news.volyx.in

Swing VPN app is a DDoS botnet (lecromee.github.io)

723 points by campuscodi · 1166 days ago · 253 comments on HN

Article summary

The Swing VPN app has been found to be using its user base as a botnet to conduct DDoS attacks on targeted websites, including Turkmenistan Airlines. The app, which has over 5 million installs on Android, sends requests to the targeted website every 10 seconds, potentially overwhelming the site's resources. The app's behavior is not limited to when it is in use, and it continues to send requests even when closed. This raises concerns about user privacy and the potential for malicious activity.

Main themes

  • VPNs and security
  • DDoS attacks and botnets
  • User privacy and protection
  • Advertising and marketing practices
  • Legal implications and responsibility
  • Malicious activity and exploitation

What commenters say

  • VPNs are often shady and can be used for malicious purposes, such as using user nodes as exit nodes or routing traffic in suspect ways.
  • Some VPN providers falsely claim that their services protect users from malware or provide better protection than vanilla SSL.
  • The over-advertisement of VPNs can lead to consumer skepticism and decreased interest.
  • The use of VPNs can have legal implications, and users may be held responsible for illegal activities conducted through their IP address.
  • VPNs can provide legitimate protection against certain types of attacks, such as malicious QoS or routing policies.
  • The profitability of the VPN industry can lead to unethical marketing practices and prioritization of financial gain over user protection.