- What does today's failure look like?
-To what happened to Telegram in 2018: then [the authorities] tried to apply some very large filter [to block the messenger]. To which this filter is now [tuned] is incomprehensible.
The first option is for specific IP addresses. For example, if you block the range of IP addresses of some Amazon or Cloudflare, then the picture will look about the same.
Another option is to block unidentified traffic, as in Iran . In this case, the entire list of IP addresses is divided into three zones: white, gray and black. In black traffic, it is blocked immediately, in white - it is always available, and in the gray there is an unfamiliar [to the authorities] traffic, which is filtered. It seems that this Iranian script begins to be introduced in Russia. Maybe they applied a similar filter to the IP address from the gray list, and chopped off all unidentified traffic-and it turns out that many more are sitting on it.
We compare the policy of Russia and Iran on the Internet in the podcast "Medusa"
![]() |
- How did it happen that this traffic was unidentified?
- He is encrypted. If you cannot understand what protocol this traffic belongs to, then it is not identified for you. Sometimes, according to the packages of packages , you can understand what this traffic belongs to: for example, if it is OpenVPN, in the package title it is clear that this traffic is from OpenVPN . If it is Wireguard , then it also shows that this traffic from the Wireguard VPN protocol. And if, for example, use protocols such as Amneziawg or Shadowsocks , then it is not particularly clear-this is just some kind of encrypted HTTP traffic.
There is another hypothesis. We see that Roskomnadzor includes the last filters, probably two weeks. Periodically, something falls from them, but they are still stubbornly trying to do it. So the hypothesis lies in the fact that now they are trying to interfere at all ...
- To prevent the Russians from bypassing blocking?
- Yes, they are trying to filter all unidentified traffic. But part of the Russian services or applications could not fully transfer their infrastructure to domestic platforms. That is, you open, for example, “Yandex.. Lovka”-and the Konovo application loads the information, some libraries that it stores not on its website, but in another place, because they are not supported by Yandex itself, but some other company.
Since the adoption of the Law on the Sovereign Runet [in 2019], all major Russian companies were invited to transfer everything to domestic infrastructure - so that we do not go to foreign Internet and not select all these libraries, and so that everything would lie inside Russia. It was explained that this was necessary to protect against external threats, but in fact it was preparations for the national shartau, in which all the key services for Russia would continue to work.
Actually, why, simultaneously with Telegram and WhatsApp [now] could there be any other resources? Because all of them could use things that are on the external Internet. They did not transfer these decisions to the domestic infrastructure, therefore [when], when blocking one service or one type of traffic, one pattern of blocking is used, it can lie down at once.
But besides this [services and sites] may also lie down due to the fact that the Cloudflare, Amazon or Microsoft Azure IP addresses are blocked. There are clouds that have a range of IP addresses, it can be Sber, Slack, WhatsApp, and Telegram, and anything. Just because Cloudflare IP addresses are used from a half-Internet, and another quarter is Amazon. Actually, for this reason, during the lock of Telegram, a bunch of everything was blocked in the past. Now there may be the same story: they either chopped IP-shniks that use half a ruin, or some kind of traffic pattern that is also used by half a Runet.
-Suppose that we are talking about blocking Telegram. What arguments are there in favor of this version?
- We have long been waiting for an attack on Runet. Roskomnadzor, firstly, is trying to block the ways of bypassing locks, and secondly, sites that distribute content and are not controlled by it. Block Signal , block YouTube , block VPN protocols . Telegram blocking is also an expected story. And they do it in August, when many are on vacation and therefore do not much monitor the news. All this falls into the overall picture of the blocking of services that cannot be made self -certified. Nothing unexpected, nothing new.
-In the case of Telegram, the blocking still may seem unexpected. We remember the story with an attempt to block in 2018, but then the conflict was settled . In recent years, the Telegram itself could have been made a complaint for blocking bots or channels associated, for example, to the FBK and Navalny, and the channels associated with the Russian authorities continue to work. Why block it in such conditions?
“It's hard for me to agree with this.” I drew attention to the fact that Telegram blocked [channels] when unrest took place in Ufa or when, after the start of the conflict in Israel [locals] in Dagestan, they ran andsearched for Jews. Then [inside Telegram itself] automatic filters worked each time: when many people complain about something, it is blocked. But a few days later all the publics that the protesters were restored were restored.
Is it possible to say that this is the evil intent of Telegram, that the FSBSHNIA calls Durov and ask: “Blok this group for three days”? No, it is rather like how Telegram support works: they usually answer randomly, a few days after you write, but they may not answer at all. And I do not really see other stories about how Durov could begin to cooperate with the FSB. Yes, they remove [channels] that define as containing terrorism, extremism or children's pornography, but they do this in all countries. I can’t believe that they agreed with them. Telegram is a company with a billion of users, and an agreement with Russia will very harshly finish her reputation.
-You can highlight one of the versions of what you voiced by what fails happened, as a priority? Or are they likely likely?
-I am inclined to the fact that these are some new patterns of blocking unidentified traffic on an IP address of some kind. And what service they tried to block, WhatsApp or Telegram - I do not have enough information to answer the question. Rather, Telegram, because he stopped opening exactly at midnight [in Moscow on August 19]. This suggests that the teachings are happening now, how to block Telegram. But not the fact that it is - these are just guesses.
-What do you think about the version that Roskomnadzor himself voiced-that the malfunctions of the services are related to DDOS-Ataka on Russian communications operators?
-It is clear that they are simply somehow justified. They made excuses with YouTube - they say this Google is to blame for the fact that YouTube is slowly working. Of course not: DDOS attacks are when you have one service. And when packages of certain services cease to walk in Russia, while they continue to walk with others, this is different. Plus with VPN, everything continued to work.
-That is, if it were a DDOS-Atak for anything, the resources would not work anywhere at all, regardless of location and regardless of which country was chosen in the VPN service?
- Yes. Well, what can you even do it? You can dodo web sites-then one website will not work. If someone knows where the TSPU control panel is located, you can try to entrust it. TSPU is a "technical means of counteract threats." This is that as a result of the Law on Sovereign Runet, they put the communications operators and through which Roskomnadzor conducts its locks. That is, each communication operator has a cable, a box is stuck in its middle, through which all traffic comes. Roskomnadzor has a single center for managing these boxes throughout Russia-and from this single center they can apply some kind of traffic filters in a particular region or at once in all.
You can make an attack on TSPU, but then it will stop working either everything or the TSPU itself. In this case, there will be no electoral locks when Telegram lies, WhatsApp lies, and Viber does not lie. This does not happen.
"Jellyfish"
Photo on the cover: michele ursi / shutterstock.com