Amnezia VPN Survives Coordinated Russian Censorship Campaign Targeting AmneziaWG Protocol Fingerprints
Amnezia VPN has released a comprehensive account of the intense blocking campaign Russian authorities waged against its services this summer, detailing how the company restored stable operation of Amnezia Free and Amnezia Premium after repeated waves of sophisticated censorship.
Attack Overview
The campaign was not a conventional protocol block but a coordinated infrastructure attack. Operators observed targeted reconnaissance of the API, service behavior, and infrastructure logic, accompanied by DDoS attempts and direct attacks on the API. While the API itself resisted compromise thanks to prior audits, individual components were successfully flooded. The company also faced DDoS against its website; because it uses Amazon CloudFront, the 100k–500k RPS peaks were mitigated through rapid rate-limit activation by Amazon.
Roskomnadzor changed its blocking strategy. Instead of blocking protocols outright, censors now fingerprint traffic patterns, map servers receiving matching traffic, and automatically blacklist addresses and entire subnets. Blocks are rolled out sequentially rather than simultaneously, allowing the service to recover from one wave before the next set of rules is deployed.
Technical Mitigations Implemented
Amnezia closed several protocol fingerprints: zero-length UDP packets in certain clients, fixed-size keepalive packets, handshake timing artifacts, nonce zero bytes, and related infrastructure detection vectors. After multiple client updates, mass blocking of newly deployed servers largely ceased. Connections from outdated Amnezia Premium clients are now disabled. Self-hosted AmneziaWG installations were mostly unaffected by protocol-level rules, though some users still encountered subnet blocks.
Timeline of the Incident
The first wave began on the night of 20 May with numerous servers blocked alongside DDoS and apparent replay or scanning activity against AmneziaWG. Subsequent waves on 1 June, 7 July, 10 July, and 25 July combined IP blacklisting, subnet monitoring, API scanning, phishing attempts against staff, and automated detection of fresh servers within hours of deployment. The active phase lasted roughly six weeks.
Engineers discovered that AmneziaWG 1.0 and 1.5 versions were identifiable by fixed packet sequences following a predictable initial handshake. This prompted an accelerated rollout of AmneziaWG 2.0, which dropped support for Windows 7, Android 8, and certain router configurations. Additional fixes addressed keepalive packets and zero-length UDP packets on specific platforms.
Future Defenses and Infrastructure Changes
Work on AmneziaWG 3.0 is underway to eliminate remaining structural features such as packet-size sequences, inter-packet timing, post-handshake behavior, and repeatable combinations that allow cumulative scoring. The company is also doubling server capacity for its VLESS infrastructure to provide resilient fallback connectivity that survives both protocol and IP-based blocking.
Related articles
Can Wi-Fi Owners See Your Google Search History? HTTPS, DNS, SNI and ECH Explained
A viral social media video sparked widespread concern that Wi-Fi owners could view users' search history and visited sites simply by knowing the router password. Security experts from Cybernews and Surfshark clarified that modern HTTPS encryption prevents reading of actual search queries or page content. However, metadata such as DNS requests, SNI fields in TLS handshakes, and device MAC addresses remain visible to the network administrator. The introduction of Encrypted Client Hello (ECH) under RFC 9849 aims to hide domain names, yet Russian authorities have blocked many ECH-enabled connections since November 2024. Corporate or school-managed devices with installed root certificates represent the main real-world exception where full traffic inspection is possible. VPNs hide destinations from the local router but transfer visibility to the VPN provider. The article emphasizes that password-protected Wi-Fi grants access only to connection metadata, not browser history.
Yandex Deploys OPRF Protocol to Protect Phone Numbers in Mandatory Audience Measurement Data Sharing
Yandex has detailed a cryptographic scheme using Oblivious Pseudorandom Function (OPRF) to help Russian audiovisual services comply with new legislation requiring transmission of user identifiers linked to phone numbers. The approach replaces a naive shared-secret hashing method that created a single point of compromise across dozens of competing companies. Instead, two independent third parties each hold separate secret keys and process blinded elliptic-curve points derived from normalized E.164 phone numbers. Services obtain deterministic identifiers without learning the third-party keys and without exposing raw numbers to the authorized research organization. The design distributes trust, limits offline brute-force attacks to scenarios requiring both keys plus final identifiers, and adds rate limits plus key-rotation capabilities to deter abuse. Yandex positions the solution as a practical compromise between regulatory demands, competitive secrecy, and user privacy.
CookieTin Extension Manages Partitioned Cookies Across Firefox, Chrome and Edge
Developer Perruer2 has released CookieTin, an open-source browser extension that fully supports partitioned cookies under Firefox Total Cookie Protection and Chrome CHIPS. The tool addresses limitations in older managers like Cookie Quick Manager by correctly retrieving and deleting cookies stored with partitionKey values. It works across Firefox, Chrome and Edge using a single Manifest V3 codebase written in TypeScript and Preact. Key features include accurate cookies.txt export compatible with curl and yt-dlp, protected cookies that survive explicit deletion, and pre-save validation of browser rules for __Host- prefixes and SameSite attributes. E2E tests using Puppeteer verify handling of HttpOnly, partitioned and container cookies in all three browsers.
Kaspersky Premium for macOS Gains App Uninstall Feature to Remove Residual Files
Kaspersky Premium now includes an App Uninstall tool for macOS that locates and deletes leftover files such as caches, cookies, settings, and logs after applications are removed. The feature also identifies duplicate copies of programs and lets users remove all instances or select specific ones while preserving shared components used by other software. Survey data from Kaspersky shows that only 44 percent of macOS users delete unused applications, even though 56 percent regularly clear browser data and 54 percent remove unwanted media files. Residual files can contain sensitive information including account tokens, passwords, IP addresses, event logs, and personal documents, creating privacy risks especially when a device is sold or accessed by unauthorized parties. Deleted files can be restored from the trash or directly within Kaspersky Premium before the application session ends. The company also warns that malicious programs are frequently disguised as legitimate macOS cleaning utilities.