
On July 3, The New York Times (NYT) published material on methods of surveillance of the network activity of Russians, which, according to the sources of the publication, is used by the Federal Security Service (FSB). An article on “hundreds of files” from an insider in an unnamed company or organization is based. The material describes the tools developed within the Russian company Citadel and its subsidiary MFI Soft .
In particular, a wide resonance was mentioned by the MFI Soft product - the Netbeholder program, which supposedly allows the special service to collect a large amount of information about Telegram, WhatsApp and Signal users. Many media interpreted the article by NYT precisely as an investigation that has opened the methods for monitoring the audience of popular messengers. However, in reality, these methods were known earlier. We will figure out in more detail what it is important to know about the sensational material and what precautions in connection with the threat of surveillance should be taken.
According to The New York Times, Netbeholder knows how to show security officials the whereabouts of two phones are nearby throughout the day. This suggests that both phones (both numbers and devices) belong to the same person. Moreover, the program knows whether the phones are together constantly or only for some time. Journalists believe that thanks to this, the FSB receives information that two people met during the day. Netbeholder even supposedly has an option that allows you to find out from which region of the Russian Federation a specific user (or from which country, if it is a foreigner).
Also, according to NYT, the program shows when one user sends another file or calls through WhatsApp, Signal or Telegram. This function is carried out using DPI technologies (Deep-Packet Inspection-deep testing of traffic packages for the purpose of regulating or filtering). “This gives the FSB access to important metadata, which show who speaks and correspond with whom and where and where it happens, and whether the files were attached to the message,” the article says. NYT notes that earlier, to receive such information, the law enforcement bodies turned to the owners of the services - and those in turn decided whether to provide data to the security forces. It is important to understand that it is only about metadata, and not about the content of the transferred files and calls.
Other programs, the description of which the American newspaper received, translate intercepted telephone conversations into the text, collect passwords that are entered on unspent sites, and even hack accounts and identify anonymous users. NYT does not lead the details of how all these technologies work and how the FSB uses.
For the first time about the program with the name Netbeholder, the creators of the AGentura.ru website Andrey Soldatov and Irina Borogan wrote ten years ago. The Canadian company Aloe Systems introduced the product with this name in the international market by the MFI SOFT. Judging by the functionality described on the site, even then the product was intended for surveillance carried out by law enforcement agencies. In addition to Canada, the investigators pointed out, Aloe worked with clients in the USA, Mexico, Argentina, Brazil, Costa Rica, Salvador, Peru and Uruguay. In the main office of the company, immigrants from Russia worked. “MFI Soft” was not yet part of the Citadel holding - it was bought in a few years.
“Citadel” is the leader of the SORM market (wiretapping complexes that use the FSB and other power structures according to the “Spring Pack” - it will be discussed below this material). The company was founded in 2015 by entrepreneur Anton Cherepennikov and his partners. However, she is considered close to Alisher Usmanov, since Cherepennikov had many other projects with him. In 2017, Boris Miroshnikov became Vice President of Citadel, who previously headed the Office of the “K” of the Ministry of Internal Affairs to combat digital crime. MFI Soft is only one of the many holding companies. It is not known to whom it belongs now: information about the company in the Unified State Register of Legal Entities is hidden.
“Citadel”, its subsidiaries and other organizations working with SORM, as well as their management since February 2023 are in the US sanctions list.
A short answer - yes, it was known. Indeed, the Nyt investigation does not say anything new.
Russian security forces can listen to telephone conversations since 1996-using the SORM-1 system (the system of operational-search measures).
In 2016, the so -called “Spring package” entered into force. According to it, communication providers are required to store half -year archives of calls and messages of subscribers and the archive of the same metadata on the transfer of messages and calls for three years. Operators implicitly provide this information from the FSB on demand, so there is nothing surprising in the fact of the existence of software for obtaining this information. For example, if the FSB wants to know about all the cases when you have visited the Internet and which sites have visited (in particular, did you go to the servers related to WhatsApp or Telegram) - the service will easily do this by requesting that your provider, who does not have the right to refuse it. In fact, thanks to the “Yarovaya Package”, the provider is obliged to monitor all your movements on the network and report them to the security forces at the first request. Unless, of course, you do not use the VPN: then the provider will be able to share a smaller amount of information with special services-for example, the IP address of your VPN server.
The New York Times indicates that the FSB has access only to information about the transfer of messages between subscribers, but not to the essence of messages transferred to encrypted messengers. This, in general, is also not news. Although, according to the “Package of Yarovoy”, the messengers were supposed to transfer the encryption keys, neither WhatsApp, nor Signal, nor Telegram - in any case, officially - this was officially done. And, most likely, they could not: in WhatsApp and Signal, the end of the default (or through) encryption (End-to-End Encryption) is used, that is, only the users themselves know the keys. In Telegram, such encryption is available in “secret chats”, which few people use due to inconvenience. But the messenger uses his own cryptographic protocol MTPROTO - and its founder Pavel Durov assured that this is an effective way not only to keep the user's archive secret, but also to limit access to data for Telegram employees. However, many cybersecurity experts still criticize Telegram for the abandonment of the end of the default encryption.
To inspect and control user traffic, the Russian authorities use the DPI technology mentioned in the article by The New York Times. Equipment for these purposes is on the infrastructure of all key providers, but, as a rule, DPI is used to slow down the work of specific sites and services. For example, with the help of technology, Twitter slowed down (users in Russia were loaded with difficulty, and the photos and videos were not uploaded at all), limited access to Google documents and “smart voting” . This happened without making sites in the register of prohibited-simply by the will of the regulator and without any warnings.
To collect metadata about the behavior of specific users, much less determining whether one user sent some files to another, DPI is usually not used. However, in theory, even if you use the usual proxy service , using DPI you can see that you transmitted messages in the messenger or made voice calls in it. The technology still does not access the contents of the calls - at least if the messenger does not transmit the FSB keys of encryption. “The operator really can determine on the characteristic signs of traffic whether the call or text correspondence occurred between certain IP addresses, but he cannot look inside if the messenger has a encryption function. It makes it difficult to obtain data if the IP is abroad, so turning on the VPN here can help confuse the one who decided to follow you, ” says experts of Roskomvoboda.
Yes, but the technology described in the article Tracking people by phone is also not news, security forces have been using it for a long time. Moreover, the information about your geolocation “mined” through the device can be acquired by a relatively small amount (in any case, until recently). This in 2019 during the editorial experiment of the Russian BBC service was shown by journalist Andrei Zakharov. In less than 10 thousand rubles, he bought information from the employees of the mobile operator about the location of his relative at the call moments for a whole month. The coordinates were exhibited at the addresses of the nearest cellular towers.
The well -known investigation by Bellingcat about who poisoned Alexei Navalny was made using the same data purchased in the black market. Similar data were used by the Mediazon and Scanner Project, which restored the chronology of the movements of the murder of Boris Nemtsov. The security forces, of course, have free access to such data.
In order to determine where there are specific people, investigators will triangulate stations. How they do this, said in an interview with Medusa Christ Christ Grozev:
In billing in the data for each call or Internet connection, the base station [of the cell operator] is also indicated, to which the phone was attached at this moment. If a person often happens in the same area, then he most likely connected to several base stations at once: for example, one because of the bad weather began to work worse-and the mobile phone simply transferred to another.
And if you find two in billing, and preferably three different base stations that the speaker connected to, then you decide the exercise purely from the school course - you calculate the triangulation.
The last resonance episode with the alleged use of technology is the detention in March in Belarus Alexei Moskalev, who ruined from Russia on the eve of the sentence in the case of “discrediting” the army. Sources claimed that the security forces managed to find him after he turned on his mobile phone.
When calling through the default application, Peer-to-Peer (P2P) technology is used. Roughly speaking, this means that a communication channel is set directly between the IP addresses of users. Using a simple program to analyze traffic, you can find out what IP address your interlocutor has, and he is what you have .
Therefore, in theory, if the special service requests from your provider, what addresses you contacted through online calls, and then the same information-the providers of your interlocutors, then it will most likely be able to find out who you called. It is clear that such an operation is more likely to be carried out if we are talking about surveillance of a specific user. It is hardly possible to constantly turn this scheme for tens of millions of users.
It depends on what anonymous messenger or mail you use, but in general - alas, maybe.
If you use Signal or WhatsApp, tied to the Russian phone number, it is easier to deanonymize you. We can say that you registered in these services “according to the passport” - because to buy the number you gave passport data, and the FSB has access to data from cellular operators. If you have a number that was purchased in another country and which you have not indicated anywhere else, it is already more difficult to reveal your identity (especially if you bought a number in the country such as Georgia, Cyprus or Croatia, where SIM cards are sold without a passport).
The Telegram user user identification uses the ID service itself, which binds to the phone number on which the account is registered. Even if you hide the number immediately after registration, in theory you can still be found through services such as "Eye of God". The same databases - containing the phone number, Telegram ID and the rest of the information known about the user through its phone number and the security forces often received from hacker “drain” are also used. For example, back in 2021, Rostec for use at the Ministry of Internal Affairs bought the development of the St. Petersburg IT company T.Hunter. “The investigator will be able to load the suspect to the IMIL or phone number, and the software complex, using this fragment, compares the data of data: IP addresses, information from payment systems and advertising identifiers-more than 40 parameters,” the manager of the developer Igor Bederov told Kommersant. The project of former Belarusian security forces by BYPOL , investigating repression in Belarus, spoke about how this works in practice for calculating and arresting activists in his YouTube channel.
The main advice, which largely protects you from the threat of surveillance, sounds simple: use VPN. Yes, always. It is advisable to use a service that not only replaces your IP address so that you can go to blocked sites, but also uses more cunning algorithms for bypassing censorship.
If you use Telegram, re -read this “Medusa” instructions on how to do it more safely. And remove in the settings the possibility of peer-to-peer calls from people who are not added to your contacts.
And for sensitive correspondence - if you have such, it is better to choose other messengers. From Signal - unless, of course, you have a phone number that is not tied to your passport data - to Briar, in which you do not need a phone number to communicate on an encrypted channel.
Dada Lindell