Live data from Hacker News

Hola VPN turns 10M users into exit nodes

8ch.net

51–60 of 144 posts

Re: Hola VPN turns 10M users into exit nodes

#51
post #46

Earlier quoted context omitted.

Source that proves he's hosting such things? Are you arguing against anonymity on the internet altogether? IMO Mr. Brennan is a hero for taking on the risks associated with hosting an anonymous image board and not backing down in the face of people who time and time again continue to slander his name. I don't want to live in a world where people live in fear of hosting an anonymous image board.

http://arstechnica.com/security/2015/01/8chan-domain-seized-... -------NSFW!----- https://8ch.net/ephe/ "Teenagers ONLY! That means only 13+ But of course, 16 is the perfect age." https://8ch.net/nnmodels/ "Young Models and Jailbait" https://8ch.net/phile/ "Show some https://8ch.net/hebe/ https://8ch.net/cuteboys/

This is not "proof" of him knowingly hosting child pornography. Sites get accused of such things all the time and I personally believe there is a group of people who intentionally orchestrated this fiasco.

I visited the 8chan links you posted and didn't see any child pornography. It seems to me like you're trying a little too hard to paint this guy as some kind of pedofile. I don't completely agree with the types of things being posted, but I didn't see anything illegal.

Of course a site that allows anyone to create their own board is going to have some politically incorrect boards.

Reddit has had similar problems and you can still find sub reddits for the same things there.

I suppose you're against free speech completely then?

For someone who claims to be anti-child porn you sure did find those links fast, almost like you had them bookmarked..

Re: Hola VPN turns 10M users into exit nodes

#53
post #29
post #3

They explicitly state in their FAQ how this works and why their service is able to be free: http://hola.org/faq#in_how_is_free They even have a non-free option that eliminates the VPN as a proxy feature. "Hola built a peer to peer overlay network for HTTP, which securely routes the sites you choose through other Hola users' devices and not through expensive servers. Hola never takes up valuable resources from these u…

Hello, Fredrick Brennan here (8chan owner). They changed their FAQ IN RESPONSE to my breaking the story on this. Proof: Google cache of Hola FAQ as of 26 May: https://archive.is/tgujS As you can see, there is no mention of Luminati, or the underlying mechanics at all. I published hola.html and updated my global announcement just hours before the FAQ change: https://twitter.com/infinitechan/status/603178141650026498 T…

Even if they had said it all along in their FAQ, it's still infuriatingly disingenuous for someone to act as if anyone ever browses to Hola's site and reads their FAQ either before or after installing the Hola malware extension. No ordinary person will ever do this.

What happens is that someone who has already installed Hola, and who is ignorant by design as to what the extension actually does, tells a friend about Hola; the friend installs it, sees the expected functionality, is unaware of the malicious functionality, and the pyramid of ignorance continues to grow after he tells his own friends about how great Hola is.

These few sentences written in the sidebar here [1] are all that at least 7,102,584 of Hola's victims ever saw (judging by the install count for this malicious Chrome extension):

Access websites blocked in your country, company or school with Hola! Hola is free and easy to use!

FREE and secure VPN. Access websites blocked or censored in your country, company or school and stream media with the free Hola Unblocker VPN proxy service.

Hola is a free and ad-free VPN proxy service that provides a faster and more open Internet.

At no point do they attempt to make it clear in the slightest that they turn your browser into a for-profit bot net node, nor that your own browser becomes a proxy for others. In all venues where Hola expects 99.9% of interested parties to see their product pitch, they intentionally convey the false impression that they personally own their own VPN proxy backends.

Aside from all of that, hiding an explanation of your malware's behavior in the FAQ on some website no one ever sees doesn't suddenly transform it into normal, respectable software. Malware is malware, and bot nets are bot nets.

This is yet another criminal enterprise allowed to flourish and fester simply because Google refuses to police browser extensions in the Chrome web store.

Google runs what I assume must be the largest de facto Universal XSS exploit breeding ground in the world (Chrome extensions in the Chrome web store), and yet they refuse to police its contents.

Here's a recent example. I run AdSense on my site, and it kept running the same ad for an atrocious web game that a 10 year old could have made as their first programming project. I eventually saw the exact same ad running on another site, so I clicked it there in order to avoid the absurd rule that clicking ads on your own site gets you banned from AdSense. (Why don't they just silently discard those clicks, since they know they are from the publisher?) Clicking the ad took me to a page which did not have a game at all; it just falsely claimed you could play a game if you installed their malware browser extension, which it immediately prompted me to install [2]. The extension actually has nothing whatsoever to do with games. It doesn't enable you to play a game at all, anywhere. All it does is replace ads across the entire web with ads from its own ad network for the remainder of the lifetime of that computer. The extension has millions of installs and probably causes Google to lose seven figures per year in AdSense revenue due to so many AdSense ads being replaced with ads from another network. I also think it's funny that ads were being run on my site for the specific purpose of installing malware that would replace the ads and destroy the ad revenue for the very same site that helped it get installed in the first place. I reported this extension three times using the official report forms for the directly relevant teams at Google (even explaining in detail how it damages their own AdSense platform, so unlike a typical consumer complaint, this was actually affecting their profits and they should listen for once), and I was consistently ignored.

1. https://chrome.google.com/webstore/detail/hola-better-intern...

2. http://i.imgur.com/8JJVjZ2.png

Re: Hola VPN turns 10M users into exit nodes

#54
post #45
post #27

Earlier quoted context omitted.

What happens when the Feds are knocking on your door because someone routed kiddie pr0n or drug deals through your connection?

To play devil's advocate: isn't this kind of a good thing for privacy though? If everyone routed everyone else's stuff, it will decouple the notion that IP = person. Although the service seems shady, if everyone did this wouldn't it be for the better? (albeit at cost of slower connections)

You're right, it would be good for privacy if we can convince the courts that users installing the software are not responsible for the traffic of other users. I'm afraid this argument will fall on deaf ears.

Re: Hola VPN turns 10M users into exit nodes

#55
post #52

Isn't 8chan that enabled gamergate to continue? If so, anything bad happened to your site is actually beneficial.

Explain what is wrong with gamergate. I don't game so I don't know. Seems to me reddit is the site you should be hating.

Edit: Actually after thinking it over, it's free speech you should be against.

It really sucks when sites host opinions you don't agree with doesn't it? I googled gamer gate and they seem to be against people exactly like you: People who want to shut down other peoples opinions that they don't agree with.

Re: Hola VPN turns 10M users into exit nodes

#57
post #51

Earlier quoted context omitted.

http://arstechnica.com/security/2015/01/8chan-domain-seized-... -------NSFW!----- https://8ch.net/ephe/ "Teenagers ONLY! That means only 13+ But of course, 16 is the perfect age." https://8ch.net/nnmodels/ "Young Models and Jailbait" https://8ch.net/phile/ "Show some https://8ch.net/hebe/ https://8ch.net/cuteboys/

This is not "proof" of him knowingly hosting child pornography. Sites get accused of such things all the time and I personally believe there is a group of people who intentionally orchestrated this fiasco. I visited the 8chan links you posted and didn't see any child pornography. It seems to me like you're trying a little too hard to paint this guy as some kind of pedofile. I don't completely agree with the types of…

/cuteboys/ in particular is a board for effeminate gay men, that does not allow underaged posters or pictures thereof. Just goes to show how zodiakzz hasn't bothered to actually visit or understand the site he's crusading against.

Re: Hola VPN turns 10M users into exit nodes

#58
post #46

Earlier quoted context omitted.

Source that proves he's hosting such things? Are you arguing against anonymity on the internet altogether? IMO Mr. Brennan is a hero for taking on the risks associated with hosting an anonymous image board and not backing down in the face of people who time and time again continue to slander his name. I don't want to live in a world where people live in fear of hosting an anonymous image board.

http://arstechnica.com/security/2015/01/8chan-domain-seized-... -------NSFW!----- https://8ch.net/ephe/ "Teenagers ONLY! That means only 13+ But of course, 16 is the perfect age." https://8ch.net/nnmodels/ "Young Models and Jailbait" https://8ch.net/phile/ "Show some https://8ch.net/hebe/ https://8ch.net/cuteboys/

[ephe] clothed teens are legal under US law- but only if they do not fail the DOST test.

[nmmodels] young models and jailbait are legal under US law. blame the parents putting their kids into young beauty pageants, not pedophiles. write your representative to make them illegal.

cuteboys is a board for transgirls, gay guys, and crossdressers, along with others that don't fit the binary. you're not some homophobe / transphobe, are you? these people are consenting adults.

if you seriously think child porn could exist in the open on the Internet in 2015, you are delusional. the FBI regularly arrests people, and takes down people for hosting CP.

your argument literally only is supported by feels, not reals. everything that you have linked is legal under US law.

Re: Hola VPN turns 10M users into exit nodes

#59
post #57
post #51

Earlier quoted context omitted.

This is not "proof" of him knowingly hosting child pornography. Sites get accused of such things all the time and I personally believe there is a group of people who intentionally orchestrated this fiasco. I visited the 8chan links you posted and didn't see any child pornography. It seems to me like you're trying a little too hard to paint this guy as some kind of pedofile. I don't completely agree with the types of…

/cuteboys/ in particular is a board for effeminate gay men , that does not allow underaged posters or pictures thereof. Just goes to show how zodiakzz hasn't bothered to actually visit or understand the site he's crusading against.

Seeing as zodiakzz seems to be completely against free speech I wouldn't be surprised if he/she equates homosexuality with pedophilia. It seems to always be the people who crusade against pedofiles who end up being the child abusers.

(see how easy it is to make unfounded assumptions about people?)

Re: Hola VPN turns 10M users into exit nodes

#60
post #10
post #7

I doubt that if they sell their users as bots they will do anything about the network being used as a botnet and there is nothing you can do about it, especially considering the users 'responsible' won't even know what they are taking part in.

It's not clear that part of the article is even true. They appear to just sell VPN server by the GB. I see nothing about a botnet in there, there is no traffic amplification or ability to run programs on the clients.

The point of that bit is that it's not only possible, but borderline-trivial, for a malicious application (e.g. spambot, DDoSbot, etc.) to hook into the API and flood a target using Hola users as endpoints; the article states that such an incident has already happened, and that 24-hour captchas have been instituted for all users as a result in an attempt to stifle future such attacks on 8chan.
Post reply on HN