PSA: Warning about NVIDIA drivers from unofficial sources
This article is a Public Service Announcement (PSA) and represents advice or tips from our team on events in the wider crypto industry. The views, opinions, and advice represented here DO NOT relate to NiceHash services directly and are simply presented here to help you make choices of your own when mining or trading. Our goal is to ensure a great user experience, and sometimes this extends beyond the services that we offer from our own company to protect our customers.
Recent events
If you are following the latest news in the tech industry, you probably know that NVIDIA had a security breach where 1TB of data was stolen. Aside from drivers' source code, LHR locking source code, and other sensitive data, hackers were able to access code signing certificates.
What does that mean?
Code signing certificates are used to sign the software from a trustworthy company. Your Windows system can then recognize the signature and allow the software to run on your PC, bypassing security.
Certificates and private keys are normally stored in a secure place and only a handful of developers (if not only one or two) can use them to sign the software and guarantee its safety. Unfortunately, NVIDIA did lose these private keys. The private keys are expired, which means that in some cases the antivirus will not treat it as signed software thus block it from running. But in other cases, where the software is a driver of some sort, Windows will allow the driver signed with an expired certificate to be loaded in the operating system.
Serial numbers of stolen certificates are:
43BB437D609866286DD839E1D00309F5
14781bc862e8dc503a559346f5dcc518
Why is this related to NiceHash users?
NiceHash top priority is our users' safety. We are determined to keep our user's funds safe. We are aware that some of our users are using RTX 3060 v2 GPU, which can be fully unlocked with NVIDIA drivers that are not available on NVIDIA's official website anymore. If you are one of these users, we urge you to triple-check for the driver's authenticity.
Another reason is that lately, the newest NVIDIA drivers are causing issues with mining. We already published a blog post about it here. Some users might be scanning the web for "modified drivers" which could allow optimal gaming and mining performance with the latest drivers. We, again, urge you not to download these kinds of drivers.
The official NVIDIA driver download page: https://www.nvidia.com/Download/index.aspx