Hola VPN Already Exploited by “Bad Guys”, Security Firm Says
torrentfreak.com
torrentfreak.com
But this:
Hola [...] installs its own code-signing certificate on
the user’s system.
Hola contains a built-in console (“zconsole”) that is not
only constantly active but also has powerful functions
including the ability to kill running processes, download
a file and run it whilst bypassing anti-virus software plus
read and write content to any IP address or device.
This is going so far into shady territory it becomes indistinguishable from actual malware. This is Lenovo/Superfish all over again.1) Boost MAU by any means necessary 2) Pray 3) Monetize/get acquired
Completely different. Superfish, I'm willing to believe, was just incompetence/indifference. If Hola really is installing a backdoor with high privileges, then that's deliberate malice.
But that's what Superfish was as well. Why are you willing to give Superfish a free pass on doing the same thing?
However, they knew full well what they consequences of this mechanism would be[0]. I find it impossible to believe that there was no person at any point along the chain who knew that MITMing all connections would be a security vulnerability[1]. And if that somehow managed to be the case, that makes them even less credible in my mind, since they're an OEM. They really have no excuse.
[0] I mean, seriously, just look at the name "Superfish". That's not a catchy phrase invented to publicize the vulnerability, like "Heartbleed" and "Shellshock". That's the actual name of the company whose product Lenovo bought.
I'd be mad at Lenovo - because they installed the malware without considering the consequence. I can, however, believe that plenty of decision making people at lenovo were unaware of the risks underlying the software.
So, does lenovo have more in common with the consumer who did something dumb based on poor information, or with the vendor distributing malware.
1. Is the Hola Chrome extension vulnerable to these kinds of issues?
2. How can you remove/fix these issues? Is uninstalling Hola enough?
I use it 100% of the time on my phone and on my laptop unless I'm at work (internal resources that I haven't figured out how to play nice with yet).
In my experience you are right for some endpoints, some of the time, but I haven't had any issue with the one I am currently using (NL based).
I hardly notice the difference when my VPN is connected.
I've tried running my own VPN but every time I run into some odd issues or it doesn't work on all my devices. PIA's offerings are well worth $40/yr IMHO but I understand that that would be the same for everyone.
I'm still guessing it's either something I need to set up differently or it's Comcast somehow throttling it but I've tried both TCP and UDP set to auto and to each of the other choices they give you. I've tried connecting to the closest server and to others. And if I do the speedtests on their site (testing the speed of their connections) they seem to be as fast as you would expect.
Just not quite sure what to try next. I'm only out $35 and on the rare occasions where I really need to use it (occasional TV show torrenting), I have no complaints about longer waits since I'm not paying for them. At this point it's mostly just bugging me that I haven't found a solution.
I am a 3rd party who has no connection to PIA and receive nothing for recommending them. There are countless cases of a HN post concerning some tech or concept where in the comments you can find alternatives that other HN'ers have recommended. I'm unsure how, given all of this, my comment is "completely unrelated to the article".
It was also unclear to me how the browser extension could be used to share user's traffic; it didn't seem like the extension did that, but I didn't read the source code too carefully.
Does anyone has a copy of these extensions?
I am disappointed the Windows and Android apps were vulnerable and that Hola didn't market their software better. It's probably the coolest app since Napster. Yes, it's a botnet of sorts, but the Internet needs a way to let users disassociate themselves from IP addresses. And most proxy services are easily identified.
[1] http://www.csoonline.com/article/2928817/vulnerabilities/hol...
[2] http://blog.vectranetworks.com/blog/technical-analysis-of-ho...
https://chrome.google.com/webstore/detail/hola-better-intern...
Update(Confirmation from TorrentFreak): http://torrentfreak.com/hola-vpn-sells-users-bandwidth-15052...
Legally this is a very risky endeavor though. In Germany for example (where I'm based), people are even scared of sharing their Internet contract with their neighbors since the account owner can be held responsible for any illegal activities (e.g. downloading copyrighted content) that are carried out through his/her connection. Allowing other people to "freeload" on my connection would therefore be a big no-no here. The only way around this risk would be to record and attribute the connection information to each user of the service, but this would of course eliminate many of the advantages of using a VPN again (e.g. privacy).
But there is a very real risk that if someone accesses child pornography and other content using Hola and your internet connection that you will wake up to police searching your home.
While the police have been incredibly professional about this, its been a truly horrible process. Anything in my house which could be used for digital storage was seized, and I spent 9 hours in a police station, variously being interviewed, and sitting in a cell with plenty of time to think about how horribly wrong it could all go. Since then I've been on bail with the condition that I'm not allowed to be unsupervised with anyone under the age of sixteen, which when you have a one year old son is inconvenient to say the least - there was a short time when it seemed a real possibility that he may be taken into care because social services didn't like that my wife believes I'm innocent. It also cost us hundreds of pounds in buying new laptops to use for work while we wait for our existing ones to be returned.
Thankfully the investigation is coming to an end now (in fact I got a call this morning to say the remaining two computers are going to be returned tomorrow), and it looks like everything is going to be ok. I've spent the last few months worrying that maybe one of our computers has also been used as a server.
To come vaguely back on topic, find a better way to get at TV you want to watch, because no amount of Game of Thrones is worth months of worrying whether the next knock at the door is going to be the police come to take you off to jail.
Also guesswork, but I think the source was probably the one Windows box in the house which I've run Tor on in the past to get round UK ISPs blocking torrent sites. The most likely thing seems to be that it was turned into part of a botnet and used as a Tor relay, but at least until I get that machine back I've got no way of verifying that (and in all honesty, will probably just format the disk and reinstall it).
As I understand it if you're just passively using Tor (on a computer which hasn't been compromised) then it won't cause you any trouble, but if you start running relay nodes or an endpoint then make sure you've got the number of a good solicitor who understands this stuff - the one I got given by the police opened the conversation with "I know nothing about computers", and was quite clearly convinced I was guilty as charged. Thankfully the police do seem to know what they're talking about, and are well aware that an IP address is far from damning evidence, they've looked like their just going through the motions because they're obliged to ever since finishing their interview the first morning.
This is not how tor works. Every connection uses several nodes, and unless they control the entire chain they cannot determine both the origin and the destination of the traffic.
Unless you mean you (or one of your compromised servers) were running an exit node?
That said, I've been looking for a good VPN for him. It seems that ProXpn isn't as solid as I thought it was because they found his IP there and were able to (D)DOS not sure how exactly they are doing it at this point, him. They have also been able to get him banned from Twitch via his IP. He needs a VPN with enough bandwith that he can do Twitch and Skype (under a different name), all while playing games. I figured ProXpn would be sufficient, but I've never loaded it like that.
Also, there is no guide out there for streamers, or people who are in the public eye on the internet, on how to avoid getting attacked by script kiddies. Or at least no guide that I've found sufficiently useful, and yes I have googled this. Does anyone here have any references they can point me to that give the "what not to do" for streamers, youtubers, big twitter people, etc? So far I've told him.
-Use strong passwords: LastPass and yes I know this is a point of contention but it's better then what he is using and it's accessible enough for him that he'll actually use it.
-Don't click links in chat: Because duh (Is there a way to verify the safety of said links first)? I know of none. -Obfuscate your Skype id: This seems to be a major tool in finding IPs.
-Keep a personal and a public email: Personal goes to banks and stuff, public goes to everyone else.
-Don't friend people on Steam you don't know.
Am I missing any major advice points that seem easy to follow?
Edit: formatting and added steam bullet point.
A famous StarCraft streamer made a guide on how to avoid this:
https://blog.destiny.gg/protection-from-ddos-attacks/
I googled "guide to preventing DDOS on twitch" and it came up as the fourth result. How hard did you look?
Thanks for pointing this out but what do you think about the VPS vs VPN. It has an increased exposure to attack because everything else you do on your pc isn't being routed through the VPS.
It also doesn't do anything for best practices for avoiding other forms of hacking. So it's a good guide but definitely incomplete.
I looked pretty hard, I spent the better part of 4 hours just looking around and reading these sort of articles and evaluating whether or not a VPN or a VPS would be better. And in retrospect a VPS might actually be better for his skype connection. So thanks for pointing me to this again so that I could think on that again. I wouldn't have gone back through it otherwise.
If he has a fixed IP this is too late for him, he needs to get a new IP for this to be useful.
This sounds like they have access to his computer (with a RAT or something). You shouldn't be getting IP banned unless you actually break Twitch rules from that IP.
So if Skype relays through servers, they get flak for spying, but if they use P2P it's their fault for giving his IP out? The Skype options have a choice for exposing it. "Allow direct connections to contacts only". Make sure it's checked, and don't add bad actors to Skype.
Instead of using the push setting in the server config you can also set redirect-gateway in the client config.
No need to configure anything at remote host, no excessive amount of options. Capable of DNS forwarding, routing of entire traffic or just traffic to chosen remote hosts.
All you think is, "I'm installing a browser add-on to watch Netflix in another country". You sort of assume it's only actually running when you are actively using it for Netflix, but it's running all of the time.
I first noticed something was up when I installed Hola (for Netflix) then all of a sudden Fiddler wouldn't work anymore. Had me completely stumped, then somebody on StackOverflow suggested turning off Hola and that indeed sorted it. - http://stackoverflow.com/a/19905099/969613
Still, creating a new user profile just for watching netflix is recommended.