Live data from Hacker News

Hola VPN turns 10M users into exit nodes

8ch.net

101–110 of 144 posts

Re: Hola VPN turns 10M users into exit nodes

#101
post #6

Anyone have VPN recommendations?

i've been renting a cheap-as-dirt vps ($15/yr) and just using sshuttle[0] to proxy through it which works great for my circumstances (my school blocks nonstandard ports but is just dandy with 22) [0] https://github.com/apenwarr/sshuttle

And just in case you're in a network that does block access to port 22, use sslh to listen to port 443 and map all ssh traffic to port 22 (and all https traffic to httpd, and all openvpn traffic to 1194).

One port (443) to rule them all!

Re: Hola VPN turns 10M users into exit nodes

#103
post #88
post #45

Earlier quoted context omitted.

To play devil's advocate: isn't this kind of a good thing for privacy though? If everyone routed everyone else's stuff, it will decouple the notion that IP = person. Although the service seems shady, if everyone did this wouldn't it be for the better? (albeit at cost of slower connections)

It provides plausible deniability. It wasn't me, it was Hola. The issue is there's no informed consent. Outside of /r/netsec, /r/techsupport and HN etc, there probably aren't people who know how Hola works and what the implications are. You can bet the majority of Hola users don't know what a MITM attack is. I'd wager more than half wouldn't know what a bot net is, or what an exit node is. Most Hola users have not gi…

I'm not sure that plausible deniability has much value if, say, a user's ISP has a policy of suspending accounts that attract too many complaints about copyright, hacking, spam, etc. The account itself is a nuisance to them, regardless of whose fault it is.

Re: Hola VPN turns 10M users into exit nodes

#104
post #37

Earlier quoted context omitted.

It looks like they clarified their story, not changed it? It did say that it uses idle resources collaboratively...I'm not really trying to argue, just wondering if it was really that deceptive. I had never heard of them until this post.

> It did say that it uses idle resources collaboratively So does Folding@Home. So does tor onion routing (relay node). Nowhere did it say outside of the EULA that they are using all their users as exit nodes. They failed to specify which "resources". It's indefensible, and people would have fallen for this cover up had Google not archived it.

Tor only relays if users explicitly configure it to. By default Tor acts as a client.

Re: Hola VPN turns 10M users into exit nodes

#105

Anyone like to recommend a browser-extension-based VPN tool that's a bit more respectful than Hola and is relatively cheap? (Of course I run my own VPN server using OpenVPN, but Hola is really convenient when I'm only trying to get an American IP to avoid Australian geoblocking - it's also easy for non-technical friends to use.)

Tunnelbear recently released a chrome plugin for their VPN service. I hear good things about it. (I personally use the application on my Mac)

Tunnlebear makes no claims relative to logging its users activities or about its responsiveness to requests for them. Beware.

Re: Hola VPN turns 10M users into exit nodes

#106

Anyone like to recommend a browser-extension-based VPN tool that's a bit more respectful than Hola and is relatively cheap? (Of course I run my own VPN server using OpenVPN, but Hola is really convenient when I'm only trying to get an American IP to avoid Australian geoblocking - it's also easy for non-technical friends to use.)

Just use Tor Browser, it's "extract and launch".

Re: Hola VPN turns 10M users into exit nodes

#107
post #29

Earlier quoted context omitted.

Hello, Fredrick Brennan here (8chan owner). They changed their FAQ IN RESPONSE to my breaking the story on this. Proof: Google cache of Hola FAQ as of 26 May: https://archive.is/tgujS As you can see, there is no mention of Luminati, or the underlying mechanics at all. I published hola.html and updated my global announcement just hours before the FAQ change: https://twitter.com/infinitechan/status/603178141650026498 T…

Not do downplay this issue, but wouldn't one simply assume it works this way. I mean, how else would it work, Hola operating their own proxies and giving all of that infrastructure and bandwidth away for free? Of course it would be P2P and would turn the user into a supplier of data and bandwidth to others. This basic model has been in use for "illegal" content for well over a decade now. Now how they exploit that ba…

I agree with most of what you said. When you're downloading proxy/vpn software like this, it's either P2P (and you're sharing your own resources) or it's centralized. They could make this clearer in the blurb to download the software, but they don't hide this fact and in fact make it clear from their FAQs and pricing pages.

But the Luminati angle is nothing different. It would make abusing the proxy network easier (from a technical perspective) but it's nothing you couldn't do with Hola alone. Luminati is just API access to Hola along with expensive pricing and a screening interview with sales staff. You could hack your own API out of only Hola if you really wanted.

The real story is that last time I checked, all their US exit nodes come from Digital Ocean, which is hardly worth $20/GB (should be more like $5/TB). I guess they don't have a lot of US users.

Re: Hola VPN turns 10M users into exit nodes

#108
post #29
post #3

They explicitly state in their FAQ how this works and why their service is able to be free: http://hola.org/faq#in_how_is_free They even have a non-free option that eliminates the VPN as a proxy feature. "Hola built a peer to peer overlay network for HTTP, which securely routes the sites you choose through other Hola users' devices and not through expensive servers. Hola never takes up valuable resources from these u…

Hello, Fredrick Brennan here (8chan owner). They changed their FAQ IN RESPONSE to my breaking the story on this. Proof: Google cache of Hola FAQ as of 26 May: https://archive.is/tgujS As you can see, there is no mention of Luminati, or the underlying mechanics at all. I published hola.html and updated my global announcement just hours before the FAQ change: https://twitter.com/infinitechan/status/603178141650026498 T…

> As you can see, there is no mention of Luminati, or the underlying mechanics at all.

They didn't write "Luminati" but they wrote this:

"Hola and Hola premium are free for private, non-commercial use. For a commercial license to Hola please contact [...]. Your commercial license will provide you with these additional features: Hola For business: License to use Hola for commercial purposes. Automation: developer API that enable controlling the routing of your HTTP requests via software. Allow many concurrent sessions. High bandwidth/high request rate with multiple IPs. More precise resolution of exit node IP. Faster changing of IP. Engineering technical support."

"Typical VPNs need to maintain servers in various countries and to route your traffic through those servers in order to change your IP. This is very expensive. Hola is a network of peers that help each other to access sites, thereby eliminating the need for servers, and thus operating without costs."

Re: Hola VPN turns 10M users into exit nodes

#109

This made me laugh--I wonder how many innocent people are going to have the FBI kick their doors down for things that past through their "exit nodes" that they hosted.

Judging by in what context I have read about Hola so far, I guess the biggest use case is to circumvent geo block to access things like Netflix. But yeah, ever since I learned that I am acting as an exit node for others I have stopped using the service as I do not want to be the one answering for stuff others have done in my name(IP).

Re: Hola VPN turns 10M users into exit nodes

#110
post #29

Earlier quoted context omitted.

Hello, Fredrick Brennan here (8chan owner). They changed their FAQ IN RESPONSE to my breaking the story on this. Proof: Google cache of Hola FAQ as of 26 May: https://archive.is/tgujS As you can see, there is no mention of Luminati, or the underlying mechanics at all. I published hola.html and updated my global announcement just hours before the FAQ change: https://twitter.com/infinitechan/status/603178141650026498 T…

Not do downplay this issue, but wouldn't one simply assume it works this way. I mean, how else would it work, Hola operating their own proxies and giving all of that infrastructure and bandwidth away for free? Of course it would be P2P and would turn the user into a supplier of data and bandwidth to others. This basic model has been in use for "illegal" content for well over a decade now. Now how they exploit that ba…

Agree that free proxies aren't free. But how many people would know about proxies. For most of the people if a content is country blocked, a google search and first or second link click solution will end up with hola installed, no more question asked. I think we should do better than "Don't use if you don't know" argument.
Post reply on HN