.
How many millions of years would it take my netbook to generate a bitcoin?
Not even the worst thing it installs (Score:3)
All this furor over Epic Scale bitcoin miner, and none over other crud like Wajam that uTorrent installs?
Have a look at the last image in this article [vice.com]. "...may change your local proxy settings...collect...URLs of the pages you visit...content of encrypted webpages...Wajam may protect itself from other software that tries to wrongfully interfere with it."
Yikes. Lenovo got spanked pretty hard for packaging advertising malware that MITMs your encrypted sessions, but at least theirs doesn't officially threaten a counterstrike against your antivirus too.
Re: (Score:3)
yeah, only way I could rip out wajam was to boot into a knoppix session and force-kill the files then boot into safe mode and hack the registry.
What a pain the fucking arse that was.
Move on, the show's over (Score:3)
uTorrent alternatives you should have moved on to a long time ago; cross platform clients, with clickable links for the lazy:
qBittorrent v3.1.12 [qbittorrent.org]
Deluge v1.3.11 [deluge-torrent.org]
Re:Disappointing, but not surprising. (Score:4, Informative)
>the leading Java-based client
If you mean the client I think you do, that has been crap for many years.
Transmission is the way to go these days.
Re: (Score:2)
http://www.transmissionbt.com/ [transmissionbt.com]
Any thoughts on Deluge?
http://deluge-torrent.org/ [deluge-torrent.org]