Advertisement

We need your help now

Support from readers like you keeps The Journal open.

You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.

If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.

This hugely popular Chrome extension could use your computer to hack websites

Hola is selling its users’ bandwidth.

ONE OF THE most popular Google Chrome extensions is selling its users’ bandwidth, largely without their knowledge — and it can be used by hackers to maliciously attack websites.

Hola is a VPN — a “virtual private network”.  As streaming platforms like Netflix have risen in popularity, there has been a corresponding boom in VPNs, which help users circumvent the regional restrictions that forbid Americans from watching certain BBC shows, or people in Ireland from watching some shows on Comedy Central in the US.

One of the most popular of these is Hola.

Unlike most VPNs, it’s free to download as an easy-to-use browser plugin in the Google Chrome store. It currently has more than 6 million users. CNN Money said, “Hola is changing the way we use the internet”.

To avoid the need for fees, Hola uses a peer-to-peer system, routing users’ traffic through other users’ connections. Someone in Ireland trying to watch an American-only service, for example, might be routed through an American user’s internet connection.

But it is also selling access to users’ bandwidth for a profit, via the service Luminati, Hola discloses on a little-read FAQ page.

PastedImage-50290 Screengrab from Hola on the Chrome Web Store.

Luminati lets users buy access to the Hola network for a fee, for instance if users need a secure way to route commercial traffic anonymously. This revenue keeps Hola free for users.

But in the wrong hands this same function can transform its networked users into an unwitting botnet, defined as “a number of Internet computers that, although their owners are unaware of it, have been set up to forward transmissions to other computers on the internet”.

Frederick Brennan found that out when Hola was used to attack his website earlier this week.

Brennan, often known by the online moniker “Hotwheels,” is the administrator of 8chan, a countercultural online messageboard. Earlier this week Brennan was targeted by thousands of “legitimate-looking” posts, “prompting a 100x spike over peak traffic,” he wrote in a blogpost.

The attack originated with a user called “Bui” (who has attacked 8chan before), who later told Brennan he had used Hola’s Luminati service to carry it out.

‘It got through our screening process’

Hola’s founder Ofer Vilenski confirmed to Business Insider that Bui had “got through our screening process.” he also said that the attack had been ended and Bui banned from the network.

Hola’s site explains in an FAQ how the peer-to-peer network works. But before Brennan reached out following the attack, there was only a brief acknowledgement that it might be used for “commercial” purposes, and no mention at all of Luminati, which has been in operation since at least October 2014. (A fuller explanation has since been added.)

With no indication on the homepage, it’s doubtful that many users realise that Hola is selling their bandwidth. A Reddit thread discussing the subject is filled users expressing their surprise and asking how to uninstall it (and in a strawpoll of people I know who use Hola, none were aware of this).

“Even if they had said it all along in their FAQ,” wrote one commenter on news site Hacker News, “it’s still infuriatingly disingenuous for someone to act as if anyone ever browses to Hola’s site and reads their FAQ either before or after installing the Hola malware extension.

No ordinary person will ever do this.

The peer-to-peer nature of the site also potentially puts users at risk. On the anonymising Tor network, which works in a similar way, users have to opt-in to become an “exit node” — a point at which traffic can come and go, in and out of the network. But everyone using Hola is an exit node. This implies that if someone is using the plugin to conduct illegal activity through your connection, law enforcement might suspect you’re to blame.

Brennan believes that the company is “acting extremely irresponsibly,” and wants to “help users learn that others are using their internet connections without their knowledge or express permission”.

Hola’s Vilenski told Business Insider that there was nothing uniquely vulnerable about Hola’s VPN — the hacker “could have used any commercial VPN network, but chose to do so with ours.”

Furthermore, the company has been “listening to the conversations about Hola and while we think we’ve been clear about what we are doing, we have decided to provide more details about how this works, and thus the changes [to the website] in the past 24 hours.”

- Rob Price

Read: The Government is thinking up new ways to stop you from being hacked >

Readers like you are keeping these stories free for everyone...
A mix of advertising and supporting contributions helps keep paywalls away from valuable information like this article. Over 5,000 readers like you have already stepped up and support us with a monthly payment or a once-off donation.

Published with permission from
View 23 comments
Close
23 Comments
    Install the app to use these features.
    Mute Jonn
    Favourite Jonn
    Report
    Dec 25th 2024, 7:23 AM

    I wonder will the Marxist rabble who recently had the audacity to gatecrash a Christmas mass in progress at a Dublin Cathedral..an outrage completely ignored by most of the media..to make some point about Israel and Gaza be out feeding the homeless on Christmas day? Somehow I very much doubt it!

    130
    Install the app to use these features.
    Mute Thomas Sheridan
    Favourite Thomas Sheridan
    Report
    Dec 25th 2024, 7:54 AM

    @Jonn: I don’t think that Hamas or their fan clubs are noted for their charitable endeavours, especially around Christian festivals.

    81
    Install the app to use these features.
    Mute Jonn
    Favourite Jonn
    Report
    Dec 25th 2024, 8:04 AM

    @Thomas Sheridan:
    That’s true! I’m curious why the leftist rent a mob chose a Christian ceremony to disrupt..luck of the draw I suppose? Would they have been as quick to invade a mosque, or even a synagogue,which in the circumstances might have been more aligned with their ’cause’? But like the cowards they are they chose a church,an easy,safe target.

    111
    See 10 more replies ▾
    Install the app to use these features.
    Mute H Woo
    Favourite H Woo
    Report
    Dec 25th 2024, 8:22 AM

    @Jonn:
    Away sking with Mummy And Papa.

    29
    Install the app to use these features.
    Mute Jonn
    Favourite Jonn
    Report
    Dec 25th 2024, 8:28 AM

    @H Woo:
    Quite possibly, the ‘climate crisis’ will have to wait while they fly into Italy for a nice festive break from virtue signalling!

    36
    Install the app to use these features.
    Mute Jack Hayes
    Favourite Jack Hayes
    Report
    Dec 25th 2024, 8:34 AM

    @Jonn: If Jesus was born now (assuming he was ever born or existed) he would undeniably be Palestinian. Unfortunately, the odds of him surviving today in Palestine might not be very good.

    17
    Install the app to use these features.
    Mute Jonn
    Favourite Jonn
    Report
    Dec 25th 2024, 8:42 AM

    @Jack Hayes:
    Jack I 100% support the Palestinians, and denounce everything Israel is doing,it’s an abomination, but still doesn’t explain why these morons thought disrupting a Christmas mass was relevant to their cause?

    43
    Install the app to use these features.
    Mute Niall Lappin
    Favourite Niall Lappin
    Report
    Dec 25th 2024, 9:32 AM

    @Jonn: jesus was Marxist before Marxism

    6
    Install the app to use these features.
    Mute Niall Lappin
    Favourite Niall Lappin
    Report
    Dec 25th 2024, 9:33 AM

    @Jonn: Mayne highlight the churchs silence on the GAZA situation

    3
    Install the app to use these features.
    Mute donal O'brien
    Favourite donal O'brien
    Report
    Dec 25th 2024, 10:32 AM

    @Niall Lappin:
    The church hasn’t been silent
    You just haven’t been listening to it

    26
    Install the app to use these features.
    Mute Jonn
    Favourite Jonn
    Report
    Dec 25th 2024, 12:46 PM

    @Niall Lappin:
    How come they didn’t rock up to a synagogue waving their Palestinian flags?Probably more appropriate especially given senior Jewish figures in Irelands unquestioning support for Israel and the IDF? Or would the optics not have looked right, easier to pick on the usual whipping boy,the catholic church!

    25
    Install the app to use these features.
    Mute Jonn
    Favourite Jonn
    Report
    Dec 25th 2024, 12:48 PM

    @Niall Lappin:
    It’s always funny when people who wouldn’t be caught dead in a church enlighten us with the true meaning of Christianity!

    8
    Install the app to use these features.
    Mute H Woo
    Favourite H Woo
    Report
    Dec 25th 2024, 10:42 PM

    @Jack Hayes:
    He was Jewish

    2
    Install the app to use these features.
    Mute Joe Lynch
    Favourite Joe Lynch
    Report
    Dec 25th 2024, 11:30 AM

    My father was in the Knights and he used to go to the mansion house every Christmas morning to bring comfort and joy and a fantastic Christmas Dinner to the homeless and make sure they weren’t forgotten about.

    57
    Install the app to use these features.
    Mute Mrs. O'Brien
    Favourite Mrs. O'Brien
    Report
    Dec 25th 2024, 10:11 AM

    Excellent work by all those involved, a heartwarming show of Christianity

    56
    Install the app to use these features.
    Mute JP Fox
    Favourite JP Fox
    Report
    Dec 25th 2024, 8:34 AM

    May God Bless them all.

    42
    Install the app to use these features.
    Mute Niall Lappin
    Favourite Niall Lappin
    Report
    Dec 25th 2024, 9:34 AM

    @JP Fox: may the force be with you too

    10
    Install the app to use these features.
    Mute Shane O Mac
    Favourite Shane O Mac
    Report
    Dec 25th 2024, 4:21 PM

    Nobody should be hungry.

    6
    Install the app to use these features.
    Mute offside again
    Favourite offside again
    Report
    Dec 25th 2024, 3:29 PM

    Logion 29 : (L’évangile de Thomas).
    Jésus disait : ‘ si la chair est venu à l’existence à cause de l’esprit,
    c’est une merveille,
    mais si l’esprit est venu à l’existence à cause du corps,
    c’est une merveille de merveille.
    mais moi, je me m’émerveille de ceci :
    Comment cet être qui Est,
    peut-il habiter ce néant ?’
    (CF MT. 21, 41; MC 12, 11 ; JN 1, 14 ; 1 TM 3, 16 ; RM 8, 13 ; 1 CO 5, 3.)
    Translated into French by Jean -Yyves Leloup.

    1
    Install the app to use these features.
    Mute Gerry Goldrick
    Favourite Gerry Goldrick
    Report
    Dec 25th 2024, 6:56 PM

    @offside again: Go home bot. You’re drunk

    7
Submit a report
Please help us understand how this comment violates our community guidelines.
Thank you for the feedback
Your feedback has been sent to our team for review.
JournalTv
News in 60 seconds