Live data from Hacker News

Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

torrentfreak.com

61–70 of 83 posts

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#61

Earlier quoted context omitted.

I recently bought a year for around $35 with some coupon code or other and honestly...I'm a bit underwhelmed. No matter what settings I use or what node I connect to, my ~100mbps (down) cable connection drops to somewhere between 1-10mbps. I was originally going to set up OpenVPN on my router so everything would go through it but I heard it can tax router hardware and lead to slower speeds so I figured I'd just test…

That's the same issue I ran into with using a VPN; I know I want to be using one as a (theoretical) enhancement to my privacy, but it was just too slow.

Really? Have you tried getting a server in your own city?

I hardly notice the difference when my VPN is connected.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#62
post #4

Selling user's bandwidth is shady, but consistent with VPN usage (i.e. traffic routing). You can present it as "hey, that's our actual business model, we just forgot to tell you guys" and maybe get away with it. But this: Hola [...] installs its own code-signing certificate on the user’s system. Hola contains a built-in console (“zconsole”) that is not only constantly active but also has powerful functions including…

> This is Lenovo/Superfish all over again. Completely different. Superfish, I'm willing to believe, was just incompetence/indifference. If Hola really is installing a backdoor with high privileges, then that's deliberate malice.

Regardless of incompetence, indifference, or deliberate intent, dubious software is still dubious.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#63
post #39

Earlier quoted context omitted.

I'm not sure how downloading Game of Thrones is connected t oyour troubles.

I'd been using Tor to bypass torrent sites being blocked by UK ISPs - while Game of Thrones wasn't directly connected to my problems, the fact I had two computers with Tor installed definitely didn't do me any favours while being interviewed.

Ok. This was missing from your description. It seemed like what happened to you could have happened outside of people using VPNs/Tor to download pirated material. E.g. you could have even just been running an open access point.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#64
post #4

Selling user's bandwidth is shady, but consistent with VPN usage (i.e. traffic routing). You can present it as "hey, that's our actual business model, we just forgot to tell you guys" and maybe get away with it. But this: Hola [...] installs its own code-signing certificate on the user’s system. Hola contains a built-in console (“zconsole”) that is not only constantly active but also has powerful functions including…

Alright, let's talk specifics.

1. Is the Hola Chrome extension vulnerable to these kinds of issues?

2. How can you remove/fix these issues? Is uninstalling Hola enough?

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#65
post #4

Selling user's bandwidth is shady, but consistent with VPN usage (i.e. traffic routing). You can present it as "hey, that's our actual business model, we just forgot to tell you guys" and maybe get away with it. But this: Hola [...] installs its own code-signing certificate on the user’s system. Hola contains a built-in console (“zconsole”) that is not only constantly active but also has powerful functions including…

> This is Lenovo/Superfish all over again. Completely different. Superfish, I'm willing to believe, was just incompetence/indifference. If Hola really is installing a backdoor with high privileges, then that's deliberate malice.

Installing a backdoor is only ok for operating systems? like Android that can remotely and automatically remove apps? or Amazon that can delete books, etc...

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#66
post #52
post #26

So this is interesting to me because lately, I've been looking for a VPN that would work for my little brother who is trying to make it to the point that he can stream full time on Twitch. The problem is that he has been targeted by script kiddies, who found his IP address through Skype. Shame on you skype. That said, I've been looking for a good VPN for him. It seems that ProXpn isn't as solid as I thought it was be…

>They have also been able to get him banned from Twitch via his IP. This sounds like they have access to his computer (with a RAT or something). You shouldn't be getting IP banned unless you actually break Twitch rules from that IP.

That's kinda what I've been worried about as well. I'll have to look into this more. Thanks though.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#67

Earlier quoted context omitted.

Perhaps you haven't attempted to view GoT from "unapproved" locations? That is why some people used Hola: to VPN to an "approved" IP address. Parent's troubles are different, but similar, in that his unwanted traffic came from Tor [EDIT: or maybe just a pwned device? I see now that it's unclear...] rather than Hola. I appreciate reading anything he cares to share, as I am interested in running Tor nodes.

I've got very little information on precisely what happened. The wording on the warrant they had for my arrest was that they'd traced an attempt to access child porn using Tor "through undisclosed means". I'm assuming that means the police are running their own nodes and logging any traffic to go through them, but that's pure guesswork. Also guesswork, but I think the source was probably the one Windows box in the ho…

> I'm assuming that means the police are running their own nodes and logging any traffic to go through them, but that's pure guesswork.

This is not how tor works. Every connection uses several nodes, and unless they control the entire chain they cannot determine both the origin and the destination of the traffic.

Unless you mean you (or one of your compromised servers) were running an exit node?

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#68

Coming from the receiving end of this. As a user of a anonymous image board this happen recently. It seems that hola is selling botnet access. Of course users are "vetted" that they are not going to use the access for nefarious purposes before they gain access. In this case one of the "vetted" users decided to DDOS said anonymous image board. (Note:Could be some other actors involved, but have confirmation from other…

This was discussed here last week, with contributions from the owner of the image forum:

https://news.ycombinator.com/item?id=9614993

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#69
post #51

Earlier quoted context omitted.

This is completely unrelated to the article.

No, it's not. This article is about Hola which was a VPN and how it was being used for malicious purposes. It stands to reason that people reading the comments are either looking for or seriously considering going with a different VPN provider in light of this news (compounded on top of the story that broke a day or so ago about being used as an exit node). I posted about a service I use that I find reliable and chea…

It's completely unrelated. It's like if there was an article talking about a flaw in Yosemite and you went here and pasted a link to microsoft.com, talking of how reliable Windows is.
Post reply on HN