In 2021, privacy in technology became mainstream. The state and corporations want to know everything about users, but this creates the opposite effect. The society discusses the ups and gaps of priivasi projects, participates in discussions about the right to confidentiality, and companies and startups are trying to catch demand and earn on it. About what is happening in this market, at the request of The Bell, was told by the technical director of Roskomvoboda, founder of Privacy Accelerator, Stanislav Shakirov.

In 2021, the Internet user leaves even more traces. The surfs on the network, working on special platforms, ordering food, calling a taxi, entering any online services, each user generates a huge amount of data, a significant part of which is one way or another personal. These data are tracking, analyzed, fixed, merged into the databases, enriched, sold and bought many times. Big Data and information accumulation technologies today allow you to collect an incredible array of information about the personality of almost every person, about his tastes, hobbies, preferences, lifestyle, income and social status, as well as about his family and the immediate environment.
Even these data are very interesting to the state, in particular, special services or control bodies for operational work, officials and political technologists to assess the social situation and the management of views. They need global corporations and companies that, through data, know better when and what you can sell. And a set of data with a concrete to a particular person is a real gold core. And if the state and corporations collect data quite legally, through many effective schemes in which users themselves joyfully leave information about themselves on different resources, considering it trusted, then there are already other people who are less intelligent in terms of the law, but no less greedy to our data. These are hackers, crackers, piercing, data merchants in black markets. And the intense struggle between them for the "new gold" only increases.
The more companies and media corporations invade the personal data of users, the deeper the state looks into the personal lives of citizens, the stronger and more acute the confrontation of those who do not accept such an intervention. Now people not only try to protect themselves, arranging privacy settings and even-finally! -Reading user agreements, but also become active participants in the business processes of the largest corporations, “voting the ruble and legs” in situations where compromised companies leave and go to competitors who demonstrate privacy care. So among the conversations that our privacy is lost forever, there is a strong request for its return and the whole industry Privacy Tech, which will satisfy this demand.
In 2021, the whole world observed how the reputations of companies dabbled and collapsed, how unknown attempts to seize personal data to IT giants, how former “trusted” services became suspiciously accommodating with the authorities, exposed with scandals.
At the beginning of the year, whatsApp, which is part of the Facebook infrastructure, is now Meta. The messenger announced that the Maternal company Facebook will be amended in the confidentiality policy will receive expanded information about user accounts “to improve advertising targeting”. The mega scandal came out: the top-leaders of opinions, the largest experts, public organizations criticized, and some stars and politicians defiantly went to Telegram and Signal. The outflow of users of the messenger was impressive. Facebook even temporarily rolled and prolonged the term for entry into force of new confidentiality rules, but did not completely abandon them. The rebellious users who did not accept a new policy (press the button in the application) threatened to turn off important functions, or even complete removal of accounts.
Telegram in the past year grew users against the background of the failure of the new Privacy Policy of WhatsApp and the migration of Donald Trump supporters from Twitter. Durov cleverly built into the agenda, inventing all new ways to take users from competitors: for example, he released a new feature to transfer the history of correspondence from other applications such as WhatsApp, Line or Kakaotalk. In June, Teelegram was suddenly “unlocked” by Roskomnadzor for “the willingness to counteract terrorism and extremism”. Many were alerted by the development of events: if Durov cooperates with the Russian authorities, perhaps the messenger will no longer be as independent and safe as during his three -year opal for failure to provide intelligence services? In September 2021, for the first time in the Russian segment of the messenger, a censorship of political content was carried out - the bot “Smart Voting” was removed. But there is still no evidence that Telegram has become less secular or that some personal information of users is transmitted to third parties, although experts are closely monitoring it. The number of users of the application is growing, and the level of trust remains high.
2021 was marked by a large scandal with mass surveillance of gadgets for human rights activists, journalists, activists, religious leaders and political leaders around the world, including current higher officials, ministers, presidents. Spyan software PEGASUS infected phones and used 50 thousand citizens to collect personal information, although it was supposed to work only to monitor terrorists and other dangerous criminals. PEGASUS penetrates smartphones based on iOS or Android and gains access to almost all the key data on them: photos, messages, geopolition, e -mail, contacts and other things. The development of the Israeli company NSO Group can be bought at the state level and, according to independent researchers, it is now used by special services at least ten countries that establish wiretap not only within their country. As a result of the scandal, the French president changed the telephone number and the device itself, the United States included NSO Group in the stop list of business companies (incidentally, the Russian Positive Technologies), the public calls for a global moratorium on the sale of spy software, and also the manufacturer is threatened by large trials.
In the fall, the reputation of the Protonmail service was shaken, which has long remained the security standard and an impeccable example of webcam with encryption. It turned out that the service handed over to the Europol the personal data of the activist of the environmental movement of Youuth for Climate, participating in the Paris rally, including information about the user and IP address devices. Protonmail is based in Switzerland, whose authorities are supposed to be pressed on the founders. The event was very cut in the industry, since Protonmail, like ProtonVPN, was considered services for crypto paranoids. The company itself tried to explain that in the privacy policy, they have prescribed the possibility of issuing IP in cases of reasonable requests from law enforcement officers and promised to make some points of the document “more understandable”. And also assured that user mailboxes are encrypted and their contents cannot be available to anyone, as well as the traffic of the ProtonVPN service.
In November 2021, Apple announced that it was starting the trials with NSO Group, a PEGASU manufacturer, in order to achieve a legislative ban on the use of any software, services or devices of apple trees for NSO. Thus, it is planned to protect users from the threat of invasion of their personal data. Meanwhile, Apple itself at the end of summer 2021 also ended up in the epicenter of the scandal after the company's statement that it would remotely check the availability of candid children's photos on the devices of its users. If you believe Apple, everything is quite decent, safe and has good goals, but specialists and users around the world were alarmed by the fact that artificial intelligence will be allowed to be private photos that will be sorted by certain criteria. First photo, and then what? Even yesterday, the company publicly refused to cooperate with the FBI and help unlock the IPIPHIENT, calling this a dangerous precedent. Today - triggers a mechanism of background scanning of information on devices, which can further be used not only to identify content related to children's porn, but also according to any other criteria, including political, economic and other.
In December, it became known that Apple turns off the scanning plans for all devices for indefinite periods for intimate children's photos - this was the result of violent criticism from users and the community. However, in the latter IOS 15.2, a new “parental control” function has been released, which needs to be forcibly enabled and then the system automatically scans the photo that the child sends and receives through Imessage, and warns about outright content.
From fresh: at the end of November, the USA was declassified in the United States with almost one -year prescription where it is spelled out, what access and which messengers have the FBI. Apple Imessage distinguished themselves again and all the same WhatsApp. According to the document, they give law enforcement officers the most data, and the Epplov messenger can show the details up to the text of the messages if they are uploaded to ICLUD, but WhatsApp shares information about new actions in the necessary accounts in almost real time. The secret of user correspondence is best protected by Signal and Telegram. Well, it is not for nothing that this year they collected millions of new users who moved to them from other platforms. It is interesting that all instant messengers have almost the same encryption (except Telegram), but metadata gives out in different ways and in different volumes.
The state and corporations want to know more and more about users, and the latter, in turn, are less and less want to share information about themselves. People begin to look for new ways to maintain their privacy and anonymity on the Internet. In 2021, the confidentiality in technology became mainstream and a key point for the formation of business concepts, both new and already established. And experts say that in the coming years this trend will only develop.
Against the background of the news about the next scandal with an unlawful capture of user data or with leaks in large corporations, users turn their attention to startups and products of companies that form the new Privacy Tech market. The number of prime solutions is growing from year to year, and their functionality and quality are increasing all the time, because they should compete not only with beginners, but also with IT giants, many of which already have their own privacy products. Crunchbase analysts in mid -December 2021 counted 230 startups with the total investment amount of $ 2.6 billion. The total investment in the industry reached $ 5.5 billion of the United States.
In July, the Canadian technological startup 1password, representing a popular password manager, attracted $ 100 million from the ACCEL venture company. The deal increased the total assessment of the company to $ 2 billion. The product was originally developed for end users, but corporate customers began to actively use it. Especially the demand in the B2B sector has become noticeable to the pandemic. According to some reports, more than 90 thousand enterprises are now using the solution, including IBM, Gitlab, Slack, Shopify and others. The company has also integrated with Slack and Ripppling.
Another of the interesting cases of this year: in September, Kape Technologies announced the purchase of an ExpressVPN VPN service. The transaction in the amount of $ 936 million of the United States should be ensured partially in cash, partly shares. Kape Technologies is a British-Israeli technological company, an operator of a virtual private network. Due to the merger, the company's client base will double and in the future will exceed 6 million users. According to experts over the past four years, the average annual growth rate of ExpressVPN has been 35.1%, and the demand for consumers convenient for consumers is growing data confidentiality and data security. Partnership agreements with the VPN service have already concluded Acer, Philips, HP, HMD Global and Dynabook. The leadership of Kape Technologies has already promised users to improve cybersecurity tools to help users “protect their data and rights”. Unfortunately, he has his own skeletons in the closet, which can give a shadow to the repressvPn reputation: it is known that the founders of the company were developing spy programs.
In October, a new round of investment was held by SkyFlow, a company engaged in developments in the field of personal data protection for technological companies. Santander Wendular Fund and the InSight Partners venture company invested $ 45 million. The main product SkyFlow is Privacy Vaults, with which the developers introduce data security into their solutions. Now the company is developing areas designed for healthcare and financial sector. Among her partners Visa, Experian, Alloy and other fintech of the company. Skyflow shows eight times growth over the last three quarters, the amount of investment for 18 months is $ 70 million.
The growth in the Privacy Tech segment is especially noticeable in the past two years. In 2020, during the pandemic, corporate solutions for safety quickly flew up: people began to work massively from home, which required investment companies in employees safety, protection against hacks and ensuring the safety of client data. In 2021, the many privas scandals gave an impetus to the B2C market-the final consumers became interested in the products of confidentiality. However, the beginning of Privacy Tech was supposed to be even earlier: in 2018 with the introduction of general data protection (General Data Protection Regulation ( GDPR ) in Europe), as well as the American analogue - the California Privacy Act, CCPA ).
Investments in Privacy Tech solutions will only grow on the horizon of the coming years. Investors looked at this market for a long time, but now they were convinced that it was formed by sustainable demand, and privacy products bring profit. This is especially interesting because a few years ago, a consensus was formed among experts that privacy no longer exists and people must humbly learn to live according to new rules, where we are all under the cap with technological giants and state bodies. But the market itself dictates the rules.
So far, startups are brightly flying in Priwasi-business and rightly, but true, large corporations unfold to privacy, discussions are going on in society and new useful practices develop that help to reconcile the interests of society, state, private companies and each individual citizen in matters relating to personal data.
The first regular reports on transparency (Transparency Reports) began to publish Google in 2010. After Snowden’s performance with the exposures of global mass surveillance by the United States, many other commercial companies also began to issue statements that disclose statistics on requests from the state (and copyright holders) for user data or removing records and content. Today, transparency reports are standard practice for decent companies, they are regularly published by Google, Twitter, Tiktok, Microsoft, Apple, Facebook, Yahoo, Cloudflare and others. Thus, companies not only demonstrate their efforts to ensure the safety of users and openness for shareholders, but also confront the increase in requests from government agencies, many of which are excessive or groundless.
In Russia, a trend is also developing for the transparency of companies in compliance with user digital rights. The pioneer became the Habr IT blogging platform, which was the first in RuNet to issue its report with information about the requests of the authorities at once in a few years. Behind her, oddly enough, “Picabu” reached out, then there were good reports from Yandex, Facebook, something from VK. Despite the fact that requests for the issuance of personal data of users are the most sensitive and numerous requests to digital companies from government agencies, only Habr and Yandex revealed information about the number of such requests. For example, according to the latest Yandex report , for the first half of 2021, the company received 19,650 requests from law enforcement officers to disclose information about users, while only fifth of them remained unnoticed. For comparison: for the entire 2020, Yandex received 8872 such requests and rejected more than half of them. Meanwhile, Google in his report in 2020 reports only 1207 requests from the Russian authorities and that he satisfied no more than 18% of them. The remaining leading Russian digital services and companies have not yet indulged in transparency, justifying this by the fact that they do not see a request from users. A few years ago, VK announced that he would share the “general statistics of requests”, but since then he published only the rules for working with the appeals of state bodies, there are no specifics.
Almost two years ago, the first independent rating of compliance with digital rights in Russia was released. In 2021, he evaluated the popular Russian Internet services and web platforms in connection with their compliance with the right of users to freedom of expression and the inviolability of private life. Для оценки применяется методология согласно которой на место в рейтинге влияет не только наличие опубликованных отчетов о прозрачности, но и новые разработки для предотвращения утечек и обеспечения защиты пользовательской информации, обучение персонала работе с чувствительными данными.
В 2021 году впервые правозащитные организации протестовали против выхода на IPO технологической компании. Речь о Cellebrite, израильском производителе оборудования и ПО для взлома смартфонов. Весной этого года компания объявила о планах по выходу на NASDAQ. И сразу столкнулась с сильнейшим противодействием. Организация Access Now, защищающая цифровые права граждан, опубликовала открытое письмо, в котором обратилась к Комиссии по ценным бумагам США, инвесторам и самой бирже NASDAQ с призывом приостановить листинг компании Cellebrite. Обращение поддержали правозащитники по всему миру. В письме говорится о том, что компания Cellebrite причастна к нарушениям прав человека, так как продает свои решения репрессивным правительствам, которые используют их для преследования несогласных. В самой компании заявляют, что она больше не ведет бизнес с Беларусью, Россией, Китаем, Гонконгом, Макао и Венесуэлой, однако продажи в некоторые из этих стран были приостановлены только в текущем году и правозащитники отмечают, что нет информации о том, было ли отозвано уже использующееся оборудование после разрыва отношений. И критики, и наблюдатели с интересом следили за развитием ситуации с IPO Cellebrite, понимая, что прецедент может повлиять на фондовые операции других компаний, которых прямо или косвенно связывают с нарушениями цифровых прав. Тем не менее, 30 августа 2021 года компания объявила о начале торгов на бирже.
Общественные организации, занимающиеся вопросами приватности, не только критикуют бизнес за промахи или неэтичное отношение к пользовательским данным. Они еще и награждают лучших, стимулируют компании и их руководителей делать больше для прайваси. Так на западе уже много лет существуют нишевые премии для инициатив и специалистов в области приватности, и в России также появляются отраслевые награды. Еще один тренд: прайваси-акселераторы и хакатоны технологий конфиденциальности, которые объединяют как признанных экспертов отрасли, так и молодых технарей, позволяют им обмениваться опытом и вместе генерить новые идеи. Сообществам важно поддерживать тех, кто занимается развитием прайваси-сферы: практикующих специалистов, компании в области приватности, стартапы и privacy-евангелистов.
Privacy-евангелисты — это IT-специалисты, которые продвигают в обществе идеи важности и необходимости приватности и защиты частной жизни людей от вмешательств как в интернете, так и в оффлайне. Как правило, это люди с хорошим техническим бэкграундом, ведущие специалисты отрасли, руководители крупнейших компаний и топ-звезды индустрии, к мнению которых прислушивается множество людей. И это не только крипто-анархисты, как например, Мокси Марлинспайк, основатель Signal, который в 2021 году взламывал устройства для слежки и критиковал их уязвимости. Это могут быть основатель Twitter Джек Дорси и техно-энтузиаст Илон Маск, которые пропагандировали защищенные мессенджеры. Это и Эдвард Сноуден, который много лет уже остается одним из самых загадочных и почитаемых экспертов по приватности и борьбе против слежки. В России развитием идей приватности и расширением знаний в этой области занимаются, в основном общественные организации и молодые политики. Представители российского IT-бизнеса в настоящий момент заметно дистанцируются от обсуждения вопросов вторжения в частную жизнь или слежки за гражданами, видя в этой сфере интересы государства и не желая переходить ему дорогу.