Live data from Hacker News

Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

torrentfreak.com

51–60 of 83 posts

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#51

I have zero connection to this company but if you are looking for a reliable, fast, unlimited VPN I would check out Private Internet Access ( https://www.privateinternetaccess.com/ ) I've got a number of friends who use this and I've been using it for a little over a month and have nothing but good things to say. At $40/yr it's well worth it IMHO and provides a native VPN client, PPTP, and Socks5 (They have mobile ap…

This is completely unrelated to the article.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#52
post #26

So this is interesting to me because lately, I've been looking for a VPN that would work for my little brother who is trying to make it to the point that he can stream full time on Twitch. The problem is that he has been targeted by script kiddies, who found his IP address through Skype. Shame on you skype. That said, I've been looking for a good VPN for him. It seems that ProXpn isn't as solid as I thought it was be…

>They have also been able to get him banned from Twitch via his IP.

This sounds like they have access to his computer (with a RAT or something). You shouldn't be getting IP banned unless you actually break Twitch rules from that IP.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#53

Anyone know of a safe VPN app to use on Android? I've been using Cyberghost.

Your best option? Pick a provider that uses OpenVPN (or roll your own) and use the open source OpenVPN for Android application => https://github.com/schwabe/ics-openvpn. Done.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#54

Earlier quoted context omitted.

> This is Lenovo/Superfish all over again. Completely different. Superfish, I'm willing to believe, was just incompetence/indifference. If Hola really is installing a backdoor with high privileges, then that's deliberate malice.

> Superfish, I'm willing to believe, was just incompetence/indifference. If Hola really is installing a backdoor with high privileges, then that's deliberate malice. But that's what Superfish was as well. Why are you willing to give Superfish a free pass on doing the same thing?

Yes, that's what Superfish was. However, I'm willing to believe that Lenovo's marketing department was incompetent enough to agree to bundling it without malice.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#55

Earlier quoted context omitted.

Not sure, but I think I might be on madeofpalk's team on this one too: Superfish was ostensibly doing it to feed data into targeted advertising; Hola has no such (marginally) benevolent excuse.

First, I fundamentally disagree that targeted advertising is in any way benevolent, even marginally. Though that's a debate for another thread. However, they knew full well what they consequences of this mechanism would be[0]. I find it impossible to believe that there was no person at any point along the chain who knew that MITMing all connections would be a security vulnerability[1]. And if that somehow managed to…

I think there's a second question. Who are we mad at in Lenovo/Superfish, and who knew about the risks.

I'd be mad at Lenovo - because they installed the malware without considering the consequence. I can, however, believe that plenty of decision making people at lenovo were unaware of the risks underlying the software.

So, does lenovo have more in common with the consumer who did something dumb based on poor information, or with the vendor distributing malware.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#56
post #26

So this is interesting to me because lately, I've been looking for a VPN that would work for my little brother who is trying to make it to the point that he can stream full time on Twitch. The problem is that he has been targeted by script kiddies, who found his IP address through Skype. Shame on you skype. That said, I've been looking for a good VPN for him. It seems that ProXpn isn't as solid as I thought it was be…

try cryptostorm.is as a VPN

Yeah, cryptostorm does a lot to defend users against attacks. Just don't confuse it as a replacement for Tor and you're good to go.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#57
post #16

Hola extension has been removed from Firefox and Chrome download sites. I read the source of the Firefox extension at one point and don't remember seeing any binaries or the so-called "zconsole". But CSO Online [1] is reporting the extensions were vulnerable (despite Vectra [2] not mentioning this). It was also unclear to me how the browser extension could be used to share user's traffic; it didn't seem like the exte…

I looked at the source a long time ago as well. I think chrome API exposes some way to open a socket which they then use as a socks proxy.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#58
post #27

Earlier quoted context omitted.

The Chrome store still is hosting Hola: https://chrome.google.com/webstore/detail/hola-better-intern...

I wonder what caused the surge of all those 5-stars positive reviews within the last 24 hours....

The "bad guys" can rate things too :)

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#59

Earlier quoted context omitted.

So, basically any VC backed, SV based startup?

Well I understand their business model. Given valuation is a function of MAU: 1) Boost MAU by any means necessary 2) Pray 3) Monetize/get acquired

That's the business model of VC's and Founders, not the companies. The company business model will only be established on 3, if they monetize. Selling to the bigger fool not included, ofcourse.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#60
post #51

I have zero connection to this company but if you are looking for a reliable, fast, unlimited VPN I would check out Private Internet Access ( https://www.privateinternetaccess.com/ ) I've got a number of friends who use this and I've been using it for a little over a month and have nothing but good things to say. At $40/yr it's well worth it IMHO and provides a native VPN client, PPTP, and Socks5 (They have mobile ap…

This is completely unrelated to the article.

No, it's not. This article is about Hola which was a VPN and how it was being used for malicious purposes. It stands to reason that people reading the comments are either looking for or seriously considering going with a different VPN provider in light of this news (compounded on top of the story that broke a day or so ago about being used as an exit node). I posted about a service I use that I find reliable and cheap that fills nearly (if not completely) the need that Hola once filled.

I am a 3rd party who has no connection to PIA and receive nothing for recommending them. There are countless cases of a HN post concerning some tech or concept where in the comments you can find alternatives that other HN'ers have recommended. I'm unsure how, given all of this, my comment is "completely unrelated to the article".

Post reply on HN