HabrAugust 11, 2026🇷🇺Translated from Russian

Configuration Drift Silently Breaks Multi-Hop Chains in sing-box Reality Fleet

A detailed post-mortem from the operators of an RCQ messenger network has exposed how configuration drift in a sing-box and Reality deployment left four out of seven nodes unreachable, while every monitoring check continued to report OK status.

Network Architecture

The fleet on 10 August comprised 14 endpoints running on seven machines hosted by four providers. Clients fetched a signed configuration (version 144) and used urltest to select routes. Since version 0.80, traffic follows a two-hop path: entry nodes know the client but not the destination, while exit nodes know the destination but not the client. This design requires every entry node to maintain an explicit allowlist of exit nodes because each machine ends its firewall rules with a reject policy.

What Went Wrong

Rules extracted from a live entry node showed only five permitted addresses: two islands and two relays. The remaining five nodes in the fleet were absent from the list. Four of those missing nodes belonged to a single provider, immediately limiting viable chains. Further inspection revealed inconsistent lists across machines; only three of the seven published nodes could reach each other. A free user whose entry landed in the first group therefore had just two possible exits, and the onion routing layer routed traffic through only three nodes instead of seven.

urltest never complained because it simply ignored dead chains and selected from the remaining live options. Canary checks verified that relays answered, external probes confirmed islands were alive, and the relay-lockdown.sh --check script only validated local services such as the masquerade host and mirrors. None of these tools compared the allowlist against the full set of relays published in the signed configuration.

Private Nodes and Additional Findings

Examination of two paid private nodes found no route section at all, meaning anyone holding the tenant key could route arbitrary traffic through the rented machine. The relay-lockdown.sh script also surfaced an outdated SNI value of www.apple.com on two machines, left over from an earlier period before operators realized the masquerade name must reside in the same ASN as the server address.

Remediation Steps

The check script was updated to compare the allowlist against relays listed in the signed configuration and to print missing addresses. A hardcoded fallback list grew from three to seven addresses. The script now runs every thirty minutes via cron on all nine machines and only expands the allowlist; narrowing remains a manual operation. Every new configuration is validated with sing-box check before deployment.

The root cause remains unknown because lists were never dated and drift leaves no log entries. The warning already present in the script header proved accurate: a snapshot locked down from one branch silently rejects every node added later.

Related articles

HabrPrivacy & Surveillance

pg_anon Open-Source Tool Receives Major Updates for PostgreSQL Data Masking and Partial Database Operations

Tantor Labs has released version 1.11.0 of pg_anon, an open-source utility designed to mask personal data in PostgreSQL databases while preserving structure and relationships. The update introduces packaging as a standard Python package, support for partial dumps and restores using whitelist and blacklist dictionaries, and improved handling of complex schema elements such as partitioned tables, generated columns, and custom types. Performance improvements include switching the dump engine to asyncio, single-query metadata collection, and on-the-fly gzip compression to reduce memory usage on large databases. New CLI options allow clean or drop operations on target databases, privilege ignoring, and passthrough of pg_dump and pg_restore flags. A REST API was added to enable integration into CI/CD pipelines and automated self-service systems for nightly masked database refreshes. The tool helps organizations comply with data protection requirements by creating pseudonymized copies suitable for development, testing, and contractor environments.

BoletimSecPrivacy & Surveillance

Pegasus Spyware Returns in Serbian Surveillance Campaign via Zero-Click iMessage Exploit

A Serbian student activist's iPhone was infected with the Pegasus spyware through a zero-click exploit in iMessage, allowing silent installation without any user interaction. The infection, confirmed by Citizen Lab in collaboration with the SHARE Foundation, showed indicators of compromise between December 2025 and January 2026. Apple later sent the target a notification warning of a mercenary spyware attack attempt. The exploit granted full access to photos, messages, files, and enabled covert microphone and camera activation. The vulnerability was addressed in the iOS 18.4.1 update released on April 16, 2025. The incident forms part of a wider surveillance wave in Serbia, with at least 14 individuals including students, activists, a parliament member, and a local political representative receiving similar Apple alerts. Additional targets were hit with Android spyware variants linked to NoviSpy.

AntiMalwarePrivacy & Surveillance

Mozilla Adds Built-in Ad Blocker to Firefox for iOS Devices

Mozilla has integrated a native ad-blocking feature directly into its Firefox browser for iOS. The update allows iPhone and iPad users to block third-party advertisements and associated trackers before web pages load, eliminating the need for separate extensions. Apple’s App Store policies have long restricted the use of third-party content blockers on iOS compared to desktop and Android platforms. The new functionality targets intrusive elements such as pop-up windows, content-overlapping banners, and other advertising formats. By handling blocking at the browser level, Firefox for iOS improves user privacy and reduces exposure to tracking mechanisms without requiring additional software installation.

HabrPrivacy & Surveillance

De-Clouding IoT Devices: Local Control for Midea Air Conditioners and Tuya-Based Cat Feeders

A security researcher detailed a methodical approach to eliminating vendor cloud dependency for Wi-Fi IoT devices in a smart home setup. After acquiring a cat, the author was forced to integrate several Tuya-based appliances that only worked through proprietary cloud apps. Using hardware analysis tools including UART adapters, multimeters, and soldering equipment, the devices were disassembled and their controllers identified. The Midea air conditioner controller based on TYWE3S ESP8266 was reflashed with ESPHome to enable direct Home Assistant integration. For the Tuya WBR3-powered cat feeder running on an RTL8720CF chip, OpenBeken firmware was installed after extracting the original firmware with ltchiptool. Detailed UART communication analysis between the Wi-Fi module and MCU allowed full recreation of scheduling and control functions locally via MQTT.