Live data from Hacker News

Hola VPN turns 10M users into exit nodes

8ch.net

61–70 of 144 posts

Re: Hola VPN turns 10M users into exit nodes

#61
post #45
post #27

Earlier quoted context omitted.

What happens when the Feds are knocking on your door because someone routed kiddie pr0n or drug deals through your connection?

To play devil's advocate: isn't this kind of a good thing for privacy though? If everyone routed everyone else's stuff, it will decouple the notion that IP = person. Although the service seems shady, if everyone did this wouldn't it be for the better? (albeit at cost of slower connections)

Sure, except for the poor soul that was looking for some anonymity, and now has the FBI knocking on her door with a mandate, because a shady service that didn't disclose what it was doing to your connection.

Decoupling IP from people won't happen anytime soon. It's better for law enforcement to just go, seize everything, and deal with the false positives later.

See the long list of "suggestions" for people interested in running their own tor exit node [1]. This is not something you should even think about doing from your personal home, mixed with your own traffic. It's asking for trouble.

[1] https://blog.torproject.org/blog/tips-running-exit-node-mini...

Re: Hola VPN turns 10M users into exit nodes

#62
So far as I can tell, there is no way to tell if an IP has the Hola VPN software installed or not: no tell tale open port, no special header from Luminati, and no specific range.

Then, immediately in the next paragraph:

An attacker used the Luminati network to send thousands of legitimate-looking POST requests to 8chan's post.php in 30 seconds, representing a 100x spike over peak traffic and crashing PHP-FPM.

How was that conclusion arrived at? Am I missing something here?

Re: Hola VPN turns 10M users into exit nodes

#63

Anyone have VPN recommendations?

I use NordVPN, which I have no complaints about. But occasionally I'll get a 1 week token from cryptostorm (https://cryptostorm.is/)

They have an interesting model: you buy a token that expires after a certain length of time (1 week, 1 month, 1 year, etc). The clock doesn't start ticking until the first time you log in. Instead of registering a username/password, you're sent the token via email and your login ends up being a sha512 hash of the token for the username. There is no password associated, just the hash of the token is all you need.

I like this because you're able to buy 'disposable' accounts basically. They take bitcoin and some alt coins too, which is nice. Dns protection and access to .onion and .bit domains. It all seems pretty solid. NordVPN tends to be a little bit faster for me, though it may depend on which servers you use.

Re: Hola VPN turns 10M users into exit nodes

#64

So far as I can tell, there is no way to tell if an IP has the Hola VPN software installed or not: no tell tale open port, no special header from Luminati, and no specific range. Then, immediately in the next paragraph: An attacker used the Luminati network to send thousands of legitimate-looking POST requests to 8chan's post.php in 30 seconds, representing a 100x spike over peak traffic and crashing PHP-FPM. How was…

"Ah, the user flooding himself (Bui) spilled the beans and told me how he did it voluntarily in IRC. Otherwise I'd have no clue." -Fredrick Brennan (8chan)

Re: Hola VPN turns 10M users into exit nodes

#65

So far as I can tell, there is no way to tell if an IP has the Hola VPN software installed or not: no tell tale open port, no special header from Luminati, and no specific range. Then, immediately in the next paragraph: An attacker used the Luminati network to send thousands of legitimate-looking POST requests to 8chan's post.php in 30 seconds, representing a 100x spike over peak traffic and crashing PHP-FPM. How was…

Copypaste is rate limited, he had this to say: https://twitter.com/HW_BEAT_THAT/status/603741442490642432

"The user flooding himself (Bui) spilled the beans and told me how he did it voluntarily in IRC. Otherwise I'd have no clue."

Re: Hola VPN turns 10M users into exit nodes

#66
post #45
post #27

Earlier quoted context omitted.

What happens when the Feds are knocking on your door because someone routed kiddie pr0n or drug deals through your connection?

To play devil's advocate: isn't this kind of a good thing for privacy though? If everyone routed everyone else's stuff, it will decouple the notion that IP = person. Although the service seems shady, if everyone did this wouldn't it be for the better? (albeit at cost of slower connections)

You can already decouple the notion that IP = person if you look at public wifi hotspots, where one IP address will typically correspond to hundreds or even thousands of devices owned by the customers of the hotspot's owner (like a Starbucks or McDonald's location) plus (depending on the setup and whether or not the hotspot is on a separate WAN connection) the company's own machines.

This, come to think of it, sounds like a more ideal approach to creating exit nodes (whether for Tor, a more traditional VPN, etc.). Some low-profile innocuous-looking wall wart - perhaps with USB ports to double as a USB charging station, or some other "clever" disguise - could really be an "exit-node-in-a-box", relaying Tor users through public wifi hotspots in restaurants, hospitals, etc. I reckon this will be more prevalent if any jurisdictions start doing silly things like holding people liable for what their computers emit when they run exit nodes (or - worse - ban Tor, VPNs, etc. outright).

Re: Hola VPN turns 10M users into exit nodes

#68

So far as I can tell, there is no way to tell if an IP has the Hola VPN software installed or not: no tell tale open port, no special header from Luminati, and no specific range. Then, immediately in the next paragraph: An attacker used the Luminati network to send thousands of legitimate-looking POST requests to 8chan's post.php in 30 seconds, representing a 100x spike over peak traffic and crashing PHP-FPM. How was…

One way to find out (not saying this is how it was done) would be to spin up a machine running Hola and see where the traffic goes.

Re: Hola VPN turns 10M users into exit nodes

#69
post #59
post #57

Earlier quoted context omitted.

/cuteboys/ in particular is a board for effeminate gay men , that does not allow underaged posters or pictures thereof. Just goes to show how zodiakzz hasn't bothered to actually visit or understand the site he's crusading against.

Seeing as zodiakzz seems to be completely against free speech I wouldn't be surprised if he/she equates homosexuality with pedophilia. It seems to always be the people who crusade against pedofiles who end up being the child abusers. (see how easy it is to make unfounded assumptions about people?)

I see nothing in zodiakzz's comments which suggests that they are 'completely against free speech,' and your personal attacks are completely out of line and against the culture and terms of Hacker News.

It's all well and good to dispute their sources, but at least they brought sources to dispute.

Re: Hola VPN turns 10M users into exit nodes

#70

Earlier quoted context omitted.

I'm not sure this will get seen but - is there an OpenVPN client for Windows that doesn't suck?

Viscosity is pretty good for Macs+Windows.

Viscosity is phenomenal. Its extremely inexpensive, and makes working with OpenVPN on the client side much less painful.
Post reply on HN