REVscene - Vancouver Automotive Forum


Welcome to the REVscene Automotive Forum forums.

Registration is Free!You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! The banners on the left side and below do not show for registered users!

If you have any problems with the registration process or your account login, please contact contact us.


Go Back   REVscene Automotive Forum > Vancouver LifeStyles (VLS) > Computer Tech, Gaming & Electronics

Computer Tech, Gaming & Electronics THIS SPACE OPEN FOR ADVERTISEMENT. YOU SHOULD BE ADVERTISING HERE!
Silicon Valley.
Tips & tricks, tech support, home theatre, online gaming, reviews, latest news...

Reply
 
Thread Tools
Old 05-28-2015, 03:10 PM   #1
Zombie Mod
 
Presto's Avatar
 
Join Date: Aug 2003
Location: Langley
Posts: 9,883
Thanked 5,170 Times in 1,552 Posts
Hola! Plug-In Users **SECURITY WARNING**

We use Hola!, regularly. I think it's time to go with the VPN on the HTPC.


Quote:
Your Tool to Access Netflix Content Abroad Is Hijacking Your Internet Connection | Motherboard

On Saturday, a well-known spammer that goes by the name of “Bui” posted more than a thousand junk posts to a few messaging boards on 8chan, a popular anonymous internet imageboard.

He did it just “to disrupt” and “for kicks,” Bui told Motherboard. But he actually ended up taking down the site for a few minutes, thanks to a sort of denial of service attack made of 1,474 nonsense posts, according to the administration of 8chan.

This seemingly minor incident reveals that millions of users of a popular free VPN service called Hola are being sold as exit nodes in a private network, potentially exposing them to having their connections and IP addresses involved in illegal or abusive activities.

Bui’s attack was made possible by a paid service called Luminati, which, until recently, was described by its creators as a “larger, faster and more anonymous” version of the anonymizing software Tor, with “millions” of exit nodes.

What Luminati’s vague website doesn’t say, however, is where these nodes come from. As it turns out, the nodes are actually unwitting users of the popular free VPN service Hola, an app used by millions of people, mostly to skirt geolocation blocks to, for example, watch Netflix abroad. Luminati is owned by Hola Networks.

In practice, if you are a user of the free version of Hola, your connection can be sold as an exit node through Luminati. In other words, your internet connection can be bought and used through Luminati, turning you and other Hola users into a node of what could be described as a voluntary botnet.

This is something that wasn’t widely known until 8chan revealed Luminati and Hola had been used to spam and take down the site. And it’s also something that Hola’s creators never disclosed openly until this week.

The lack of transparency in how Hola sold its users connection was evident on its website too.

The FAQ on Hola’s site didn’t mention Luminati until Wednesday, according to several archived pages of the FAQ. The page was updated after 8chan’s accusation got some traction on Reddit and Twitter, and after I reached out to Hola to clarify whether the accusation was true.

"We can provide [Hola] for free since each user is also an exit node for other users."
Vilenski said that the explanation “actually was there in a different form,” and pointed to the old FAQ, which said: “if you would like to use Hola for commercial use contact us at business@hola.org for a quote.”

Yet, Vilenski himself admitted most users are probably not aware of it.

“Are 100 percent of users aware that they are on a peer-to-peer network and what it means?” he told me on the phone. “The answer is no. Not because we’re covering it, trying not to show them—because we are telling them about it—but because most of them just don’t care, they want a good service, it works well and it doesn’t screw them up.”

“What???? Horrible!” a Hola user told me in chat when I asked her whether she was aware of the fact that Hola allows others to use her connection when it’s idle, and that her connection can be sold through a separate service. “I had no idea. [...] WTF I am deleting it ASAP.”

By becoming an exit node for a Tor-like network, Hola users are exposed to the same risks that Tor exit nodes operators are. Their connection can be abused by someone else, by trafficking in child pornography or downloading illegal material, for example. To police authorities, it would look like the innocent Hola user was responsible for those actions, since his or her IP address would be associated with them.

“If it works the way it is explained, it's a terrible idea to use it,” Raphael Vinot, a security researcher, told Motherboard. “Because you end up being responsible for what the other users of the service are doing.”

In fact, in the case of Tor exit nodes, the Tor Project itself advises against running an exit node at home, given the legal risks. As Motherboard previously reported, Tor exit operators can face police raids and even jail if their nodes are involved in illegal activities.

With Hola and Luminati, millions of users (Vilenski says Hola has 46 millions installs) are exit nodes, likely without realizing it.

Vilenski told me that they don’t allow customers of Luminati to do illegal activities, and that Bui’s account was suspended after the incident with 8chan.

“We’re very, very serious about people not misusing our network,” he said, adding that it’d be “stupid” to use the network for criminal activity. (It’s worth mentioning that the old FAQ did not say that Hola is a “managed and supervised” network and thus not a good fit for criminals trying to hide their identities.)

Yet, when another security researcher posed as a potential customer, a Luminati representative told him that “we simply offer you a proxy platform, what you do with it, is up to you,” and that “we have no idea what you are doing on our platform,” according to chat logs provided by the researcher, who wishes to remain anonymous, to Motherboard.

At the same time, the Luminati website now doesn’t describe the service as “the world's largest anonymity network” anymore, as it did on Tuesday. Now, it’s a “VPN network” and the words "anonymous" or "anonymity" have disappeared from the site.

“The bottom line is they're trying to figure out how to run a profitable business,” Adam Fisk, the founder of Lantern, an app that allows people to become proxies for internet users in countries where there’s online censorship, told Motherboard. “And they're essentially selling out their users to try to figure that out.”

Vinot, the security expert, described it as “an interesting business model.”

“Honestly,” he said, “that level of trickiness is art.”
Advertisement
__________________
Romans 10:9
Presto is offline   Reply With Quote
This post thanked by:
Old 05-28-2015, 05:27 PM   #2
Hacked RS to become a mod
 
SkinnyPupp's Avatar
 
Join Date: Feb 2002
Location: Sunny Hong Kong
Posts: 52,343
Thanked 23,816 Times in 8,190 Posts
I thought everyone knew that those free VPNs were sketchy as fuck anyway Obviously there's some reason they are free...

Go sign up for PIA now! It's only like $4 a month
SkinnyPupp is offline   Reply With Quote
This post thanked by:
Old 05-29-2015, 09:14 AM   #3
It's like going crazy when you're already nuts
 
jing's Avatar
 
Join Date: Aug 2005
Posts: 5,827
Thanked 2,904 Times in 751 Posts
I only ever use Hola for Pandora, lol. Meh.
__________________
my feedback
jing is offline   Reply With Quote
Old 05-29-2015, 09:56 AM   #4
Hacked RS to become a mod
 
SkinnyPupp's Avatar
 
Join Date: Feb 2002
Location: Sunny Hong Kong
Posts: 52,343
Thanked 23,816 Times in 8,190 Posts
Quote:
Originally Posted by jing View Post
I only ever use Hola for Pandora, lol. Meh.
So you're fine with letting people use your IP to download CP and email ISIS?
SkinnyPupp is offline   Reply With Quote
Old 05-29-2015, 11:55 AM   #5
It's like going crazy when you're already nuts
 
jing's Avatar
 
Join Date: Aug 2005
Posts: 5,827
Thanked 2,904 Times in 751 Posts
Quote:
Originally Posted by SkinnyPupp View Post
So you're fine with letting people use your IP to download CP and email ISIS?
My bad. What I meant to say was that, in light of this recent discovery, the loss of using Hola for me is not a big deal since I only used it for Pandora.
__________________
my feedback
jing is offline   Reply With Quote
Old 05-29-2015, 01:30 PM   #6
To me, there is the Internet and there is RS
 
Manic!'s Avatar
 
Join Date: Apr 2004
Location: Nanaimo
Posts: 16,019
Thanked 7,384 Times in 3,466 Posts
Quote:
Originally Posted by SkinnyPupp View Post
So you're fine with letting people use your IP to download CP and email ISIS?
So you're fine paying a company that lets people download CP and email ISIS anonymously?
__________________
Until the lions have their own historians, the history of the hunt will always glorify the hunter.
Manic! is offline   Reply With Quote
This post thanked by:
Old 05-29-2015, 04:31 PM   #7
Rs has made me the woman i am today!
 
Mr.Money's Avatar
 
Join Date: Jan 2011
Location: Vancouver DT
Posts: 4,314
Thanked 2,796 Times in 915 Posts
"Free"... you are the product,of course there is a catch
__________________
Fly Your Own Flag.
Mr.Money is offline   Reply With Quote
Old 05-29-2015, 06:44 PM   #8
Hacked RS to become a mod
 
SkinnyPupp's Avatar
 
Join Date: Feb 2002
Location: Sunny Hong Kong
Posts: 52,343
Thanked 23,816 Times in 8,190 Posts
Quote:
Originally Posted by Manic! View Post
So you're fine paying a company that lets people download CP and email ISIS anonymously?
I don't think you get it...
SkinnyPupp is offline   Reply With Quote
Old 05-30-2015, 11:25 AM   #9
To me, there is the Internet and there is RS
 
Manic!'s Avatar
 
Join Date: Apr 2004
Location: Nanaimo
Posts: 16,019
Thanked 7,384 Times in 3,466 Posts
Quote:
Originally Posted by SkinnyPupp View Post
I don't think you get it...
I do get it.
__________________
Until the lions have their own historians, the history of the hunt will always glorify the hunter.
Manic! is offline   Reply With Quote
Old 05-30-2015, 08:26 PM   #10
Hacked RS to become a mod
 
SkinnyPupp's Avatar
 
Join Date: Feb 2002
Location: Sunny Hong Kong
Posts: 52,343
Thanked 23,816 Times in 8,190 Posts
No you don't
SkinnyPupp is offline   Reply With Quote
Old 05-31-2015, 02:22 AM   #11
To me, there is the Internet and there is RS
 
Manic!'s Avatar
 
Join Date: Apr 2004
Location: Nanaimo
Posts: 16,019
Thanked 7,384 Times in 3,466 Posts
Quote:
Originally Posted by SkinnyPupp View Post
No you don't
Yes I do. You are like those people that tell me I should have a password on my wifi router.
__________________
Until the lions have their own historians, the history of the hunt will always glorify the hunter.
Manic! is offline   Reply With Quote
This post FAILED by:
Old 05-31-2015, 03:47 AM   #12
Hacked RS to become a mod
 
SkinnyPupp's Avatar
 
Join Date: Feb 2002
Location: Sunny Hong Kong
Posts: 52,343
Thanked 23,816 Times in 8,190 Posts
Trust me, you have absolutely no clue what you're talking about.
SkinnyPupp is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off



All times are GMT -8. The time now is 02:45 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
SEO by vBSEO ©2011, Crawlability, Inc.
Revscene.net cannot be held accountable for the actions of its members nor does the opinions of the members represent that of Revscene.net