News: 1621426508

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

GitLab tries to address crypto-mining abuse by requiring card details for free stuff

(2021/05/19)


In a bid to tackle cryptocurrency miners slurping free pipeline minutes, GitLab will expect users to [1]provide a valid credit or debit card number to use shared runners on its platform.

The move, which the company admitted was "imperfect", is the latest salvo in the ongoing battle between GitLab and other CI/CD providers against users putting those free minutes to work in the crypto-mines.

Microsoft has also been hunting for ways to deal with users hogging resources by first tinkering with the free tier of Azure Pipelines and then announcing plans to be a little more selective over its freebies in private projects. Microsoft's Azure DevOps Hosted Pools experienced a [2]particularly nasty wobble last month , the blame for which was laid at the door of "abusers."

[3]

[4]

Tired of firefighting, GitLab has opted to require a credit or debit card number which it will verify using a one-dollar authorisation transaction (and not make a charge). "We will never fully solve platform abuse," the company sighed, "but the more barriers we put up, the more difficult and expensive it becomes to engage in abuse."

The change only affects shared runners; no card number is needed for a user's own runner. It will also only apply to new free users created on or after 17 May. The requirement may, however, be spread to existing users "if we continue to see abuse through existing free accounts."

Self-managed users are not affected, nor are paid or program users on GitLab.com.

[5]

The team has other barriers including restrictions around the creation of namespaces via the API and failing job creation or pipelines when minutes have been exceeded. However, it is the demand for a credit or debit card number to get access that is likely to prove controversial.

One user worried that the requirement would "set the bar high for new users" while another pointed out that stolen card details were "incredibly easy to come by" thus raising the spectre of CAPTCHAs.

We can imagine some users potentially being excluded, but, when faced with "intermittent performance issues", GitLab clearly feels that user account verification will give the abusers pause for thought. ®

Get our [6]Tech Resources



[1] https://about.gitlab.com/blog/2021/05/17/prevent-crypto-mining-abuse/

[2] https://www.theregister.com/2021/04/07/azure_devops/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YKU2Gzg2URIFyC2r--ANHwAAAJA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YKU2Gzg2URIFyC2r--ANHwAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YKU2Gzg2URIFyC2r--ANHwAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://whitepapers.theregister.com/

msobkow

Sorry, but I have no sympathy with so-called "coders" who don't want to identify themselves or provide financial verification that they are legal adults with the means to pay for what they are using.

There are a lot of people in this industry who think everything should be free for their own personal use. Well, if something is given away, it is going to come with restrictions, and seeing as you're not paying for it, you have no right to complain about what KIND of restrictions the offer comes with. If you don't like the free offer, you can always pay for services to your liking.

Anonymous Coward

So, is the way to thwart criptomining abuse to offer a free service to check the validity of stolen credit card data?

This will not end well.

Might not even be lawful

Mike 137

" GitLab will expect users to provide a valid credit or debit card number to use shared runners on its platform. "

Under the dreaded GDPR, it's quite possibly not allowable to collect payment card details (which are personal data) where no payment is required for provision of the service. Some other control that doesn't involve personal data which is not strictly necessary for provision of the service would be lawful. As if MS actually cared about the legality of this though...

Fellow programmer, greetings! You are reading a letter which will bring
you luck and good fortune. Just mail (or UUCP) ten copies of this letter
to ten of your friends. Before you make the copies, send a chip or
other bit of hardware, and 100 lines of 'C' code to the first person on the
list given at the bottom of this letter. Then delete their name and add
yours to the bottom of the list.

Don't break the chain! Make the copy within 48 hours. Gerald R. of San
Diego failed to send out his ten copies and woke the next morning to find
his job description changed to "COBOL programmer." Fred A. of New York sent
out his ten copies and within a month had enough hardware and software to
build a Cray dedicated to playing Zork. Martha H. of Chicago laughed at
this letter and broke the chain. Shortly thereafter, a fire broke out in
her terminal and she now spends her days writing documentation for IBM PC's.

Don't break the chain! Send out your ten copies today!