Live data from Hacker News

Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

torrentfreak.com

1–10 of 83 posts

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#3
Hola really don't make it clear what you are installing when you download it.

All you think is, "I'm installing a browser add-on to watch Netflix in another country". You sort of assume it's only actually running when you are actively using it for Netflix, but it's running all of the time.

I first noticed something was up when I installed Hola (for Netflix) then all of a sudden Fiddler wouldn't work anymore. Had me completely stumped, then somebody on StackOverflow suggested turning off Hola and that indeed sorted it. - http://stackoverflow.com/a/19905099/969613

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#4
Selling user's bandwidth is shady, but consistent with VPN usage (i.e. traffic routing). You can present it as "hey, that's our actual business model, we just forgot to tell you guys" and maybe get away with it.

But this:

  Hola [...] installs its own code-signing certificate on 
  the user’s system.

  Hola contains a built-in console (“zconsole”) that is not 
  only constantly active but also has powerful functions 
  including the ability to kill running processes, download 
  a file and run it whilst bypassing anti-virus software plus
  read and write content to any IP address or device.
This is going so far into shady territory it becomes indistinguishable from actual malware. This is Lenovo/Superfish all over again.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#5
Hola is going down a dangerous route here by turning all of their users into exit nodes, but if they actually make this work it would give them a unique position among all VPN providers.

Legally this is a very risky endeavor though. In Germany for example (where I'm based), people are even scared of sharing their Internet contract with their neighbors since the account owner can be held responsible for any illegal activities (e.g. downloading copyrighted content) that are carried out through his/her connection. Allowing other people to "freeload" on my connection would therefore be a big no-no here. The only way around this risk would be to record and attribute the connection information to each user of the service, but this would of course eliminate many of the advantages of using a VPN again (e.g. privacy).

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#6
I wish to just use OpenVPN but it's not so easy. Certificates - no problem. Forward DNS requests - there is an option for it in the config file. Routing entire traffic through OpenVPN - quite tricky unless you're fluent in command line network management tools and computer networks in general.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#7

Hola is going down a dangerous route here by turning all of their users into exit nodes, but if they actually make this work it would give them a unique position among all VPN providers. Legally this is a very risky endeavor though. In Germany for example (where I'm based), people are even scared of sharing their Internet contract with their neighbors since the account owner can be held responsible for any illegal ac…

Downloading copyrighted content is the least of worries here, that is mostly a private matter.

But there is a very real risk that if someone accesses child pornography and other content using Hola and your internet connection that you will wake up to police searching your home.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#8

Hola is going down a dangerous route here by turning all of their users into exit nodes, but if they actually make this work it would give them a unique position among all VPN providers. Legally this is a very risky endeavor though. In Germany for example (where I'm based), people are even scared of sharing their Internet contract with their neighbors since the account owner can be held responsible for any illegal ac…

Nitpick: Downloading proprietary works is not a problem in Germany, just uploading.

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#9
Coming from the receiving end of this. As a user of a anonymous image board this happen recently. It seems that hola is selling botnet access. Of course users are "vetted" that they are not going to use the access for nefarious purposes before they gain access. In this case one of the "vetted" users decided to DDOS said anonymous image board. (Note:Could be some other actors involved, but have confirmation from other board users).

Update(Confirmation from TorrentFreak): http://torrentfreak.com/hola-vpn-sells-users-bandwidth-15052...

Re: Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

#10
post #8

Hola is going down a dangerous route here by turning all of their users into exit nodes, but if they actually make this work it would give them a unique position among all VPN providers. Legally this is a very risky endeavor though. In Germany for example (where I'm based), people are even scared of sharing their Internet contract with their neighbors since the account owner can be held responsible for any illegal ac…

Nitpick: Downloading proprietary works is not a problem in Germany, just uploading.

[deleted]
Post reply on HN