Privacy & Surveillance

Cybersecurity news in this category

๐Ÿ‡ท๐Ÿ‡บSep 9

PII-Guard: Open-Source Detector for Personal Data in Russian Text

Andrey Ivanov, an NLP researcher at red_mad_robot, has released PII-Guard, an open-source system that detects and masks personal data in Russian text before it reaches language models. The tool combines rule-based checks with a fine-tuned ruBert-base NER model to handle names, addresses, phones, passports, INN, SNILS, bank cards and other entities. It replaces detected PII with structured XML-like tags that preserve grammatical information such as gender and entity ID, allowing models to generate coherent responses that are later restored with real values. The hybrid pipeline first applies normalization, pattern matching, Luhn and weighted checksum validation, and context windows with positive and negative keywords, then merges results with model predictions via an arbitration module. Evaluation on four public datasets, including Hivetrace, alexen2 and alrosait, shows PII-Guard outperforming other open solutions on both strict span matching and type-overlap micro-F1 metrics. The project, including datasets and code, is available on GitHub and aims to reduce leakage risks while maintaining downstream model utility.

Habr
๐Ÿ‡ท๐Ÿ‡บSep 8

Google to Add Explicit Content Warnings in Android System Photo Picker

Google is preparing a new safety feature for the system photo picker in Android that will scan images and videos for explicit or nude content. The tool is designed to warn users before they share intimate photographs, whether accidentally or due to a momentary lapse in judgment. This functionality will operate at the system level, meaning it applies across multiple apps that use the built-in photo selector. The feature aims to reduce the risk of unintended distribution of private images that could lead to embarrassment or privacy violations. By integrating the check directly into Android, Google seeks to provide a consistent layer of protection without requiring third-party applications to implement similar logic themselves.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บSep 8

LG Smart TVs Record Audio in Standby Mode and Scan Home Networks for Advertising Data

Researchers from the Gamers Nexus YouTube channel analyzed multiple LG OLED television models, including the LG G5 series, and discovered that the devices continue to capture audio through built-in microphones even when the screen is off and the television is in standby. The TVs scan local networks to identify smartphones and smartwatches, collect internal IP addresses, available Wi-Fi network names, and location data. When internet connectivity is removed, audio recordings are stored locally and transmitted once the connection is restored. The devices also employ Automatic Content Recognition (ACR) technology to generate digital fingerprints of viewed content, with the resulting data reportedly sent to LG Ad Solutions for targeted advertising. Additional vulnerabilities were identified in webOS that could potentially allow remote code execution. LG has not yet commented on the findings, and experts recommend disconnecting the televisions from the internet and using external streaming devices until official clarification is provided.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บSep 7

Engineer Details Six Weeks Spent Training and Testing Signature Redaction Models for Closed-Loop Document Anonymization

A detailed case study describes attempts to automatically redact handwritten signatures from scanned and text-based PDFs containing personal data such as names, phones, addresses and signatures. The work was performed inside an air-gapped environment on a single GPU machine with no internet access. Multiple approaches including color-based ink gates, pre-trained YOLO detectors, custom-trained YOLO11s models, Tesseract OCR heuristics and various vision-language OCR engines were evaluated on 492 real pages plus synthetic augmentations. Key findings include rotation handling bugs, line-assembly failures in Tesseract, the necessity of using apply_redactions instead of draw_rect for true removal, and the limited value of vision models once rule-based pipelines are mature. The final pipeline reduced expensive vision-model calls from 50 pages to 18 pages while achieving zero leaks across thousands of redactions. The author also measured twelve OCR engines and demonstrated that combining PaddleOCR detection with Tesseract recognition yields the best accuracy-to-speed trade-off.

Habr
๐Ÿ‡ท๐Ÿ‡บSep 5

pg_anon Open-Source Tool Receives Major Updates for PostgreSQL Data Masking and Partial Database Operations

Tantor Labs has released version 1.11.0 of pg_anon, an open-source utility designed to mask personal data in PostgreSQL databases while preserving structure and relationships. The update introduces packaging as a standard Python package, support for partial dumps and restores using whitelist and blacklist dictionaries, and improved handling of complex schema elements such as partitioned tables, generated columns, and custom types. Performance improvements include switching the dump engine to asyncio, single-query metadata collection, and on-the-fly gzip compression to reduce memory usage on large databases. New CLI options allow clean or drop operations on target databases, privilege ignoring, and passthrough of pg_dump and pg_restore flags. A REST API was added to enable integration into CI/CD pipelines and automated self-service systems for nightly masked database refreshes. The tool helps organizations comply with data protection requirements by creating pseudonymized copies suitable for development, testing, and contractor environments.

Habr
๐Ÿ‡ต๐Ÿ‡นSep 4

Pegasus Spyware Returns in Serbian Surveillance Campaign via Zero-Click iMessage Exploit

A Serbian student activist's iPhone was infected with the Pegasus spyware through a zero-click exploit in iMessage, allowing silent installation without any user interaction. The infection, confirmed by Citizen Lab in collaboration with the SHARE Foundation, showed indicators of compromise between December 2025 and January 2026. Apple later sent the target a notification warning of a mercenary spyware attack attempt. The exploit granted full access to photos, messages, files, and enabled covert microphone and camera activation. The vulnerability was addressed in the iOS 18.4.1 update released on April 16, 2025. The incident forms part of a wider surveillance wave in Serbia, with at least 14 individuals including students, activists, a parliament member, and a local political representative receiving similar Apple alerts. Additional targets were hit with Android spyware variants linked to NoviSpy.

BoletimSec
๐Ÿ‡ท๐Ÿ‡บSep 3

Mozilla Adds Built-in Ad Blocker to Firefox for iOS Devices

Mozilla has integrated a native ad-blocking feature directly into its Firefox browser for iOS. The update allows iPhone and iPad users to block third-party advertisements and associated trackers before web pages load, eliminating the need for separate extensions. Appleโ€™s App Store policies have long restricted the use of third-party content blockers on iOS compared to desktop and Android platforms. The new functionality targets intrusive elements such as pop-up windows, content-overlapping banners, and other advertising formats. By handling blocking at the browser level, Firefox for iOS improves user privacy and reduces exposure to tracking mechanisms without requiring additional software installation.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บSep 2

De-Clouding IoT Devices: Local Control for Midea Air Conditioners and Tuya-Based Cat Feeders

A security researcher detailed a methodical approach to eliminating vendor cloud dependency for Wi-Fi IoT devices in a smart home setup. After acquiring a cat, the author was forced to integrate several Tuya-based appliances that only worked through proprietary cloud apps. Using hardware analysis tools including UART adapters, multimeters, and soldering equipment, the devices were disassembled and their controllers identified. The Midea air conditioner controller based on TYWE3S ESP8266 was reflashed with ESPHome to enable direct Home Assistant integration. For the Tuya WBR3-powered cat feeder running on an RTL8720CF chip, OpenBeken firmware was installed after extracting the original firmware with ltchiptool. Detailed UART communication analysis between the Wi-Fi module and MCU allowed full recreation of scheduling and control functions locally via MQTT.

Habr
๐Ÿ‡ท๐Ÿ‡บSep 2

Russia Starts Blocking Encrypted DNS Protocols DoH and DoT Across Major ISPs

Since mid-August 2026, subscribers of Rostelecom, Dom.ru, Tattelecom, SkyNet and Beeline have reported sudden failures of encrypted DNS services from Google and Cloudflare. The blocking affects both DoT on port 853 and DoH on port 443, but the mechanisms differ: DoT connections receive TCP RST packets while DoH sessions are silently dropped after the TLS ClientHello. Analysis shows the interference originates from TSPU equipment performing DPI on SNI fields and known resolver domains. At the same time, ordinary UDP DNS queries are being intercepted and answered by the NSIDI infrastructure, returning NXDOMAIN for blocked domains. The changes indicate a centrally coordinated rollout of new filtering rules rather than isolated operator actions. Users are advised that encrypted DNS no longer provides reliable privacy or circumvention and that full VPN tunnels remain the only robust option.

Habr
๐Ÿ‡ท๐Ÿ‡บSep 1

Glassbox Tool Exposes Browser Fingerprinting Risks and Limitations of Incognito Mode

Developer and security researcher David Dale has released Glassbox, an open tool that runs over 30 browser fingerprinting checks to show how identifiable a user appears to trackers. The service evaluates Canvas, WebGL, installed fonts, WebAssembly functions, available APIs, third-party authentication state, and audio processing characteristics entirely in the browser. Results include raw test data and an identifiability score capped at roughly 33 bits, sufficient in theory to single out one person among the global population. Tests reported by The Register showed Chrome at 99 percent identifiability, Firefox at 89 percent, and Tor Browser at 56 percent, though these figures rely on a mathematical model rather than real-world visitor databases. Dale warns that overly hardened configurations can increase uniqueness and recommends using Tor or VPN together with WebRTC leak prevention to blend into larger anonymity sets.

AntiMalware
๐Ÿ‡ต๐Ÿ‡นSep 1

Android 17 Adds Local Network Protection and Strengthens Wi-Fi Privacy Controls

Android 17 introduces Local Network Protection, requiring apps to obtain explicit permission before scanning or connecting to devices on the same Wi-Fi network. The feature limits unauthorized discovery of TVs, cameras, printers, consoles and other local equipment that could previously be used to build detailed user profiles. The update also enables Encrypted Client Hello by default to hide domain names during HTTPS handshakes from network observers. Certificate Transparency is now activated by default to detect fraudulent or mis-issued certificates that could enable interception attacks. Additional safeguards block forced downgrades to insecure 2G networks often exploited by fake base stations for SMS-based fraud. These changes collectively reduce passive tracking and man-in-the-middle risks without disrupting legitimate local network functions such as media casting.

BoletimSec
๐Ÿ‡ท๐Ÿ‡บSep 1

Review of GL.iNet Mudi 7 and Xray Configuration for Flexible Traffic Routing

The article provides a hands-on review of the GL.iNet Mudi 7 portable router combined with detailed instructions for deploying Xray. The author explains moving away from managing multiple separate VPN clients by installing Xray directly on the router. This setup allows all connected devices to route traffic intelligently without manual configuration on each endpoint. Local and Russian services connect directly to avoid latency, while international traffic is forwarded through a personal server. The guide covers practical scenarios for home use and emphasizes maintaining speed for permitted connections while ensuring selective proxying for the rest of the traffic.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 31

Taiwan Man Uses Robot Vacuum Camera to Prove Wife's Affair, Wins Compensation but Receives Prison Sentence for Illegal Recording

A resident of Taiwan suspected his wife of infidelity after discovering a stranger's toothbrush in their countryside home. He reviewed footage from a parking lot camera and later accessed the live feed of their robot vacuum cleaner through its mobile application, capturing intimate recordings without consent. The man preserved the video evidence and successfully sued for breach of marital rights, receiving approximately $19,000 in compensation. His wife filed a counterclaim, arguing that the recordings violated her right to privacy because the device's sensors and indicators did not clearly indicate active surveillance. Although the footage was accepted in the civil case, the court ruled that the illegal method of obtaining it outweighed marital obligations, prioritizing personal privacy protections. The husband was sentenced to five months in prison and fined 150,000 Taiwanese dollars, representing 30 percent of his awarded compensation.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 31

Russian Firms Accumulate Digital Clutter: 35% of Corporate Files Unused for Years, Weak Passwords Expose Sensitive Data

A study by Russian cybersecurity firm Garda examined more than 157 terabytes of data and over 511,000 user accounts across more than 100 companies. Researchers found that approximately 35% of files in corporate repositories had not been accessed for more than five years, while duplicate data could occupy another 35% of storage volume. In several industries, up to one-third of stored content consisted of personal photographs, videos, and archives unrelated to business operations. More than 33% of accounts used critically weak passwords or credentials that had not been changed for extended periods, and numerous contractor and temporary employee accounts remained active despite being unused for over 90 days. Direct access permissions bypassing security groups were widespread, allowing broad access to folders containing passport scans, client registries, and database exports. Garda recommends automated inventory, classification, centralized access management, and lifecycle automation to reduce risks instead of manual cleanup.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 30

Apple Updates Private Relay Domain for Sign in with Apple: Why Email Cannot Serve as Account Identity

Apple announced that new Private Relay addresses for Sign in with Apple will use the private.icloud.com domain starting later in 2026, while existing privaterelay.appleid.com addresses will continue functioning without interruption. The change highlights a deeper architectural issue: many applications incorrectly treat email addresses returned by Apple as stable identifiers rather than transient contact channels. Proper implementation requires separating the signed identity token, the verified subject claim, and the optional email relay address into distinct data models. Developers must validate the full identity token on the server, including signature, issuer, audience, nonce, and expiration, before linking any Apple identity to an internal account. Using provider and subject pairs as the unique key prevents duplicate accounts, accidental merges, and broken logins when relay domains or email claims change. The article provides concrete recommendations for data models, token verification boundaries, and test cases that remain resilient to future Apple updates.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 28

Step-by-Step Guide to Removing Personal Data from Search Engines, Databases and Social Networks

The guide provides a practical seven-step checklist for individuals seeking to reduce their digital footprint by removing personal information from websites, search engines, and social platforms. It emphasizes starting with a 20-minute audit to compile exact URLs rather than vague requests, followed by direct contact with site owners under Russia's 152-FZ personal data law. Subsequent steps cover submissions to Yandex and Google for de-indexing, manual cleanup of old social media accounts, handling of phone numbers in caller ID services, and removal from directories and review sites. The process includes templates for formal requests, timelines for responses, and escalation paths to Roskomnadzor when operators fail to comply. Special attention is given to leaked databases, where technical removal is impossible, and to web archives such as Internet Archive that require specific legal justifications. The full cycle is estimated at two months, with quarterly maintenance recommended to sustain results.

Securitylab
๐Ÿ‡ท๐Ÿ‡บAug 28

telEgo Combines MTProxy and WEB Proxy on Single Port 443 with TLS Fronting

telEgo, a Go-based Telegram MTProxy implementation using the gnet network engine, now supports all four WEB proxy transport modes alongside traditional MTProxy connections on the same public port 443. The solution allows FakeTLS with ee secrets, Obfuscated2 with dd secrets, and WEB carriers including https, https-lanes, websocket, and websocket-lanes without requiring separate ports or secret changes. telEgo performs handshake detection, forwards ordinary TLS traffic to Nginx on a private port using PROXY protocol v2, and routes authenticated WEB streams back to the internal MTProxy backend. The setup uses Docker Compose with separate containers for telEgo, Nginx, and certificate management via Certbot, keeping ports 8080, 8443, and 8444 internal. Existing MTProxy links continue to function while new WEB proxy links become available for Telegram Desktop. The configuration supports Prometheus metrics, connection limits, and automatic certificate renewal through systemd timers.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 28

From HAProxy to VLESS+Reality: Overcoming DPI Blocks for MTProto Telegram Proxies

A detailed case study describes the challenges of running an MTProto proxy for Telegram on Russian servers facing ISP-level DPI. Initial attempts using HAProxy TCP relays and SOCKS5 tunnels failed because modern DPI systems detect MTProto and fake-TLS signatures regardless of transparent forwarding. The author eventually succeeded by layering mtg with an Xray VLESS+Reality tunnel that performs genuine TLS 1.3 handshakes to legitimate domains. Key configuration pitfalls included the xtls-rprx-vision flow breaking non-TLS payloads, missing mux causing handshake timeouts on short-lived connections, and provider-specific network policies. Final architecture places mtg and an Xray client on the Russian entry server while the foreign exit server runs Xray in VLESS+Reality inbound mode. The guide supplies complete docker-compose examples, key generation commands, and a checklist of common misconfigurations to avoid.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 28

TLS MITM and Throttling to 10 Mbps: Two Distinct Network Degradation Patterns Observed in Russia

Russian users have reported sudden slowdowns and instability on international connections over the past several days. Analysis of Tunnel Cat logs revealed two separate issues that produce similar user symptoms but require different diagnostic approaches. The first pattern involves successful TCP and TLS handshakes followed by sharp drops in throughput, often from 80 Mbps to 8-12 Mbps, consistent with DPI-based throttling of international traffic. The second pattern shows TLS certificate substitution on Windows systems, indicating active man-in-the-middle interception. Tunnel Cat now detects invalid certificates and terminates such sessions, yet the underlying network phenomena persist. The observations highlight the need to examine both bandwidth dynamics and certificate chains when troubleshooting connectivity problems from Russia.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 27

Deleted Database Records Remain Recoverable in SQLite Files Despite DELETE Operations

A standard DELETE query in SQLite removes rows from the table view but leaves the actual data intact inside the database file until pages are reused. The pragma secure_delete setting controls whether freed pages are zeroed immediately or simply marked as available. With the default setting of 0, strings containing names and credit card numbers can still be extracted using grep even after deletion. The same behavior appears in PostgreSQL through dead row versions until VACUUM runs and in MySQL InnoDB through undo logs and the binary log. The issue directly affects compliance with personal data deletion requests because backups, replicas, and analytics exports often retain the original records. Proper mitigation requires enabling secure_delete, running VACUUM after bulk deletions, or encrypting sensitive fields with per-record keys that can be destroyed on request.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 27

Russian TSPU Systems Redirect DNS Queries to Google and Cloudflare Servers Toward National Domain Name System

Since the evening of August 26, Russian technical means of countering threats (TSPU) began intercepting open DNS queries sent to Google and Cloudflare public resolvers. For domains such as YouTube and RuTracker, UDP-based queries received NXDOMAIN responses while TCP queries successfully reached the original servers and returned valid IP addresses. Analysis with low TTL packets revealed that responses originated from IP address 195.208.5.1 belonging to the National System of Domain Names (NSDI). The mechanism performs targeted DNAT on recognized DNS traffic, making the query appear directed to NSDI rather than the foreign resolver. The redirection is imperfect, allowing subsequent identical queries sent in quick succession to bypass the system and reach Google. The findings come from experiments conducted by Habr user angry_agent and have not yet received official confirmation from Russian authorities.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 27

HTTPS Lock Icon Present but List of Visited Sites Remains Visible

Even when HTTPS is active and passwords stay protected, DNS queries and the SNI field in TLS handshakes expose the exact domains a user visits over public Wi-Fi. Classic unencrypted DNS over UDP sends domain names in plaintext, allowing anyone on the same network to observe them with simple packet captures. The SNI extension reveals the target hostname before encryption is negotiated, enabling domain-based filtering without decrypting traffic. DNS over HTTPS moves queries inside encrypted channels but shifts visibility to the chosen resolver instead of the local network. Encrypted Client Hello offers partial protection for SNI yet requires support from both browsers and server infrastructure. The practical takeaway is that metadata about services used, timing, and frequency leaks more readily than credentials in modern public networks.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 27

Russian TSPU Begins Intercepting UDP DNS Queries to Cloudflare and Google Public Resolvers

Starting on the evening of August 26, Russia's TSPU DPI system began actively intercepting plaintext DNS queries sent over UDP to public resolvers operated by Cloudflare and Google. Queries to 1.1.1.1 and 8.8.8.8 now return NXDOMAIN responses for blocked domains instead of the real IP addresses. The interception works exclusively on UDP; TCP-based DNS queries continue to receive legitimate answers from the original resolvers. Technical analysis shows the system performs targeted DNAT, rewriting the destination IP to the NSDI server at 195.208.5.1 only when a DNS query is detected inside the packet. Experiments with varying TTL values confirm that the redirection occurs after the traffic passes the TSPU node, and rapid successive queries can sometimes bypass the filter and return genuine records. The change affects netflow statistics visible to network operators, as traffic previously destined for foreign resolvers is now redirected domestically.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 27

Google Develops Public Android API for On-Device Content Safety Classification

Google is creating a new public Android API that will allow third-party applications to analyze images and other files locally on the device and assign them one of four safety statuses. The system builds on the existing SafetyCore component already used in Google Messages to blur intimate images. ContentSafetyManager will process images, raw files, and multimedia content entirely on-device without transmitting data to Google servers. Applications will then decide whether to display, blur, or hide the content based on the classification result. Experts warn that malicious apps granted broad permissions could misuse the classifier to scan large volumes of user files and build detailed profiles. SafetyCore itself previously sparked controversy after being installed automatically without explicit user consent and without a visible icon, leading some users to install blockers to prevent reinstallation via the Play Store. Google continues to emphasize minimal permission requests and local processing as safeguards for user privacy.

AntiMalware
๐Ÿ‡ต๐Ÿ‡นAug 26

WhatsApp Adds Support for Multiple Passkeys on Single Account

WhatsApp has expanded its account protection features by allowing users to register more than one passkey on the same profile. The update particularly benefits users who switch between Android and iOS devices while maintaining phishing-resistant login methods. Passkeys replace traditional codes and passwords with biometric authentication, facial recognition, or device lock mechanisms. Meta reports that more than one billion people already use the feature on WhatsApp, with Android support introduced in 2023 and iOS support added in 2024. The change reduces reliance on a single device during authentication by associating multiple keys with one account. Users can manage keys through Settings > Account > Passkeys. WhatsApp has also strengthened two-factor verification by allowing replacement of the six-digit PIN with longer passwords containing letters, numbers, and special characters.

BoletimSec
๐Ÿ‡ท๐Ÿ‡บAug 26

Russian ISPs Begin Disrupting Encrypted DNS Services from Google and Cloudflare

Users of several major Russian internet providers have reported widespread issues accessing encrypted DNS protocols offered by Google and Cloudflare. The affected services include DNS over HTTPS (DoH) and DNS over TLS (DoT), which are designed to prevent providers from inspecting domain queries. Measurements show that connections to Cloudflare addresses 1.1.1.1 and 1.0.0.1 on port 853 establish TCP handshakes but are then reset with ECONNRESET errors before TLS authentication completes. Google Public DNS endpoints experience different interference, with sessions stalling after the TLS ClientHello or terminating with unexpected EOF errors. The disruptions have been observed across Rostelecom, Dom.ru, Tattelecom, and SkyNet subscribers, with varying impact depending on region and operator. Tattelecom support reportedly advised one customer to disable both protocols to restore connectivity. No official confirmation of centralized blocking has been issued, yet the coordinated pattern across multiple providers suggests deliberate interference rather than random failure.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 26

DuckDuckGo Study Shows Users Confide Sensitive Personal Details in AI Chatbots Without Realizing Data Retention

A new DuckDuckGo survey reveals that chatbots have evolved from simple search tools into digital confidants where users disclose highly personal information. Nearly one in three AI users admitted sharing details they would not discuss with friends, family, colleagues, or doctors. The figure rises sharply to 56 percent among users who describe themselves as strong AI enthusiasts. The research underscores that many people remain unaware that AI systems store and can later reference these conversations. This behavior creates significant privacy risks as conversational data becomes part of long-term model memory. The findings highlight a growing gap between user expectations and the actual data-handling practices of AI platforms.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 24

Telegram Desktop Adds WEB Proxy to Hide MTProxy Traffic Inside HTTPS and WebSocket Connections

Telegram Desktop has received an initial implementation of a new WEB proxy designed to conceal messenger connections within ordinary HTTPS and WebSocket traffic. The feature makes user activity appear as simple website browsing to network providers while MTProxy continues to operate underneath. Developers inserted more than 3,000 lines of code, including a dedicated WEB-proxy transport, domain configuration options, and interface elements such as โ€œOpen browserโ€ and โ€œWaiting for browser.โ€ The mechanism works by opening an embedded web page that establishes a secure WebSocket link to a domain resembling a regular site. Multiple MTProxy connections are multiplexed into a single stream and sent through this channel. On the server side an intermediate node demultiplexes the stream and forwards the individual connections to a standard MTProxy instance without decrypting message content.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 21

Gesture Dynamics CAPTCHA Emerges as Privacy-Focused Drop-in Alternative to reCAPTCHA

A new open-source CAPTCHA system called Aptogon replaces traditional image-based challenges with analysis of hand gesture dynamics to verify human users. Instead of clicking on traffic lights or buses, visitors draw a free-form gesture for about ten seconds while the system measures velocity variance, pause entropy, rhythm irregularity, and micro-corrections that distinguish human motor patterns from bots. The solution addresses recent reCAPTCHA restrictions, including Google's reduction of free monthly verifications from one million to ten thousand and tightened GDPR data responsibility rules starting in April 2026. An iframe architecture loaded from the vendor origin eliminates cross-origin issues and CORS blocks while supporting public and secret key pairs for domain validation. Machine learning relies on a local gradient boosting model for confident decisions and an LLM only for borderline cases, with fail-closed behavior returning 503 errors when the classifier is unavailable. Coordinates never leave the browser; only derived statistics are sent, satisfying GDPR requirements without cookie banners or biometric templates. The project is released under AGPL-3.0 with a free tier of one thousand checks per month and integration examples for HTML, React, Node, Python, and PHP.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 20

Cat Tunnels Service Deploys Kotator-Rotator to Counter Mass Blocking of Relay Nodes in Russia

The operators of the decentralized Cat Tunnels service faced a sudden wave of blocks that disabled all several dozen of their tracker nodes inside Russia. Without these anchor relays, new user connections slowed dramatically and existing sessions degraded. The team responded by building Kotator-Rotator, an automated system that continuously evaluates node reachability from the client side and replaces failing relays with fresh instances. The decision engine relies on Grohotator, an aggregated availability metric derived from client technical logs that also triggers an audible alarm when thresholds are crossed. Analysis of the logs revealed that blocking activity follows a clear weekday pattern, pausing on Friday evenings and resuming Monday mornings. The experience demonstrated that server-side health checks alone are insufficient when censors interfere with paths between clients and relays.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 20

Google Chrome Tests Visible Global Privacy Control Toggle in Canary

Google is testing a new visible toggle for Global Privacy Control in Chrome Canary that lets users send a standardized request asking websites not to sell or share their personal data and not to use it for targeted advertising. When enabled, the browser adds the Sec-GPC: 1 header to web requests and exposes the setting via navigator.globalPrivacyControl. In regions with supporting laws such as California's CCPA, the signal can serve as a formal opt-out from data sales. The feature currently appears primarily on Android, with experimental flags available on Windows, macOS, Linux, and ChromeOS, though the desktop interface remains incomplete. Two separate flags are requiredโ€”one to show the toggle and another to actually transmit the signalโ€”because enabling only the UI does not send Sec-GPC: 1. The mechanism is not a guaranteed enforcement tool; websites decide how to respond, and effectiveness depends on legal frameworks and site compliance. The feature is absent from the stable Chrome release and may still change before wider rollout.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 19

OpenAI ChatGPT Computer History Feature on macOS Could Expose Detailed User Activity Logs to Infostealers

OpenAI has introduced the Computer History feature in its macOS ChatGPT app, which records application switches, clicks, keystrokes, and accessibility context to generate AI summaries and memories. The feature is disabled by default and requires explicit activation of Memories, with availability limited to Pro, Business, and Enterprise users outside the EEA, Switzerland, and the UK. While raw event files are deleted after 48 hours and not used for model training, the resulting Markdown memory files remain unencrypted on the local Mac. These files can be read by any process running under the same user account, creating a ready-made activity log for infostealers and other malware. OpenAI also warns about prompt injection risks where hidden instructions from websites or apps could influence ChatGPT or Codex behavior. Users retain controls to select participating apps, pause collection, or delete history, but the lack of encryption on stored memories raises significant privacy concerns.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 19

AirTag and SmartTag: How to Detect If a Bluetooth Tracker Is Following You

Phones can now warn users when an unknown Bluetooth tracker such as an Apple AirTag or Samsung SmartTag is moving alongside them for an extended period. The alerts do not automatically confirm stalking, since the same tags can be left in taxis, rental cars or borrowed bags, yet they should never be ignored. AirTag and SmartTag rely on crowdsourced Bluetooth networks rather than built-in GPS or cellular connections, allowing them to report approximate locations only when nearby phones relay the signal. The article details differences from traditional GPS trackers, explains how to interpret notifications on iOS 17.5+ and Android 6.0+, and provides step-by-step guidance for locating hidden devices in clothing, vehicles or personal items. It also covers immediate safety actions, evidence preservation for police reports, and practical steps to reduce future tracking risks through account and permission hygiene.

Securitylab
๐Ÿ‡ท๐Ÿ‡บAug 18

VPN Encryption Alone Cannot Hide Traffic from Network Detection Systems

A Habr user known as mr_tom detailed why encrypted VPN connections remain detectable despite their encryption. Observers can identify connections through visible metadata such as server IP addresses, ports, transport protocols, handshake patterns, packet sizes, timing intervals, and overall flow behavior. Simple DPI systems block traffic by restricting known IPs or ports, while advanced filters build traffic fingerprints and use active probing to verify suspicious endpoints. The popular combination of VLESS, XHTTP, and REALITY operates across different layers rather than functioning as three equivalent VPN protocols. Even traffic on port 443 can be distinguished from standard HTTPS by analyzing handshake details and subsequent packet behavior. The core conclusion is that no universally unblockable VPN exists, as detection can rely on IP blocking, new signatures, or active verification regardless of encryption strength.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 17

Browser Extension Anonymizes Sensitive Data Before Sending to AI Chatbots

A new browser extension automatically detects and replaces sensitive information such as names, INN numbers, bank cards, and emails with pseudonyms before any text or files reach AI chat services. The tool operates entirely locally in the browser, ensuring original data never leaves the user's device while allowing AI models to process anonymized placeholders. Responses from the AI are decrypted back to readable form only on the user's screen using an in-memory mapping that disappears when the browser closes. The solution supports over 70 file formats including DOCX, XLSX, and PDF, plus offline OCR for scanned documents to handle the most common leakage vectors used by HR, legal, and accounting teams. Multiple validation layers including checksums, Luhn algorithm, entropy checks, and normalization for Russian name declensions reduce false positives that plagued earlier regex-based attempts. The extension is available in a free version on the Chrome Web Store covering 33 data categories, with advanced file and scan features offered on request.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 17

Browser Privacy Ranking 2026: Tor Browser Leads at 9.5 While Chrome and Yandex Rank Lowest

SecurityLab.ru has published a detailed 2026 browser privacy ranking that evaluates major browsers across six criteria including initial network behavior, site isolation, fingerprint resistance, funding model, configurability, and code auditability. Tor Browser scores highest at 9.5 for its comprehensive protections including unified fingerprinting and layered JavaScript controls, followed by Mullvad Browser at 9.0 and LibreWolf at 8.5. Brave earns 7.5 for built-in tracker blocking but faces criticism over default telemetry and cryptocurrency features. Firefox scores 6.0 out of the box yet reaches 8.5 after extensive configuration, while Google Chrome, Microsoft Edge, Opera, and Yandex Browser occupy the bottom positions due to persistent tracking mechanisms and closed-source components. The report also highlights the Local Mess localhost tracking technique used by Meta and Yandex that bypassed browser isolation entirely.

Securitylab
๐Ÿ‡ท๐Ÿ‡บAug 17

Russian Ministry Certificates Enable Potential State MITM on Foreign Domains

Russian companies facing sanctions have started adopting root certificates issued by the Ministry of Digital Development and Communications to maintain HTTPS access after commercial CAs revoked or refused to renew their certificates. Installing these Ministry certificates allows browsers to trust sites using Russian national CAs but also creates a pathway for man-in-the-middle interception by state-controlled entities. The article details a concrete threat model where a government-linked operator could use the Ministry root to generate on-the-fly certificates for any domain, including foreign services outside Russian jurisdiction. To mitigate this, the author demonstrates how to re-sign the Ministry root with OpenSSL nameConstraints limited to .ru, .su, and .ั€ั„ domains only. Tests on macOS with Homebrew show that the constrained certificate still validates Russian banking sites such as online.sberbank.ru while correctly rejecting attempts to validate foreign domains like sberbank.com. The technique requires users to maintain their own cross-signed root and never rely on pre-installed Ministry or Yandex Browser roots for full protection.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 15

Bypassing Blocks, Privacy, and Anonymity Remain Separate Challenges for Decentralized Networks

The developers of the decentralized circumvention tool Tunnel Cat have clarified that their service addresses only traffic delivery and does not guarantee privacy or anonymity. Transport-layer TLS encryption protects data in transit between nodes but provides no end-to-end protection for conversation content. The team explicitly recommends using separate E2E-encrypted messengers such as Signal or Matrix rather than relying on Telegram. Operational telemetry is retained to comply with legal obligations in multiple jurisdictions and to monitor blocking patterns inside Russia. Because client devices relay traffic for others, the architecture inherently prevents strong anonymity guarantees comparable to Tor. The project deliberately separates the circumvention function from messaging and anonymity tools to avoid overpromising security properties.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 14

How to Detect and Remove Stolen Photos from Fake Profiles, Listings and Ads

Photos are frequently stolen from social networks, old listings, building chats and review sites, then reused in fake profiles, advertisements and rental scams. Russian law under Article 152.1 of the Civil Code protects the right to one's image, while separate copyright rules protect the photographer. Victims are advised to gather strong evidence including full-page screenshots, PDF copies and original files before contacting platforms. Search tools such as Yandex Images, Google Lens and TinEye help locate copies across multiple services. Complaints can be filed directly with site administrators on VKontakte, Odnoklassniki, Avito and Telegram, or escalated to Roskomnadzor and police when personal data or fraud is involved. Preventive steps include lowering image resolution, adding watermarks and restricting album visibility through privacy settings.

Securitylab
๐Ÿ‡ท๐Ÿ‡บAug 11

Configuration Drift Silently Breaks Multi-Hop Chains in sing-box Reality Fleet

A post-mortem analysis of a censorship circumvention network using sing-box and Reality revealed that four out of seven nodes were unreachable due to outdated allowlists, even though all monitoring reported green status. The fleet consisted of 14 endpoints across seven machines and four providers, with traffic routed in two hops where entry nodes only knew client identities and exit nodes only knew destinations. White-list rules on entry nodes permitted only five addresses instead of all required relays, causing urltest to silently discard most chains without logging failures. Canary checks, external probes, and the relay-lockdown.sh script all passed because none compared the allowlist against the full signed configuration. Two private paid nodes lacked any route section entirely, exposing them to potential abuse. The issue stemmed from configuration drift over time, with no single person maintaining an overview of the entire system. Automated fixes were implemented with safeguards to prevent fleet-wide lockouts.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 10

Why Distributed Mesh Architectures Resist IP Blocking Better Than Centralized Servers

The article explains the fundamental limitations of single-server or small-server setups when facing IP-based censorship and DPI systems. A centralized infrastructure relies on a finite, relatively static list of addresses that can be discovered, tracked, and blocked over time. In contrast, a client-side mesh turns user devices into active transport nodes that relay traffic peer-to-peer, creating a constantly changing set of endpoints. This architectural shift transforms address blocking from a one-time list-maintenance task into an ongoing discovery problem. The design still requires an auxiliary trust and coordination layer called the backbone network, while anti-DPI techniques such as ClientHello rotation and decoy traffic protect individual connections. The approach carries real costs in battery life, bandwidth, and operational complexity on client devices.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 8

Chrome Adds On-Device Gemini Nano While Ask Gemini Sends Page Content to Google Cloud

Google has introduced an 'AI on device' toggle in Chrome settings that enables local execution of the Gemini Nano model directly on the user's computer. Several gigabytes of Gemini Nano weights are now stored in the browser profile directory and can run on CPU or GPU for tasks such as initial analysis of suspicious pages. Despite the local model being present, the user-facing 'Ask Gemini' feature does not use it and instead routes page content, URLs, and up to ten additional tabs to Google's cloud infrastructure. The company uses two distinct systems under the Gemini name: the cloud-based Ask Gemini / Gemini in Chrome service and the on-device Gemini Nano accessed only through internal APIs or by websites and extensions. When Enhanced Protection is enabled, results from the local Safe Browsing analysis may still be transmitted to Google Safe Browsing servers. The naming and interface choices have created confusion, as users cannot directly invoke the downloaded Gemini Nano model for tasks like summarizing open pages.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 7

Yandex Details Alice Voice Assistant Audio Buffering and Data Handling in Android Apps

Yandex has issued a detailed technical response to an analysis of its Android applications that raised concerns over potential collection of audio, contacts, bank card data, and other sensitive information. The company acknowledged the existence of a cyclic audio buffer that retains approximately 1.5 seconds of sound before an activation phrase and 0.5 seconds after it, with some pre-command audio possibly transmitted to servers for speech recognition quality checks. Yandex clarified that the Alice assistant only listens locally for the wake word when the app is open and does not continuously record conversations. Access to contacts was explained as necessary for voice commands such as calling entries from the address book, with the full book sent on first sync and only changes thereafter, without hashing to support accurate speech processing. The firm rejected claims of reading messaging app conversations and stated that bank card details are routed directly to an isolated PCI DSS-compliant environment rather than standard application servers.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 7

One Request, Five Observers: What Websites, Providers, DNS and VPNs Learn When Loading a Page

The article breaks down exactly what each participant in a typical web request can observe when a user visits a page over HTTPS. It examines the roles of the browser, DNS resolver, ISP, VPN service and the destination site itself, showing that each sees different pieces of metadata or content. HTTPS protects the page body and parameters from network observers, while Encrypted Client Hello and secure DNS further limit visibility of domain names. VPNs replace the user's home IP address with the VPN exit node but introduce a new trusted party that sees all traffic metadata. Browser fingerprinting, cookies and account logins often allow sites to re-identify users even after an IP change. The piece stresses that privacy tools must be chosen according to the specific threat model rather than relying on any single mechanism.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 6

Windscribe Releases Open-Source PowerShell Script to Remove Microsoft's Persistent Global Device Identifier from Windows

Windscribe has published an open-source PowerShell script called deGDID that removes Microsoft's Global Device Identifier (GDID) from Windows systems and prevents the creation of new identifiers. The persistent tracker survives IP address changes and operates below the VPN layer, allowing Microsoft to maintain device tracking even when users employ privacy tools. The script was developed after the FBI used GDID to identify a suspected hacker, raising concerns about undisclosed device fingerprinting. deGDID modifies registry access control lists and blocks the DeviceAdd interface to stop Windows from regenerating the identifiers after reboots or server contacts. While effective at disabling the tracking mechanism, the tool can break authentication to login.live.com and disrupt certain Microsoft cloud services. It is intended only for unmanaged consumer devices and will not run on domain-joined or corporate-managed systems. The project is described as experimental and cannot delete identifiers already transmitted to Microsoft servers.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 3

Yandex Apps Leak Pre-Trigger Audio Buffers, Payment Data, and Contacts via Reverse Engineering

Reverse engineering of Yandex Search and Yandex Browser APKs reveals extensive data collection practices on Android devices. The apps maintain a server-controlled pre-trigger audio buffer that captures up to three seconds or more of microphone input before the wake word Alice is detected. WiFi fingerprinting, full contact book synchronization via ContentObserver, and transmission of PAN and CVV details to mobpayment.yandex.net occur before tokenization. Additional findings include 94 JavaScript Bridge methods, logcat exfiltration with AES encryption, hardcoded Yandex DNS servers, and a native surveillance library named libquarkenstein_daemons.so. The analysis also covers passive geolocation, cell tower data collection, and inventory of installed applications including competitors such as Chrome, Firefox, WhatsApp, and Telegram. These mechanisms operate under remote configuration flags and bypass several Android privacy restrictions through manifest queries.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 1

TSPU Filtering Disrupts Timeweb Cloud Servers: Diagnosis, CDN Failures, and Reverse Proxy Bypass

Russian hosting provider Timeweb Cloud experienced widespread TSPU-based DPI filtering starting in early June that selectively blocked TLS handshakes on port 443 while leaving SSH, ICMP, and TCP connectivity intact. The issue affected multiple providers including Beget and Selectel, was publicly acknowledged by Timeweb on June 5, and proved highly variable by region, operator, and time of day. Attempts to mitigate via new IP addresses or Timeweb's own CDN failed due to poisoned caches and platform outages, while Yandex Cloud CDN blocked all POST requests required for WordPress functionality. A working solution involved deploying a minimal nginx reverse proxy on another Russian cloud VPS that preserves full HTTP methods, handles certificate synchronization, and routes ACME challenges correctly. Timeweb support later closed tickets without resolution after requesting ineffective mtr traces that cannot detect DPI behavior. The case highlights systemic challenges in diagnosing state-mandated filtering and the limitations of standard network diagnostics against selective TLS interference.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 1

UnifiedPush and Public ntfy.sh: Why Push Notifications Fail on Android Without Google Services

Developers building a messenger without Google services adopted UnifiedPush with the public ntfy.sh instance as the default distributor and push server. Production logs revealed that four out of five delivery attempts failed from day one, with error codes 507, 429, and 400 dominating. The 507 errors occurred because ntfy from Google Play relies on Firebase for instant delivery, leaving no active subscriber visible to the server when FCM is unavailable. Rate-limit 429 responses were triggered against the recipient's IP rather than the sender, collapsing under carrier-grade NAT used by mobile users. WebPush endpoints additionally rejected requests missing the mandatory TTL header. The team ultimately deployed a self-hosted ntfy instance and an embedded distributor inside the app to bypass these constraints.

Habr
๐Ÿ‡ท๐Ÿ‡บJul 30

Innovative Tunneling Techniques Leverage File Storage, IMAP, Meek, and NTP for Covert Connectivity

A new wave of experimental tunneling tools has emerged for establishing network connectivity through unconventional channels such as shared file storage, email accounts, legacy CDN protocols, and NTP. File-Tunnel enables TCP proxying by writing data to common storage backends including S3 and WebDAV, allowing traffic to blend with ordinary object storage access. True IMAP Tunnel (Secure) turns an IMAP mailbox into a bidirectional transport by storing encrypted frames as draft messages, supporting providers like Gmail, Outlook, and Yandex while offering optional AES-256-GCM encryption. Meek, originally from the Tor project, is being repurposed as a standalone pluggable transport that uses HTTP POST requests with session headers to traverse CDNs and shared hosting environments. ntptun implements IP-over-NTP and UDP-over-NTP by embedding payloads in NTP extension fields, with poll and push modes for downstream traffic and integration options with GOST for KCP-based proxies. These methods target dissidents and network experimenters seeking resilient bypass techniques against filtering and surveillance.

Habr
๐Ÿ‡ท๐Ÿ‡บJul 30

Six Bitrix24 Disk Migration Errors That Force Portal Redesign After Six Months

A detailed analysis reveals that copying a legacy file share structure directly into Bitrix24 Disk creates persistent access control, ownership and performance problems that surface only after several quarters of operation. The article examines six specific mistakes including one-to-one folder replication, overuse of personal My Disk storage, assignment of rights to individual users instead of departments, dumping unclear documents into the common drive, attaching file copies rather than links to CRM and tasks, and enabling full desktop synchronization. Each error is illustrated with real symptoms, root causes from rushed migrations, and concrete remediation steps using REST and D7 API calls. A Toyota T-Connect case from 2013-2023 demonstrates how unmonitored open permissions can remain undetected for a decade. The guidance stresses pre-migration inventory, pilot testing on one department, named owners for every top-level section, and quarterly rights audits. The piece is aimed at integrators and IT leads who handle large Bitrix24 deployments.

Habr
๐Ÿ‡ท๐Ÿ‡บJul 30

TGLock 2.0 Restores Telegram Connectivity with Local MTProto Proxy Over WebSocket

Russian developer babin2002 has released TGLock 2.0, a free open-source application for Windows, macOS and Linux that helps users restore Telegram when the client remains stuck on the Connecting screen due to content filtering systems. The tool launches a local MTProto proxy and routes only Telegram traffic through an encrypted WebSocket tunnel to the messengerโ€™s own web infrastructure, leaving all other network activity untouched. Unlike the first version, TGLock 2.0 now verifies that a working WebSocket tunnel has been established before displaying the โ€œTelegram connectedโ€ status and automatically tries alternative routes when a connection drops. The application avoids disabling TLS verification, changing system DNS or importing third-party Cloudflare domain lists, although users may optionally supply their own Cloudflare Worker. A LAN mode allows a smartphone on the same network to use the computer as a proxy, but voice and video calls may fail because UDP traffic is not proxied. No Android version is currently available and the macOS build is not signed with a Developer ID certificate.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 29

Smart Speakers Always Listen: Privacy Controls for Yandex Alice, Marusya, Salyut, Siri and Google Assistant

Voice assistants from Yandex, VK, Sber, Apple and Google keep microphones active in standby mode to detect wake words such as Alice, Marusya, Salyut or Hey Siri. No audio leaves the device until the activation phrase is recognized, yet false triggers, stored interaction histories and third-party app permissions create ongoing privacy exposure. Hardware mute buttons on Yandex Stations and VK Capsules cut microphones at the circuit level and display red indicators. Users can also disable voice activation, delete activity logs and turn off model-training options inside Yandex ID, Apple Settings and Google account controls. The article details exact steps for each platform and warns against placing always-listening devices in rooms where sensitive conversations occur.

Securitylab
๐Ÿ‡ท๐Ÿ‡บJul 29

Apple Updates Find My in iOS 27 to Automatically Switch Location Source to Apple Watch

Apple is enhancing the Find My application in the upcoming iOS 27 release to intelligently switch the source of a user's location data between devices. The current system relies on a single selected device, typically the iPhone, which causes inaccurate location reporting when the user leaves the phone at home. In iOS 27, the app will detect when paired Apple Watch devices move far from the iPhone and automatically begin transmitting coordinates from the watch instead. The feature supports both standard Apple Watch models and cellular variants, with LTE-equipped watches providing more reliable updates without depending on Wi-Fi or nearby iPhones. watchOS 27 will also consolidate the separate Find People, Find Devices, and Find Items apps into a single unified Locator application featuring a full-screen map and Digital Crown navigation. Both iOS 27 and watchOS 27 are currently in beta testing, with a public release expected in September.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 29

Russian Users Report BiP and KakaoTalk Inaccessible Without VPN, Suspecting Roskomnadzor Filtering

Russian home users have started complaining about disruptions in BiP and KakaoTalk messenger services. Messages fail to send or receive without a VPN connection, but function normally once a VPN is enabled. The issue reportedly began three days ago and affects the author, relatives, and friends according to a Pikabu post. Beeline support denied any operator-side restrictions, and Roskomnadzor has issued no official statement on blocking the services. Similar reports have emerged from other users, including those in the Volga region, with the consistent symptom that direct connections fail while VPN routes succeed. No independent technical confirmation of traffic filtering exists yet, and complaints may relate to specific operators, regions, or service infrastructure. The pattern matches previous Russian experiences with content filtering, though official confirmation of any block on BiP or KakaoTalk remains absent.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 28

One Underscore, 18 Months in Prison: Username Typo Sends Innocent Man to Jail

Brandon Klaym, a resident of Nova Scotia, spent 18 months in prison after Canadian and U.S. authorities confused two similar Kik usernames during a child exploitation investigation. Police sought records for the account fus__ro_dah but requested data for fus_ro_dah, directing them to the wrong individual. The error originated in a 2018 Wisconsin case involving 125 messages sent to a 12-year-old girl; the real suspect used a Skyrim reference that contained two underscores. Kik supplied Klaymโ€™s subscriber information, and his IP address led investigators to Canada. Despite finding no evidence on his devices and no proof he had ever used Kik during the relevant period, prosecutors charged him with multiple child-sex offenses. He was convicted in 2023, served his full 18-month sentence, and was only exonerated in 2024 when the correct username was examined during appeal proceedings.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 27

Free VPNs Fail Within Days as Russian Filters Detect Tunnels Without Decrypting Traffic

Free VPN services promoted in Telegram now stop working after just a few days, with Instagram Reels freezing, YouTube stalling in endless loading, and Google Gemini returning 403 errors. Modern Russian content filtering systems have advanced beyond simple IP blocking and can identify proxy tunnels through indirect traffic characteristics such as packet sizes, inter-packet intervals, and TLS handshake structures. A common failure pattern involves connections succeeding initially before data transfer abruptly slows or drops after roughly 16 KB, a behavior linked to deep packet inspection recognizing proxy patterns. Users and developers counter these detections with techniques including packet fragmentation, reduced TCP segment sizes, and tools like zapret to desynchronize analyzers while preserving normal server-side flow. Services such as sing-box employ uTLS to better mimic legitimate browser TLS fingerprints, while ShadowTLS v3 and padding methods help mask connections as ordinary HTTPS sessions to allowed resources. Recommended working options include AmneziaVPN, Cloudflare WARP, Red Shield VPN, and self-hosted setups on Xray or sing-box, though some claims around hynet.cloud lack independent verification.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 27

Why Simple VPNs No Longer Suffice Against Advanced DPI Blocking Telegram, Reels and Google AI Studio

Over the past year or two, users have observed that free VPNs and Telegram proxies often stop working after a few days, with Reels freezing, YouTube failing to load, Telegram stuck on Connecting, and Google AI Studio or Gemini returning errors. Modern filtering systems now analyze traffic behavior such as packet sizes, timing intervals, and TLS handshake characteristics rather than decrypting content. Techniques like TCP desynchronization via nfqws, MSS clamping with iptables, uTLS fingerprint emulation in sing-box, and ShadowTLS v3 for borrowing legitimate sessions are being deployed to evade detection. Padding is added to encrypted streams to reduce entropy and frustrate statistical shaping by TSPU systems. Commercial and self-hosted options including hynet.cloud, AmneziaWG, Red Shield VPN, GoodbyeDPI, and Cloudflare WARP each present distinct advantages and limitations when facing evolving network restrictions.

Habr
๐Ÿ‡ท๐Ÿ‡บJul 26

Personal Digital Resilience: Strategies to Secure Access Chains and Preserve Data Portability

The article explores how individuals can strengthen their digital infrastructure against service outages, lost access, and data loss without turning maintenance into a full-time project. It defines digital resilience through two pillars: security against unauthorized access and reduced dependence on any single provider, especially when regulators in different jurisdictions interfere. The author maps real-world processes to digital services, access methods, and stored data, then outlines recovery formulas for each failure scenario. Practical steps include auditing password-manager entries, eliminating circular dependencies, separating recovery roots by jurisdiction, and exporting data in portable formats. Special attention is given to secrets such as TOTP seeds and recovery codes, which are stored in an encrypted offline archive whose master password exists only on paper. The resulting structure features two independent trees rooted at Yandex and Google, with all critical services backed by verifiable exports and tested recovery paths.

Habr
๐Ÿ‡ท๐Ÿ‡บJul 22

Phantomdrive Open-Source USB Drive Conceals Encrypted Storage to Resist Coercion

Developer Ryan Walker has released Phantomdrive, a fully open-source USB device that initially appears as an 8 GB drive while hiding the remaining capacity from the operating system. The gadget uses a CH569 microcontroller with hardware AES support and an SD card for storage, switching to a hidden encrypted partition when a specific password string is written to a text file. It employs a key derivation function with 100,000 rounds of SHA-256 combined with a unique device salt derived from the USB serial number to strengthen password security. The project supports AES-CTR mode by default for performance reasons, delivering up to 20 MB/s reads, while AES-XTS is available as a slower but more robust alternative. All firmware, hardware schematics, and mechanical designs are published under open licenses, and the device is physically secured with epoxy resin to deter tampering. Walker acknowledges earlier community criticism regarding cryptographic implementation details and has addressed functional testing against OpenSSL references.

Habr
๐Ÿ‡ท๐Ÿ‡บJul 22

DeepSeek User Conversations Appear in Google Search Results via Publicly Shared Links

Conversations between users and the Chinese AI service DeepSeek, including Russian-language exchanges, have surfaced in Google search results. The exposed pages belong to Shared Conversations that users themselves made public through shareable links. These pages display full question-and-answer histories along with the names of any uploaded documents. No actual breach of DeepSeek occurred, and security researchers note that search engines indexed similar public chatbot dialogues more than a year ago. MWS AI confirmed that no closed chat histories or account access were exposed. Meanwhile, Yandex stated that links to conversations with its Alice AI assistant are blocked from indexing, remain active for only 14 days, and do not transmit attached files to recipients.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 20

What Makes a Quality Anti-Detect Browser and Why Aurorium Built Its Own Solution

Aurorium explains the current state of the anti-detect browser market and why most existing tools fall short for professional use. The company highlights that true anti-detect browsers must modify browser fingerprints at the kernel level rather than relying on JavaScript injections. It details how solutions like incognito mode, virtual machines, and browser extensions fail to provide proper isolation and spoofing. Aurorium emphasizes its own approach of modifying Blink and V8 engines directly in C++ to create consistent, undetectable profiles. The article also covers legitimate use cases including QA testing, OSINT research, SEO monitoring, and secure web scraping. Advanced fingerprinting techniques such as Canvas and WebGL noise injection are explained alongside methods to detect superficial spoofing attempts.

Habr
๐Ÿ‡ท๐Ÿ‡บJul 20

LG Monitors Automatically Install McAfee App via Windows Update Without User Consent

Home users of Microsoft Windows have discovered that certain LG monitors automatically install companion software upon connection to a PC, followed by prompts to try a trial version of McAfee antivirus. The installation occurs through the standard Windows driver and software delivery mechanism without providing a clear, separate confirmation dialog. The LG Monitor App Installer requests broad access to system resources, raising concerns even though the application itself is not classified as malicious. YouTube channel Gamers Nexus identified the behavior across both new monitors and models released approximately three years ago, including units previously used in office environments. Manufacturers commonly supply utilities for display calibration, firmware updates, and monitor management, yet the process becomes problematic when it serves as an entry point for optional software and advertising. Users are advised to review installed applications and remove unnecessary LG utilities, while organizations should monitor automatic software deployment after connecting peripherals. Neither LG nor Microsoft has commented on the issue at the time of publication.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 20

VPN Services Stabilize in Russia? Expert Warns Users Not to Relax as New Blocks May Be Coming

Russian users have recently noticed that personal VPN services and anonymizers are operating more stably after months of aggressive disruptions. Technical director Sergey Shcherbakov of the company Stakhanovets explains that the current improvement is likely only a temporary pause while deep packet inspection systems recalibrate. Earlier this year, DPI equipment was blocking traffic based on crude digital fingerprints of protocols such as OpenVPN and WireGuard, causing widespread collateral damage and connection drops. Operators are now believed to be collecting detailed data on ports, reconnection patterns, and obfuscation techniques to build more precise filters. Shcherbakov predicts the next wave of restrictions will arrive by late summer or early autumn, possibly shifting from outright blocks to throttling speeds during peak hours and delaying large file transfers. Meanwhile, users have adapted by maintaining multiple VPN clients, switching protocols and ports, and enabling obfuscation when needed.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 19

Mimolet Dating App Shows Strong Data Protection Practices in Photo Handling, Moderation, and Infrastructure Review

A detailed technical review of the Russian dating service Mimolet reveals several well-implemented security and privacy measures across its photo upload pipeline, content moderation systems, and infrastructure choices. The app processes every uploaded image by validating its actual content rather than file extension, strips EXIF metadata, resizes it, and stores only the cleaned version. Public images undergo pre-publication checks using two AI models plus an additional verification pass before they appear in group chats or profiles. Complaints and blocks are available to all users without requiring a subscription, and moderator decisions are logged for accountability. The core API and database run in Russia while media files are stored in a domestic S3-compatible object storage, and the main AI features operate on dedicated GPU infrastructure managed by the team. The review highlights two areas needing improvement: clearer data retention timelines and a dedicated, trackable appeals process for blocked accounts.

Habr
๐Ÿ‡ท๐Ÿ‡บJul 19

Mimolet Dating App Review Highlights Privacy Protections, AI Moderation, and UX Trade-Offs in Detailed Analysis

A comprehensive review of the Mimolet dating application examines its registration process, vertical profile feed, free filters, and advanced communication tools including built-in calls and AI-assisted messaging. The analysis praises detailed profiles visible directly in the feed, free access to comprehensive search criteria, and strong privacy measures such as automatic EXIF metadata removal from photos and primary data storage within Russian server infrastructure. It also covers public interest-based groups, pre-publication image moderation using multiple AI checks, and transparent complaint handling that does not require a subscription. Concerns are raised about lengthy registration potentially reducing user completion rates, the inclusion of weight as a searchable filter, unclear data retention timelines, and the lack of a formal appeals process for blocked accounts. The app offers three paid tiers focused on visibility and extra AI features while keeping core communication and moderation tools free, with approximately 200,000 registrations and 15,000 daily active users reported alongside retention rates of 44.96% at day three and 19.11% at day thirty.

Habr
๐Ÿ‡ท๐Ÿ‡บJul 16

69% of Browsers Worldwide Vulnerable: How Chrome Sync Enables Stealth Surveillance Without Malware

Google Chrome's standard synchronization feature can be silently abused to turn any browser into a surveillance tool, requiring only brief physical access to a victim's device and the addition of an attacker's Google account. Security researchers at Certo highlighted the technique after multiple cases involving intimate partner surveillance, including one incident where a womanโ€™s visits to a family lawyer and domestic abuse support sites were monitored in real time by her partner. Once sync is enabled, browsing history, bookmarks, open tabs, autofill data, and saved passwords are automatically transmitted to the attackerโ€™s profile, which can be viewed from any device worldwide without needing the victimโ€™s password or installing spyware. Chrome provides no prominent warnings about new profiles or active synchronization, and alerts about logins are sent only to the account owner rather than the device owner. With Chrome holding a 69.65% global market share according to StatCounter data from June 2026, the method potentially affects millions of users on Android, iOS, Windows, and macOS. Experts recommend regularly checking connected profiles in browser settings, using Incognito mode for sensitive activity, securing devices with strong passcodes and biometrics, and immediately removing unknown accounts while changing important passwords.

securitylab_n
๐Ÿ‡ท๐Ÿ‡บJul 15

Russia's ะœะ’ะ” Proposes Mandatory Purchase of Special Smartphones for Migrants to Enable Permanent Digital Location Tracking

Russia's Ministry of Internal Affairs is advancing plans to replace paper-based migration controls with continuous digital surveillance by requiring labor migrants to purchase a dedicated smartphone upon entry. Deputy Minister Igor Zubov announced that the device would create an electronic profile allowing police to monitor the owner's movements in real time and prevent unauthorized relocation between regions. The initiative builds on the existing "Amina" app already mandatory in Moscow and the Moscow region since September 2025, which has already led to more than 139,000 migrants being removed from registration. From July 2026, all visa-free foreigners must use the RuID app to create digital profiles, while a unified ะœะ’ะ” database containing documents, employment, housing, fines, and phone numbers is already operational. The new proposal differs from current rules by making the purchase of a government-specified device a condition of entry rather than simply installing software on an existing phone. Human rights advocates, including Svetlana Gannushkina, have previously criticized similar ideas, noting that forcing migrants to buy expensive devices is unlawful given financial and technical barriers. The plan remains a future proposal and has not yet been enacted into law.

securitylab_n
๐Ÿ‡ท๐Ÿ‡บJul 12

Telegram Will Not Allow Scanning of Private Chats โ€” Pavel Durov Strongly Criticizes EU Over Chat Control Initiative

Pavel Durov has sharply criticized the European Union following renewed discussions on the Chat Control law, which could mandate or encourage scanning of user messages, emails, and photos in online services to detect prohibited content. The Telegram founder described the tactics used to advance such surveillance legislation as reminiscent of those employed in banana republics, emphasizing that private user correspondence must remain protected from mass monitoring. Durov explicitly stated that Telegram will not implement any scanning of personal messages regardless of regulatory pressure from the EU. The European Parliament has returned the controversial bill for further consideration, with earlier versions proposing voluntary scanning by platforms to identify illegal material. Critics argue that the initiative effectively creates a mechanism for widespread surveillance of private communications under the guise of safety, while supporters claim it is necessary to combat illegal content and protect users. Telegram continues to position itself firmly on the side of privacy, refusing to turn personal chats into subject matter for automated government monitoring.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 10

Windows Tracks Users Through Persistent GDID Identifier: How to Minimize Your Digital Footprint

A recent case involving a 19-year-old hacker identified through his Windows installation has highlighted how Microsoftโ€™s GDID creates a permanent device fingerprint that survives VPNs and IP changes. GDID serves as a constant identifier across licensing, Microsoft Store, telemetry, and other services, making it difficult for users to stay anonymous even when changing networks. While there is no single button to disable this functionality completely, several practical steps can significantly reduce the amount of data Windows sends to Microsoft. These include switching to a local account instead of a Microsoft Account, disabling activity history, limiting optional diagnostic data, and turning off unused background services such as Phone Link and cloud synchronization. Experts note that simply reinstalling Windows does not erase the link if the same Microsoft Account is used afterward. The story underscores the ongoing trade-off between privacy and convenience in the Windows ecosystem.

AntiMalware