- What is “TikTok including Musical.ly”? Tuesday 8:48 PM
- Video shows driver yelling N-word at Black woman in road rage incident Tuesday 7:40 PM
- A fan gifted Billie Eilish a jacket–it ended up in a thrift store for another fan to find Tuesday 6:49 PM
- Fans are surprisingly hyping Moby up for his new vegan tattoo Tuesday 6:13 PM
- Suspicionless searches of travelers’ electronics ruled unconstitutional Tuesday 5:22 PM
- Facebook testing TikTok clone within Instagram called Reels Tuesday 5:11 PM
- Han Solo shooting scene changed yet again, spawning ‘Maclunkey’ memes Tuesday 4:52 PM
- Facebook bug opened iPhone cameras while users scrolled their feeds Tuesday 4:36 PM
- Black Facebook employees say company racism has ‘gotten worse’ Tuesday 4:01 PM
- This fish with a ‘human face’ is here to give you nightmares Tuesday 3:28 PM
- TikTok’s piercing challenge leaves the fate of your face up to a filter Tuesday 2:54 PM
- Soldiers with top-secret clearance say they were ordered to install a sketchy app Tuesday 2:46 PM
- How to take your Korean beauty routine on the go Tuesday 2:24 PM
- Disney+’s ‘Encore!’ is a love letter to high school theater Tuesday 2:15 PM
- White tourist filmed shouting homophobic, racist slurs Tuesday 1:31 PM
If you’re using Hola, a free virtual private network (VPN) that lets you stream things like Netflix abroad, you need to stop immediately. The company behind Hola is turning your computer into a node on a botnet, and selling your network to anyone who is willing to pay.
Security researchers discovered multiple security flaws in Hola and published their findings on a site called “Adios Hola.”
“Hola is harmful to the internet as a whole, and to its users in particular,” researchers wrote.
So what’s the big deal? By using Hola as a VPN, you can view any content that might otherwise be blocked in your location by routing your traffic through the U.S. or whatever country you want your content to be in. But Hola turns your computer into an exit node without your permission, essentially letting anyone browse the Web through your network. Any malicious activity could then be traced back to you.
As the researchers note, it’s the same problem people have on the Tor browser—but on Tor, you can opt out.
Hola is going even further, by selling access to the network through a site called Luminati from $1.45 to $20 per GB. On Adios Hola, researchers published chat logs between them and the company explaining that they don’t enforce rules that say people shouldn’t be engaging in illegal activity because the company has “no idea what you are doing on our platform.”
Additionally, Hola can let someone take over programs on your computer. The researchers explain:
And on some systems, it gets worse; Hola will happily run whatever you feed it as the ‘SYSTEM’ user. What this means in simple terms, is that somebody can completely compromise your system, beyond any repair. It allows for installing things like a rootkit, for example.
This problem is not just an ‘oversight’. It’s not a thing where you say ‘well, bugs can happen’. This kind of security issue can only happen if a developer is either grossly incompetent, or simply doesn’t care about the security of their users. It’s negligence, plain and simple, and there’s no excuse for it.
If you haven’t already, uninstall Hola right now. And if you’re not sure whether or not you’re vulnerable thanks to Hola, you can visit the site to find out.
Selena Larson is a technology reporter based in San Francisco who writes about the intersection of technology and culture. Her work explores new technologies and the way they impact industries, human behavior, and security and privacy. Since leaving the Daily Dot, she's reported for CNN Money and done technical writing for cybersecurity firm Dragos.