Swing VPN app is a DDoS botnet
lecromee.github.io
lecromee.github.io
At this point one must assume that any "free" vpn software is free because it uses its install base for DDoS / other traffic abuse.
Where else would they get the 100 million users?
If they're truly hijacking end user clients, why don't you point to the section of their open source client that's responsible for that?
https://github.com/NordSecurity/nordvpn-linux
Easy enough to prove.
Credit or debit card, Klarna, PayPal, Google Pay, Cryptocurrencies
https://news.ycombinator.com/item?id=22532682
NordVPN used residential proxies at one point to enable access to Disney+ and other streaming services; that's a world apart from hijacking end-user connections.
They've got an open source client. Where's the code that's turning end users into endpoints?
I'm sorry but that's incredibly sketchy
But yes, it's also sketchy with the other implications and all, and not the least what kind of traffic that people want to hide that you're unknowingly a proxy to!
The standard linux vpn client clearly has some exitnode capabilities.
"We are a market-leading web intelligence collection platform, driven by the highest business ethics"
I think that's a bit debatable!
Which then makes this viewpoint not that useful at all.
And this issue already been long summed up as “nothing is free in life.”
You might not like something, but does it really make it a dilemma in the sense of 'having to pick which of the 2 bulls horns will impale you?' - i don't think so. (interesting points though, and perhaps i am still missing your point!)
Obviously for consumer it is better to be able to scrape sites. It is only those store owners (greedy capitalists) who do not want consumer to know that their prices are inflated.
Another thing is looking for some information, it is better just to have a language model go around the web and summarize the data for you rather than read someone's site with white letters on black background and weird font.
If a store owner doesn't want the reach, it's their loss. IMHO no need for a DoS attack.
Individuals also, IMO, have a right to sell access to their network for scraping-via-proxy. But they should be prepared to deal with the consequences, like a potential IP ban. Most people using VPNs that resell their residential network for scraping probably don’t know that’s happening, and many scrapers are indeed doing something bad, which is why there is a disdain for the practice.
Yes, I realize that LinkedIn is a self aggrandizing cesspool. I never post anything there.
[0] https://www.techradar.com/news/judge-orders-mediation-after-...
I never looked into that, but always used Nord VPN via the official OpenVPN client.
I formerly worked in the consumer VPN space (an older, but once quite big player), and use cases go from content access (including everything from getting US Netflix from Germany, to sidestepping national firewalls), to general-purpose paranoia about IP logging by websites. There are also lots of cases that get marketed a bit too liberally by companies like Nord, Express, and the hydra that is Kape, like that VPNs can add meaningful security to submitting payment information online; this is despite the fact that it's harder than ever to MITM payment sites.
It's generally agreed that the state of public Wi-Fi combined with evolving web standards and sky-high HTTPS adoption makes VPNs largely, though definitely not completely obsolete for protecting yourself against someone sniffing traffic at Starbucks.
Having said all that: if you need a VPN and a lack of port-forwarding isn't a dealbreaker, I wholeheartedly recommend Mullvad. My former company never worked with them directly but our team had immense respect for their integrity, ethics, and approach to developing a quality product.
The problem I have with all the "checks" that press foundations do is that none of them seem to know what they're talking about in regards to what tech is trustworthy and audited, and what is not.
I found a nice article about it, skimmed through it and seems to be true and reflect my own research that I did for my cyber defense network [1]
[1] https://vpnpro.com/blog/hidden-vpn-owners-unveiled-97-vpns-2...
They shouldn't keep logs but even if they did there's no personal information metadata.
Just your personal IP, which is via your provider very tied to your person.
(In many places it can trivially linked to your real ID, if there is a court order)
Unless the use case is circumventing region barriers.
If you are just a file sharer or normal low level criminal I doubt the CIA (or whoever may have infiltrated Mullvad) would give anyone your IP.
1. https://www.svt.se/nyheter/lokalt/vast/husrannsakan-mot-vpn-...
Or NSO or some other private actor did so, and now every dictatorship has access to it, and we all know how broad their “terrorist” definition can be…
If you are a dissident in Iran, you really should not trust some random VPN. Tor is probably safe enough, but there is also no guarantee, that the chinese are not sharing with them, because as far as I know (but last time I checked has been some years), many nodes are china based. So they might know.
But if all you do is pirating some videos, then this is not something to worry about.
Just so everyone is clear on a few facts, it is possible for a TLA or agency from another large government to just try to blackbox the VPN nodes and be done with it without needing to infiltrate Mullvad. Just pressure the network provider of the VPN instances to get flow data, and at that point they can match up traffic going in and out and the VPN disappears from the picture.
Mozilla gained good will over the years and I like the browser. The vpn is fairly seamless and permissive for number of devices. I understand it is a wrapper on Mullvad and we are paying a healthy overhead. Still, it is worth it because I’d trust that if the vpn service provider behaves in bad faith that Mozilla will be able to quickly respond and adopt another provider. Whereas if it were up to me I may hear of it years later and not necessarily know what service to adopt instead.
My use is merely hoping to reduce tracking based on ip. I wouldn’t trust it to be subpoena proof. I’m not into pirating music anyway.
Actually, they rather lost a lot over the last years, with various shady things, like tracking for advertisement enabled from the browser by default (called studys).
So sadly, I also would not trust them as a VPN. Way more than some random VPN service, sure, but not completely. But I also do not know of a better alternative.
I've lost track of the times a Mozilla misstep has resulted in people here saying that's the reason they're switching back to chrome, which I find frankly ridiculous. Also, the whole damn thing is open source, so it's not like they're really hiding anything, people just don't care until someone makes a stink and then all of a sudden everyone cares a lot.
No browser is perfect, but Mozilla is definitely one of the better ones for anyone privacy conscious.
We technical folks get it and can deactivate it.
Every non technical person I know, who still uses firefox does not know and has all the defaults activated, until I change it for them.
So sure, they are still better than google and microsoft, where I just assume that they track everything, but that is a really low standard.
Some of the other incidents were overblown but the Cliqz thing shows of a company culture where user data is something which can be sold to make a profit, which is essentially what they did, and not something which is vital to protect.
Yes, it was many years ago now but I have no reason to think that they cleaned up their company culture.
All Mozilla know is the mullvad username. Mullvad don’t know the credit card details of the purchaser. To link a given vpn ip to a specific credit card would require compromising mullvad and Mozilla.
(Or of course the normal way of fingerprinting which doesn’t rely on IPs)
Now sure you can buy mullvad via cash, but that’s far more work. Using Mozilla as a reseller feels like one more step in the chain
This might be useful:
I am also familiar with a recent police investigation where law enforcement subpoenaed NordVPN and the company replied, essentially, that they had no information connecting a particular IP address, at a specific date and time, to any specific user.
https://www.pcmag.com/news/nordvpn-actually-we-do-comply-wit...
They don’t keep traffic logs
Not sure about the links to Proton though.
Hola is ran by luminati/bright data which absolutely are pure scum scam botnet-enabling shitbag company.
Most people exclusively care about scum vs. not scum, and all but vuln-dev level sources shouldn’t distinguish.
Maybe HN fell on the savvy side of this at one point, but it was so long ago…
I will note your posts are reading as activism/consensus building, which gets people removed from hackernews. So you might want to dial it down.
Nuance matters! While the guy who makes sexist jokes and the guy who will rape you if ever alone with you are both scum, that difference really really matters.
I wrote an article in 2013 about why free proxies are free [1] and got so much feedback from people who had never thought about that.
This was back in the HTTP only days (very shortly before the Snowden leaks) and it was a good way to make money because your proxy could just replace all ads on all sites with your Google ads and you could see all communication. Insane from today's view
In 2015 I did a followup post where I analyzed the existing proxies for any manipulation of the original site and found that 80% of the free proxies did in fact change something [2]
[1] https://blog.haschek.at/2013/05/why-free-proxies-are-free-js...
[2] https://blog.haschek.at/2015-analyzing-443-free-proxies/
> I have to give props for Swing VPN teams creativity to bypass security measure of Apple appstore and Google PlayStore but it is sad that Apple/Google security systems does not have some automated ways to detect these types of actions.
It's a tricky problem. The amount of attack traffic from an infected device is negligible and very little of it is visible to the operating system due to TLS. It's also presumably intermittent (there's no point in keeping an attack ongoing forever; you stop when the site has found a way to defend itself), so just running the app for a while as part of validating an update might not show any suspicious behavior. The suspicious part is in the configurations downloaded from the CnC servers, not packaged with the app, so static analysis won't help.
The only reliable option for catching these proactively thatI can think of would be to use some kind of aggregate telemetry from all the app installations combined, but that'd be incredibly scary both in terms of privacy and the blast radius when something goes wrong.
> Currently in the beginning of June 2023 it has over 5 million install base on android
That's not really a reliable number. It's more like "the number of distinct users who had this app installed at some point". AFAIK it doesn't get decremented when somebody uninstalls the app, and doesn't go up when somebody installs it for a second time on a new device. Those factors might cancel out, might not.
Aren't there free APIs to get your IP address, like ifconfig.me? This sounds like more work but probably doesn't have any chance of running into rate limits.
I wonder what's the 'sliver' property
I find this very odd that they would target those websites. What would be the gain of taking down those websites _for anyone_. I doubt that the reason is political.
P.S. Turkmenistan is probably the worst country when it comes to free internet. Almost all IP addresses are blocked, with very few websites (mostly google-owned) being reachable. The entire population is desperate for VPN (preferrably free). They are not educated about malwares, or anything about security, so they will download anything that promises free internet.
These DDoS tools appear to take things to the next level, and an undeniably blackhat direction.
There's another story on HN today, the famous story of CIA setting up shell companies to buy Soviet titanium for the SR-71. The Soviet counterintelligence was completely fooled. This stuff is bread and butter for the more aggressive intelligence departments around the world.
I think that shit like this should be reported to law enforcement, so that they can route it to national intelligence or counterintelligence. They can decide to shut it down or investigate further. Opening the case in public let's the other side do a quick cleanup.
lol
If I had a known user agent doing a curl to icanhazip or whatnot, could that eventually be blacklisted?
Until it's discovered, traffic to their own servers would appear the most innocuous. After that, the app gets kicked off the store and the server doesn't matter.
Unless it doesn't actually do any VPN and it's all just a farce, lol.
The vpn functionality is secondary.
"Some people wrote me saying that the DDOS is not happening on ios devices. Just did a quick check and you guys are right. iOS app is using different way to do VPN and also does not do anything suspicious. I should appologize to you and to Appstore team for my lazy extrapolation without actually checking it."
Many vendors surreptitiously use user nodes as exit nodes and route traffic in suspect ways.
VPN software stack is surely a major target for state and non-state actors to monitor and exploit.
If so, would simply having an account and exe file be enough to argue “my wifi is open, I didn’t download all that XYZ!”
No body has ever been convicted with their home IP as the only evidence.
Convicted? No. Raided? Yes.
I partially blame the myriad YouTubers who happily push these to their fans to supposedly protect their privacy and protect their computers from harm.
They're still marketed as a way to prevent macular degeneration?
How could it be blocking any significant amount of light in the visible spectrum and still be clear? I'm sure the "16x" claim is true, but normal lenses block a small amount of light. 16 times nearly zero is still nearly zero. It's just a marketing gimmick.
Zenni Optical also sells lenses which are orange. I'm sure that actually does block a significant amount of blue light, but I also know from my experience visiting optician offices that many consumers are buying the first kind.
I'm aware of studies which link blue light to eye fatigue and disruption of the circadian rhythm but I'm skeptical that blocking 5% of blue light or whatever could have a perceptible medical effect.
With that being said, I don't feel strongly about claims like the 16x thing if its actually true (just a bit misleading). My comment above was mostly about the claims that they prevent macular degeneration which there is no evidence for. And regulators are right to jump in before it gets too bad, otherwise why stop at macular degeneration? Just say your lenses prevent hair loss and skin cancer while you're at it.
That's... not exactly true, given what definition of "protecting" you follow. VPNs definitely can protect against some forms of attacks that plain old HTTPS can't:
- malicious QoS/routing policies at the ISP (or a public WiFi operator) that, say, down-prioritise or throttle stuff like YouTube, or route it through backed-up links (German Telekom was infamous for bad peering towards high traffic sites including Youtube [1] or where they all but extorted money from "double paid traffic" from server owners [2])
- ISPs hijacking DNS for a myriad of reasons (NXDOMAIN ad-hijacks, government-ordered censorship, thinking they can offer "improved" DNS service by simply answering all requests going out on UDP53 with their own servers [3], ...)
- ISPs and WiFi operators listening on DNS requests or doing traffic analysis to sell to advertisers [4]
- other devices on the network attacking your machine (e.g. in a coworking space) - proper VPN software like Cisco will "cut off" all communication with the outside with the exception of the remote VPN endpoint IP and DHCP.
The part about malware is more sketchy, but in case the VPN operator uses something like PiHole and other shared lists of malware domains and IPs to blacklist common-known vectors and C&C sites, it is a valid statement.
[1] https://winfuture.de/news,63355.html
[2] https://www.golem.de/news/hetzner-und-netzneutralitaet-extra...
[3] https://labs.ripe.net/author/babak_farrokhi/is-your-isp-hija...
[4] https://www.washingtonpost.com/wp-dyn/content/article/2008/0...
I agree though that a lot of YouTubers have grown fat and comfortable with VPN providers led largely because of the financial incentives over their desire to protect fans.
Famously described by Tom Scott —
[How it started https://www.youtube.com/watch?v=WVDQEoe6ZWY
[How it's going] https://www.youtube.com/watch?v=Wif1EAgEQKI&t=320s
On the other side of that, some random Joe has probably purchased access to a set of these 'residential proxies' and is using them to scrape flight data from the airline site the article author noticed, with some of those requests being sent over the author's connection.
Many 'free vpn' and 'free proxy' apps engage in this behavior, you may proxy your requests via their connection, but they also proxy their requests via yours, generally reselling that access to someone who finds your IP address to be of value to them due to the fact that it's not a datacenter address.
It's certainly questionable to straight up unethical either way, especially so if the service doesn't disclose to you that they're doing that, but on the other hand I find the author's DDoS conclusion to be so contrived and out of touch with reality that I had to write this comment.
"urlList": [
{
"url": "https://turkmenistanairlines.tm/tm/flights/search?_token=J8SxUX2Qwzltw4LiHsRHTCtfthgBYxf4hyI8oNly&search_type=internal&departPort=TAZ&arrivalPort=CRZ&tripType=rt&departDate=4%2F22%2F2023&arrivalDate=5%2F4%2F2023&adult=1&child=0&infant=0&is_cship=on",
"method": "GET"
},https://developers.google.com/android/play-protect/pha-repor...
(It is a bit odd that there's no DoS category on the report form, despite it being listed as a category on their taxonomy page at https://developers.google.com/android/play-protect/phacatego..., but I expect that you can just enter that in the "other" free text field.)
(To answer the inevitable: Mullvad and Proton are the legitimate offerings that spring to mind.)
Not a rhetorical question: When is the last time you’ve visited a non-HTTPs website?
> you wont be part of a traffic redirection network
These are also only a concern for HTTP.
Other common use cases for VPNs include geo-unblocking, and hosting IP ranges are commonly blocked by streaming sites.
I can’t think of a good reason to use a VPS for a VPN anymore these days, to be honest – the privacy/security landscape has changed dramatically over the last few years.
You probably get better privacy these days on public (free/unauthenticated) Wi-Fi than you would on many "free" or paid VPN services.
Need to bypass geoblocking, e.g. when traveling? You'll likely need a residential IP -> use your own network at home (e.g. Tailscale or a self-setup solution) or one of the shady "residential IP broker" utilizing commercial VPNs out there.
Want privacy (from visited sites' trackers)? Your VPS is definitely not that: The IP is static, and if you send your entire traffic through it, this is much more fingerprintable than even residential web usage. -> Use a commercial VPN that you can trust (I don't know many) or something like iCloud Private Relay or TOR.
Want privacy from your ISP tracking you (including public Wi-Fis), and only that? Then, yes, a VPS-based VPN might be for you (or any of the commercial VPNs out there).
But my claim is that the last one (and only that) is probably not the biggest concern of most people.
I’ve run a private vpn for extended family off of my residential connection for this reason. It helps them and me.
On another note, one of the first firewall rules that many of my clients ask for is to block cloud servers IP ranges.
Installing open VPN is like carrying the One Ring to Mount Doom. I’ve installed operating systems, databases, web servers, full LAMP stacks that took less effort.
FTA:
> I have to give props for Swing VPN teams creativity to bypass security measure of Apple appstore and Google PlayStore but it is sad that Apple/Google security systems does not have some automated ways to detect these types of actions.
You couldn't rewrite it to just be:
I have to give props for Swing VPN teams creativity to bypass security measures of the Google PlayStore but it is sad that Google security systems does not have some automated ways to detect these types of actions. (Note: A previous version mention the Apple App Store but the iOS version does not appear to participate in these DDOS attacks)
The explanation about not fixing the article is longer that the entire paragraph that only needed 22 characters removed (and potentially a sentence added). I don't get it.
All paid VPNs == honeypots
You think they are honeypots?
I would personally stay away from proton for anything, vpn or email, I’ve been following their news since started and a lot of sketchy things about them, you can read about some of it here (1), the CEO of protonvpn and Tesonet (data mining company) is the same person, they used to have a lot of vulnerabilities and bad patching system (2)(3). There are other stuff about it can’t find the reference for right now (hmmm?), but I can dig deep later if needed.
Mullvad has been better so far, I personally use / used it, last two years been really bad with their network, and recently they stopped port forwarding (4), but again, you have to trust them.
(1) https://encryp.ch/blog/disturbing-facts-about-protonmail/
(2) https://blog.talosintelligence.com/vulnerability-spotlight-m...
(3) https://www.scmagazine.com/news/network-security/protonvpn-a...
(4) https://mullvad.net/en/blog/2023/5/29/removing-the-support-f...
The second and third articles are over 5 years old, that attack also requires a device to already be compromised. Proton VPN undergoes annual security audits and is also open-source, so anything "sketchy" (like if the app were actually data mining) could be quite easily and quickly discovered.
There's no way to conclusively prove trustworthiness, but there's a lot that Proton does in terms of trust that no other VPN can match: https://protonvpn.com/blog/is-protonvpn-trustworthy/
NordVPN are probably fine. But if I were actually keen to avoid government monitoring, I'd probably look for a VPN service that doesn't put much effort into marketing to an English speaking audience. And I'd combine that with at least one more layer of indirection.
https://play.google.com/store/apps/details?id=com.switchvpn....
Any pointers on where you'd start would be appreciated though.
Running Wireshark or an equivalent smartphone app is easy. Understanding it probably a lot less so, but network protocols can be googled. One trick to not get overwhelmed too much is to not use the device you're analyzing too much so you only collect background traffic. Another is to filter out traffic you can't do much with. A lot of traffic is encrypted by TLS these days, but a lot of data is still visible, like in this case a random domain that you shouldn't be seeing. However, except for that very first TLS packet, you won't be able to see anything interesting in the rest of the stream, which can be gigabytes in size!
The real challenge for network analysis is that 99% of the time, your network is not doing anything strange (or at least interesting). If you want to find something, you can try seeking out sketchy apps (free VPNs are a nice target, they're almost always shady) but there's no guarantee that you'll find anything. Or you can dive deeper if you think there's more to be found.
In the case of Android apps, those are often easily decompiled into either VM byte code (smali) or even obfuscated Java code. apktool, jd-gui, or ghidra can usually get some kind of readable-ish code out of an app. There's also an excellent online APK decompiler if you trust that. Grabbing the APK is quite easy, you can find apps that do this or otherwise you can use Android's debugging tools to pull the app off your phone.
Depending on how obfuscated your target is, complete reversing may be difficult. You can often take shortcuts, though, like looking for interesting strings or setting files.
Another nice trick to employ when reversing applications is to run Frida. Frida is a toolkit for injecting arbitrary code into another process. You can either inject Frida into an APK you've downloaded, or if you've got a rooted device run it against any unmodified app. It works on other platforms as well! With Frida you can write Javascript in the Chrome dev tools to control the app, list objects and functions, call random APIs, whatever you need, all without decompiling.
Another trick I like to employ is using mitmproxy to man-in-the-middle apps so you see every HTTPS call they make, the responses, and you can even mess with the traffic (change responses, alter requests, you name it). The tricky part is to get the app to accept your TLS interception, but there are Frida scripts that will disable validation of TLS certificates in all manner of apps, giving you the ability to inspect them.
That last part can also be very useful if you're reverse engineering an API. I've written a blog post about a Norton VPN where I did exactly that, not because Norton was being shady, but because I wanted to use the OpenVPN config file on my laptop and they didn't provide me with the necessary files (even though they totally could have).
Not the best writing, it was mostly a recap of the things I did for myself if I ever needed to fetch that file again, but I think the core concepts may still be useful.
How does a clientless ngrok alternative help here (which tunnels server traffic), and why is it even necessary given that many OSes support at least one VPN protocol natively?
In this example, Swing VPN is offering a "free VPN" service, but they actually pay for it with botnet contracts.
For twenty dollars you can take down an airline that lost your luggage and didn't bother trying to find it back. It's childish behavior, but someone is petty enough. Store didn't honor their warranty? Pay five dollars and they'll lose more money in lost sales than their refusal would've cost them.
Sometimes it's not just petty criminals either. Extorting businesses with these types of attacks is all too common. "Pay us $x or your website will be down for months" is an easy threat to make, especially if you can take down a business for a fraction of their lost revenue. Attack twenty or more companies, wait for one of them to pay out and you've made yourself a huge chunk of cash.
There are all kinds of reasons to hire these botnets. Developing these botnets isn't very hard either, especially if you can sneak a trojan into a useful software library or hack someone else's library. You just have to think real scummy.
https://scrapestack.com/faq: Residential ("premium") proxies provide IP addresses that are connected to real residential addresses and devices, which makes them much less likely to get blocked while scraping the web. We highly recommend using residential proxies for your web scraping needs as they make it easy to work around geo-blocked content and harvest data at scale.
DDoS is just freedom of speech. Just some people have louder voices than others which is not a foreign concept to the rest of us. So long as the VPN (or whatever) operator mentions it in their terms of service (e.g. if they rely on user resources), it's fine IMO.
There needs to be an incentive for companies to implement good quality software and to not be evil (not to make enemies) and legalizing DDoS might help create such an incentive.
Getting DoS-ed is sufficient "punishment" for not being able to mitigate a DoS. "their fault for accumulating too many enemies" is dubious considering that one "enemy" is enough for a DoS and that the DoS-er might not actually have something personal against the target.
> DDoS is just freedom of speech. Just some people have louder voices than others which is not a foreign concept to the rest of us.
I wouldn't characterize a DoS-er as "the one with the louder voice". I hope you don't think doxxing and revenge porn should be legal too. Anyway, there's the saying "My right to swing my fist ends where your nose begins."
I used to think like that but in reality, the way the world really works is that anyone can punch you in the nose if they really want to... Whether or not the assailant will be punished for that depends on who got punched and who did the punching.
Access to the justice system is asymmetrical. Big corporations or organizations are often not held liable for many of their 'crimes' on a per-infraction basis because their victims have a much weaker voice; they can basically do all the crimes they want and then, if they harm enough people and they get caught and there is a class action (a lot of IFs), they MAY pay a lump sum fine at the end.
I prefer the ancient Roman system where some crimes were forgiven based on context (e.g. retaliation was allowed). I think it would bring back the human element to the justice system. People should be allowed to take the law into their own hands provided that their cause can be morally justified in front of a random sample of citizens.
Also, legalizing DDOS would simply enable protection racket type schemes (Mirai/Protraf Solutions) and affect small businesses without the ability to defend against them.
I think vigilantism would better allow human nature to shine through. E.g. you can talk and reason with an extortionist directly but you cannot do that with a corporation or other large organization.