Live data from Hacker News

Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

torrentfreak.com

31–40 of 83 posts

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#31
post #26

So this is interesting to me because lately, I've been looking for a VPN that would work for my little brother who is trying to make it to the point that he can stream full time on Twitch. The problem is that he has been targeted by script kiddies, who found his IP address through Skype. Shame on you skype. That said, I've been looking for a good VPN for him. It seems that ProXpn isn't as solid as I thought it was be…

>Also, there is no guide out there for streamers, or people who are in the public eye on the internet, on how to avoid getting attacked by script kiddies.

A famous StarCraft streamer made a guide on how to avoid this:

https://blog.destiny.gg/protection-from-ddos-attacks/

I googled "guide to preventing DDOS on twitch" and it came up as the fourth result. How hard did you look?

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#32
post #4

Selling user's bandwidth is shady, but consistent with VPN usage (i.e. traffic routing). You can present it as "hey, that's our actual business model, we just forgot to tell you guys" and maybe get away with it. But this: Hola [...] installs its own code-signing certificate on the user’s system. Hola contains a built-in console (“zconsole”) that is not only constantly active but also has powerful functions including…

> This is Lenovo/Superfish all over again. Completely different. Superfish, I'm willing to believe, was just incompetence/indifference. If Hola really is installing a backdoor with high privileges, then that's deliberate malice.

> Superfish, I'm willing to believe, was just incompetence/indifference. If Hola really is installing a backdoor with high privileges, then that's deliberate malice.

But that's what Superfish was as well. Why are you willing to give Superfish a free pass on doing the same thing?

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#33
post #4

Selling user's bandwidth is shady, but consistent with VPN usage (i.e. traffic routing). You can present it as "hey, that's our actual business model, we just forgot to tell you guys" and maybe get away with it. But this: Hola [...] installs its own code-signing certificate on the user’s system. Hola contains a built-in console (“zconsole”) that is not only constantly active but also has powerful functions including…

I suppose the lesson here is don't use "free" services until you fully understand the provider's business model.

So, basically any VC backed, SV based startup?

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#34
post #27

Earlier quoted context omitted.

The Chrome store still is hosting Hola: https://chrome.google.com/webstore/detail/hola-better-intern...

I wonder what caused the surge of all those 5-stars positive reviews within the last 24 hours....

Hola's marketing team at work.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#35

Earlier quoted context omitted.

> This is Lenovo/Superfish all over again. Completely different. Superfish, I'm willing to believe, was just incompetence/indifference. If Hola really is installing a backdoor with high privileges, then that's deliberate malice.

> Superfish, I'm willing to believe, was just incompetence/indifference. If Hola really is installing a backdoor with high privileges, then that's deliberate malice. But that's what Superfish was as well. Why are you willing to give Superfish a free pass on doing the same thing?

Not sure, but I think I might be on madeofpalk's team on this one too: Superfish was ostensibly doing it to feed data into targeted advertising; Hola has no such (marginally) benevolent excuse.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#36

I have zero connection to this company but if you are looking for a reliable, fast, unlimited VPN I would check out Private Internet Access ( https://www.privateinternetaccess.com/ ) I've got a number of friends who use this and I've been using it for a little over a month and have nothing but good things to say. At $40/yr it's well worth it IMHO and provides a native VPN client, PPTP, and Socks5 (They have mobile ap…

I recently bought a year for around $35 with some coupon code or other and honestly...I'm a bit underwhelmed. No matter what settings I use or what node I connect to, my ~100mbps (down) cable connection drops to somewhere between 1-10mbps. I was originally going to set up OpenVPN on my router so everything would go through it but I heard it can tax router hardware and lead to slower speeds so I figured I'd just test…

That's the same issue I ran into with using a VPN; I know I want to be using one as a (theoretical) enhancement to my privacy, but it was just too slow.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#37

I have zero connection to this company but if you are looking for a reliable, fast, unlimited VPN I would check out Private Internet Access ( https://www.privateinternetaccess.com/ ) I've got a number of friends who use this and I've been using it for a little over a month and have nothing but good things to say. At $40/yr it's well worth it IMHO and provides a native VPN client, PPTP, and Socks5 (They have mobile ap…

I recently bought a year for around $35 with some coupon code or other and honestly...I'm a bit underwhelmed. No matter what settings I use or what node I connect to, my ~100mbps (down) cable connection drops to somewhere between 1-10mbps. I was originally going to set up OpenVPN on my router so everything would go through it but I heard it can tax router hardware and lead to slower speeds so I figured I'd just test…

One possibility is that your ISP is throttling encrypted connections. It's something that seems easy enough to test.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#38
post #27

Earlier quoted context omitted.

The Chrome store still is hosting Hola: https://chrome.google.com/webstore/detail/hola-better-intern...

I wonder what caused the surge of all those 5-stars positive reviews within the last 24 hours....

Tons of articles being written about it? I hate to say this, but because of Google+ it is pretty easy to see if users are legitimate or not. And from what I could tell many in those reviews are legitimate users (at least on G+).

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#39

Earlier quoted context omitted.

Downloading copyrighted content is the least of worries here, that is mostly a private matter. But there is a very real risk that if someone accesses child pornography and other content using Hola and your internet connection that you will wake up to police searching your home.

This is a far more real risk than you might think, I'm currently on the tail end of a police investigation triggered by a device on my home network accessing child porn via Tor. My current theory is that something got added to a botnet and used as a proxy, but I'm not eager to leave things running to find out. While the police have been incredibly professional about this, its been a truly horrible process. Anything i…

I'm not sure how downloading Game of Thrones is connected t oyour troubles.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#40
post #11

I wish to just use OpenVPN but it's not so easy. Certificates - no problem. Forward DNS requests - there is an option for it in the config file. Routing entire traffic through OpenVPN - quite tricky unless you're fluent in command line network management tools and computer networks in general.

Try OpenVPNs Access Server - it comes with 2 free licenses and a web UI to configure it. Makes the entire process quite straightforward: https://openvpn.net/index.php/access-server/pricing.html

[deleted]
Post reply on HN