
Photo: Getty images
Most came to the conclusion that nothing sensational happened - however, it is not worth forgetting about security measures, in any case. The new newspaper Europe has collected the main thing on this topic and talked with IT specialists.
IMPORTANT
We remind you that the “new newspaper Europe” is recognized as undesirable. Do not refer to us in social networks if you are in Russia.
Over the years of internal repressions, the Russian authorities have gathered a whole arsenal of methods for tracking citizens' actions on the Internet, and with the outbreak of a full -scale war in Ukraine, the need for them has increased. Russian President Vladimir Putin is increasingly based on technology to ensure political power-because of the military failures of the Russian army, severe economic sanctions and “problems with leadership” after the rebellion of the founder of the Wagner PMC Evgeny Prigozhin, journalists say.
A artisan industry of technical contractors appeared in Russia, creating technologies for digital observation. Among them are Mfi Soft, Vas Experts and Protei, which began their activities with the production of components of the communication systems for special services.
Many of these firms, according to the publication, belong to Citadel Group - a company that was previously partially controlled by the Russian businessman Alisher Usmanov.
Access to such products was received by police and FSB officers. According to the documents of Russian providers of tracking services that are at the disposal of NYT, they allow “tracking some types of activity in encrypted messengers WhatsApp and Signal, track the location of the phones, identify anonymous users of social networks and break other people's accounts.”
The publication got acquainted with the "hundred files", about 40 of which "describe the surveillance tools in detail." They were provided by a person “having access to internal documents”, however, NYT does not specify the sphere of activity of his interlocutor. Based on these documents, journalists managed to find out at least about three digital tracking technologies:
The tracking system developed by MFI Soft allows you to display information about the telecommunication companies and monitor statistical data about their Internet traffic. According to one of the NYT schedules received, this program demonstrates the flow of information on a specialized management panel, access to which the FSB regional employees have access.
Another MFI Soft tool called Netbeholder is able to display the location of two phones during the day to determine whether they were next to each other, which indicates a potential meeting between people. He can determine “when someone sends a file or connects to the voice network in encrypted applications, such as WhatsApp, Signal or Telegram”, but the content of files and conversations remains unknown to security forces. The program also has data from which region of Russia the user of the messenger or from which country he came.
Protei has developed a product that deciphers intercepted telephone conversations and reveals “suspicious behavior”.
Journalists also got acquainted with “marketing documents”, according to which manufacturers tried to sell their products in Eastern Europe and Central Asia, as well as in Africa, in the Middle East and South America. According to the publication, such systems were used in the territories of Ukraine occupied by Russia, and Protei equipment was noticed in the use of the Iranian telecommunication company to register traffic and block websites.

According to the experts of RoskomSvoboda, "there is no sensation in this material." They explained that Russian special services almost always use data provided by operators - and this is no secret for a long time. Telecommunication companies can indeed analyze traffic and determine whether the exchange exchange or call occurred between certain users, but the content of such messages and calls in encrypted messengers is not available to them.
“[The article] describes those methods of obtaining information that special services have been used for years, or even decades (for example, SORM and the provision of user data themselves, if they were entered into the register of information distribution organizers),” the project said.
In addition, the material states about the detection of the location of people by mobile tower towers.
This has been done for a very long time - as well as the fact that calls on ordinary mobile communications are listening, the lawyers of Roskomvoboda emphasized.
The Executive Director of the “Internet Protection Society” Mikhail Klimarev believes that “the article is too emotional and there is no evidence of the performance of“ resolution decisions ”, but at the same time it describes the fact that we already knew for a long time.” He explained in his telegram channel that operators, for example, had the opportunity to determine that one user had two mobile phones.
“It is quite simple: in the HLR database (Home Location Register), all facts of the user terminal terminal to the network are stored (for example, registration time on the base stations chain). If you look in this base exactly the same requests from another apparatus, then with a high probability it will be possible to say that these devices are in one hand, ”he says.
As for Netbeholder technology, according to Klimarev, you can technically really “try to compare the fact of sending and recruiting any messages in messengers,” but there are restrictions. If tens of millions of people use the messenger, as in the case of Telegram, "then the amount of data is so large that the sample becomes very large and unreliable." Signal from this point of view is more vulnerable, because it is used less often, the specialist believes.
In addition, if the user changes the IP address, for example, connecting to Wi-Fi and using VPN, then "all this scheme becomes unreliable and useless."
NYT claims that Netbeholder uses the “Deep Verification of Network Packages” technology (DPI - Deep Packet Inspection), thanks to which operators analyze traffic. This gives the FSB access to metadata - general information about communication: for example, who is with whom, when and where they talk, and also the file is attached to the message.
“Here, however, there are many assumptions,” writes Mikhail Klimarev. - Such a scheme will not work if this is just a message. Because tens of millions of users generate billions of events that themselves may not be unique. That is, this is if it works, then only for calls. ”
In addition, security forces should have access to both subscribers, and if one of them uses VPN or is abroad, this will greatly complicate the process, the expert claims. In addition, special services will need serious and expensive equipment in order to analyze a huge amount of data to connect “Subscriber A” with “Subscriber B”.
“Theoretically, of course, you can send a request from the TK“ Find all sessions with such and such a length in such and such timestamps ”, but in practice this is the so-so tool“ Big Data ”. This kind of system, to put it mildly, is expensive, ”said the director of the Internet Society for the Protection of the Internet.
Journalist-investigator Andrei Zakharov noticed that Nyt journalists write about the use of DPI technology, but do not specify what it follows. “Are these the conclusions of the journalist? The paragraph above is only about DPI, but in my understanding this technology does not give such a deep analytics, ”he wrote.
Even if such a statement made Netbeholder, the article did not say about his verification, the investigator noted. “Nyt brought a panic without additional explanations,” he summed up the discussion.
The project “In touch” , which advises for free on security issues on the Internet, told Novaya Gazeta Europe that “NYT does not give quite new reasons for concern”.
According to experts, tracking the fact of a call is not some complex or new technology. “You can calculate that you called mom yesterday, but what exactly you chatted with her for an hour, it is impossible to find out for the whole hour - if, of course, you called whatsApp or Telegram: absolutely all calls on a regular mobile network are stored and can be listened. The same thing with tracking messages. The fact that you correspond with someone can become famous, but not the content of the correspondence, ”experts emphasize.
They recalled the "package of Yarovo", adopted in Russia in 2017. According to these laws, the entire traffic of the Internet and telephone communications should be recorded and stored for three years on special disks. According to the “Yarovoy Package”, all metadata (or logs) about when the user device has been contacted on the Internet is stored for three years.
“If you watched memes about cats, talked through WhatsApp or donated to human rights activists, then the state will know which site you entered and when. And store this information for six months. Theoretically, knowing this, it is possible to track your calls in the array of data: from which, for example, the messenger you made this or that call. And then get the second call from the array, the same in duration and messenger, compare them and find out who you called. Only, again, this is all not news for a long time, ”experts say.
In their opinion, the risks may be as follows: “It is very easy to build a graph of ties between people. Knowing the time and interlocutor, you can easily calculate who communicates with whom and how regularly. For example, your schedule of work calls. ”
“By the way of anonymization: do not forget that in Russia for many years the Internet is a passport. You present a passport when applying for a SIM card with which you use a mobile Internet, when conducting the Internet to the apartment, and public points without authorization are found less and less. To track that a certain device was connected to some networks, being in some geots, is not at all difficult. As well as tracking which of the colleagues you go to dinner: your phones lie very close for a long time, for example, on the same table, in the dining room, ”the team“ in touch ”noted.
All experts agree that VPN services need to be used. It will also be more difficult for special services to compare statistics with each other if one of the interlocutors is abroad.
Andrei Zakharov explains that under certain conditions, security forces will be able to find out who and when you call through Telegram, Signal or WhatsApp. To prevent it, at least one of the calling must enable VPN. Also, both should disable the “Calls through Peer-to-Peer” function, which directs the call directly to the device of the interlocutor
“When disconnecting Peer-to-Peer, the call goes through the messenger’s server, and then it is almost impossible to track who you call. Peer-to-Peer is disconnected in the settings of the messenger; It is important to understand that without it the quality of communication can be worse. As for messages, they go through the messenger servers. It is almost impossible to understand who you write - that is, you can conduct complex calculations, but, as I understand it, are quite expensive and not necessarily guaranteeing the result.
Total:
If you do not want the security forces to know who you are calling for instant messengers, turn on the VPN or disconnect Peer-to-peer. And this is relevant for those in Russia, ”writes the investigator.
In Roskomsvobod, they agree with Zakharov that the quality of communication in such cases will really fall significantly. They also believe that the inclusion of VPN "can help confuse the one who decided to follow you."
Experts of the “In touch” project give the following tips:
- Do not use ordinary mobile connection to talk and conventional SMS for correspondence.
These data are stored and not protected in any way. Since 2017, all calls have been recorded and preserved, this traffic has not been encrypted in any way. We need to call - call the messenger!
- Use messengers with reliable encryption.
Traffic of almost all messengers is encrypted, companies spend serious money on this technology and it is very difficult for any state to hack these messengers simply hacking. And completely sensitive conversations can be conducted in hidden chats or in chats with endangered messages - they are in almost every messenger.
Important: do not use unreliable services and messengers, such as VKontakte or Yandex, as well as “garbage” messengers - for example, ICQ or Tamtam.
- Use VPN always.
With any VPN, your traffic is encrypted from the provider. This means that any outside observer will see that you turned on the VPN, and that’s all. To whom you called, what sites you went to, what information you were looking for - it will remain between you and your phone.
- Follow the news in the field of information security in specialized channels and communities.
Seek for advice from experts if you are not sure how best to protect yourself on the Internet. Many civilian projects provide them for free.