Live data from Hacker News

Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

torrentfreak.com

41–50 of 83 posts

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#41

Earlier quoted context omitted.

> Superfish, I'm willing to believe, was just incompetence/indifference. If Hola really is installing a backdoor with high privileges, then that's deliberate malice. But that's what Superfish was as well. Why are you willing to give Superfish a free pass on doing the same thing?

Not sure, but I think I might be on madeofpalk's team on this one too: Superfish was ostensibly doing it to feed data into targeted advertising; Hola has no such (marginally) benevolent excuse.

First, I fundamentally disagree that targeted advertising is in any way benevolent, even marginally. Though that's a debate for another thread.

However, they knew full well what they consequences of this mechanism would be[0]. I find it impossible to believe that there was no person at any point along the chain who knew that MITMing all connections would be a security vulnerability[1]. And if that somehow managed to be the case, that makes them even less credible in my mind, since they're an OEM. They really have no excuse.

[0] I mean, seriously, just look at the name "Superfish". That's not a catchy phrase invented to publicize the vulnerability, like "Heartbleed" and "Shellshock". That's the actual name of the company whose product Lenovo bought.

[1] https://news.ycombinator.com/item?id=9078536

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#42
post #39

Earlier quoted context omitted.

This is a far more real risk than you might think, I'm currently on the tail end of a police investigation triggered by a device on my home network accessing child porn via Tor. My current theory is that something got added to a botnet and used as a proxy, but I'm not eager to leave things running to find out. While the police have been incredibly professional about this, its been a truly horrible process. Anything i…

I'm not sure how downloading Game of Thrones is connected t oyour troubles.

Perhaps you haven't attempted to view GoT from "unapproved" locations? That is why some people used Hola: to VPN to an "approved" IP address. Parent's troubles are different, but similar, in that his unwanted traffic came from Tor [EDIT: or maybe just a pwned device? I see now that it's unclear...] rather than Hola. I appreciate reading anything he cares to share, as I am interested in running Tor nodes.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#43

Earlier quoted context omitted.

Downloading copyrighted content is the least of worries here, that is mostly a private matter. But there is a very real risk that if someone accesses child pornography and other content using Hola and your internet connection that you will wake up to police searching your home.

This is a far more real risk than you might think, I'm currently on the tail end of a police investigation triggered by a device on my home network accessing child porn via Tor. My current theory is that something got added to a botnet and used as a proxy, but I'm not eager to leave things running to find out. While the police have been incredibly professional about this, its been a truly horrible process. Anything i…

[deleted]

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#44

Earlier quoted context omitted.

I suppose the lesson here is don't use "free" services until you fully understand the provider's business model.

So, basically any VC backed, SV based startup?

Well I understand their business model. Given valuation is a function of MAU:

1) Boost MAU by any means necessary 2) Pray 3) Monetize/get acquired

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#45
post #31
post #26

So this is interesting to me because lately, I've been looking for a VPN that would work for my little brother who is trying to make it to the point that he can stream full time on Twitch. The problem is that he has been targeted by script kiddies, who found his IP address through Skype. Shame on you skype. That said, I've been looking for a good VPN for him. It seems that ProXpn isn't as solid as I thought it was be…

>Also, there is no guide out there for streamers, or people who are in the public eye on the internet, on how to avoid getting attacked by script kiddies. A famous StarCraft streamer made a guide on how to avoid this: https://blog.destiny.gg/protection-from-ddos-attacks/ I googled "guide to preventing DDOS on twitch" and it came up as the fourth result. How hard did you look?

Yeah I've seen this, and gone over it with him. He has some added exposure due to Steam which is another potential risk. I added a bullet point for that.

Thanks for pointing this out but what do you think about the VPS vs VPN. It has an increased exposure to attack because everything else you do on your pc isn't being routed through the VPS.

It also doesn't do anything for best practices for avoiding other forms of hacking. So it's a good guide but definitely incomplete.

I looked pretty hard, I spent the better part of 4 hours just looking around and reading these sort of articles and evaluating whether or not a VPN or a VPS would be better. And in retrospect a VPS might actually be better for his skype connection. So thanks for pointing me to this again so that I could think on that again. I wouldn't have gone back through it otherwise.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#46
post #39

Earlier quoted context omitted.

I'm not sure how downloading Game of Thrones is connected t oyour troubles.

Perhaps you haven't attempted to view GoT from "unapproved" locations? That is why some people used Hola: to VPN to an "approved" IP address. Parent's troubles are different, but similar, in that his unwanted traffic came from Tor [EDIT: or maybe just a pwned device? I see now that it's unclear...] rather than Hola. I appreciate reading anything he cares to share, as I am interested in running Tor nodes.

I've got very little information on precisely what happened. The wording on the warrant they had for my arrest was that they'd traced an attempt to access child porn using Tor "through undisclosed means". I'm assuming that means the police are running their own nodes and logging any traffic to go through them, but that's pure guesswork.

Also guesswork, but I think the source was probably the one Windows box in the house which I've run Tor on in the past to get round UK ISPs blocking torrent sites. The most likely thing seems to be that it was turned into part of a botnet and used as a Tor relay, but at least until I get that machine back I've got no way of verifying that (and in all honesty, will probably just format the disk and reinstall it).

As I understand it if you're just passively using Tor (on a computer which hasn't been compromised) then it won't cause you any trouble, but if you start running relay nodes or an endpoint then make sure you've got the number of a good solicitor who understands this stuff - the one I got given by the police opened the conversation with "I know nothing about computers", and was quite clearly convinced I was guilty as charged. Thankfully the police do seem to know what they're talking about, and are well aware that an IP address is far from damning evidence, they've looked like their just going through the motions because they're obliged to ever since finishing their interview the first morning.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#47
post #45
post #31

Earlier quoted context omitted.

>Also, there is no guide out there for streamers, or people who are in the public eye on the internet, on how to avoid getting attacked by script kiddies. A famous StarCraft streamer made a guide on how to avoid this: https://blog.destiny.gg/protection-from-ddos-attacks/ I googled "guide to preventing DDOS on twitch" and it came up as the fourth result. How hard did you look?

Yeah I've seen this, and gone over it with him. He has some added exposure due to Steam which is another potential risk. I added a bullet point for that. Thanks for pointing this out but what do you think about the VPS vs VPN. It has an increased exposure to attack because everything else you do on your pc isn't being routed through the VPS. It also doesn't do anything for best practices for avoiding other forms of h…

Skype is definitely #1 on the list. It is remarkably easy to get an IP given a skype username

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#48
post #39

Earlier quoted context omitted.

This is a far more real risk than you might think, I'm currently on the tail end of a police investigation triggered by a device on my home network accessing child porn via Tor. My current theory is that something got added to a botnet and used as a proxy, but I'm not eager to leave things running to find out. While the police have been incredibly professional about this, its been a truly horrible process. Anything i…

I'm not sure how downloading Game of Thrones is connected t oyour troubles.

I'd been using Tor to bypass torrent sites being blocked by UK ISPs - while Game of Thrones wasn't directly connected to my problems, the fact I had two computers with Tor installed definitely didn't do me any favours while being interviewed.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#49

I have zero connection to this company but if you are looking for a reliable, fast, unlimited VPN I would check out Private Internet Access ( https://www.privateinternetaccess.com/ ) I've got a number of friends who use this and I've been using it for a little over a month and have nothing but good things to say. At $40/yr it's well worth it IMHO and provides a native VPN client, PPTP, and Socks5 (They have mobile ap…

I recently bought a year for around $35 with some coupon code or other and honestly...I'm a bit underwhelmed. No matter what settings I use or what node I connect to, my ~100mbps (down) cable connection drops to somewhere between 1-10mbps. I was originally going to set up OpenVPN on my router so everything would go through it but I heard it can tax router hardware and lead to slower speeds so I figured I'd just test…

I have a 50Mbps connection and don't actively notice the speed drop but speed tests (which are not that reliable and I didn't do enough tests to really confirm) show about a 10Mbps difference (slower on VPN). My phone connection is never anywhere near that fast so I really don't notice it there. I'm sure that fast home connections will have more issues (as in being slower) but I'm willing to take the hit (as long as it's only about 1/5 penalty as it appears to be now for me) for the gain.

I've tried running my own VPN but every time I run into some odd issues or it doesn't work on all my devices. PIA's offerings are well worth $40/yr IMHO but I understand that that would be the same for everyone.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#50

Earlier quoted context omitted.

Not sure, but I think I might be on madeofpalk's team on this one too: Superfish was ostensibly doing it to feed data into targeted advertising; Hola has no such (marginally) benevolent excuse.

First, I fundamentally disagree that targeted advertising is in any way benevolent, even marginally. Though that's a debate for another thread. However, they knew full well what they consequences of this mechanism would be[0]. I find it impossible to believe that there was no person at any point along the chain who knew that MITMing all connections would be a security vulnerability[1]. And if that somehow managed to…

There is quite a difference between the security issues of MITM HTTPS and installing a control console. The first is a potential security issue that might lead to something bad, the seconds is already one of those bad things that might happen. Given that this console is as exploitable as it sounds.
Post reply on HN