Habr•September 28, 2026•🇷🇺Translated from Russian

Klark and Klara Launch Self-Hosted Corporate Messenger and Task Manager for On-Premise Data Control

Klark and Klara represent a paired self-hosted solution that combines corporate messaging with task management while ensuring all data remains on company servers.

The project originated from common enterprise pain points: work discussions scattered across personal Telegram groups, tasks lost in chat history, and departing employees taking files and context with them. The developers aimed for three core capabilities: internal-only storage of messages and files, one-click task creation from conversations, and single-command deployment without external cloud dependencies or subscriptions.

Klark offers familiar messaging features including private chats, groups, channels, and self-notes. Supergroups support forum-style topics, threaded replies, and read receipts showing exactly who viewed each message. Voice messages can be recorded with simple gestures and transcribed locally using an on-premise speech model. All attachments undergo scanning by ClamAV before delivery. Audio and video calls, screen sharing, and conferences run through the LiveKit media server installed on the customer’s infrastructure.

A dedicated “Today” panel displays unread messages, scheduled meetings, and tasks pulled from Klara without leaving the chat interface. One-time secret links allow secure sharing of passwords or keys that expire after a single view. Bot API support enables automated alerts from monitoring systems and CI pipelines.

Klara provides project and product tracking with a strict workflow of “Not started → In progress → Review → Completed.” Weekly sprints close automatically, carrying unfinished items forward with clear change history. The built-in wiki supports version control, approval workflows, scheduled publishing, and live embedding of task cards. Both products share an LDAP connector for Active Directory, OpenLDAP, and FreeIPA authentication while enforcing TOTP two-factor authentication and detailed audit logging.

Deployment uses a single Docker Compose script that generates secrets, obtains certificates, and starts all services. Updates require only a git pull and rebuild, leaving data volumes untouched. The stack relies on standard components: PostgreSQL 16, Redis, FastAPI, React, Capacitor, and Electron to ensure maintainability by ordinary system administrators.

Related articles

AntiMalware•Other

Russia's Taxi Market Overrun by Illegal Drivers Using Fake Accounts and Gray Intermediaries

Russian taxi aggregators are increasingly relying on complex chains of intermediaries that allow drivers without proper licenses, experience, or even Russian permits to operate. These gray schemes involve dispatch services, car fleets, individual entrepreneurs, and so-called podklyuchashki that sell ready-made accounts for 3-7 thousand rubles after minimal verification. A high-profile incident in Odintsovo exposed how a driver refusing service to a disabled veteran of the special military operation was later deported, revealing a corporate maze where the vehicle, the connecting IP, and the driver had no direct link to the aggregator. Official data shows over 900,000 vehicles registered in the FGIS Taxi system, yet more than 1.5 million drivers may be operating outside legal requirements. With Russians taking around 10 million taxi trips daily, the lack of accountability has contributed to over 3,100 accidents involving taxis in 2025, resulting in 143 deaths and more than 3,800 injuries. Courts remain inconsistent in assigning liability across aggregators, fleets, and individual drivers. Experts are calling for aggregators to be designated as carriers with mandatory checks and joint liability.

AntiMalware•Other

Russians Offered Unofficial 5G Activation on iPhone for 399 Rubles with No Guarantees

A Russian service called 5G First is selling a tool that removes Apple's 5G restrictions on iPhones for 399 rubles without requiring a jailbreak. The method works by modifying carrier profile settings that control which network features are permitted for a given SIM card. A free alternative named CarrierSIM achieves the same result by forcing the device to adopt the Vodafone Hungary carrier profile where 5G is already enabled. Both solutions are described as experimental, depend on specific iOS versions, operators and SIM cards, and offer no assurance they will survive future system updates. The Ministry of Digital Development is already in discussions with Apple about enabling 5G officially on Russian iPhones. Successful activation of the 5G menu option does not create network coverage where Russian operators have not yet deployed it.

Habr•Other

CryptoLab: Interactive Educational Platform Turns Cryptographic Protocols Course into Hands-On Alice, Bob and Mallory Experiments

A university instructor developed CryptoLab, an educational testbed that lets students run live cryptographic protocol experiments with active attackers instead of simple encrypt-decrypt exercises. The platform models the classic Alice-Mallory-Bob scenario where each participant runs as a separate application mode, allowing inspection, modification, dropping, and replay of packets. The first lab focuses on AES-GCM, AEAD properties, nonce reuse, replay protection, weak RNGs, key rotation, and metadata leakage. Students can operate in interactive mode to manually attack traffic or execute automated scenarios that verify expected security outcomes. Experiments demonstrate that modifying ciphertext triggers authentication failure and that a valid authentication tag does not guarantee message freshness without additional replay defenses. The tool also includes Python 3.10 assignments for correctly using cryptographic primitives rather than implementing algorithms from scratch. CryptoLab currently supports Windows x64 and macOS Apple Silicon builds and serves as the foundation for upcoming labs on symmetric encryption modes, asymmetric cryptography, key exchange, and TLS.

Habr•Other

From Scanner Overload to Manual Insight: A Bug Bounty Hunter's Journey

A young researcher recounts his transition from automated scanning to thoughtful manual analysis in Bug Bounty programs. After completing a broad information security course covering cryptography, networks, Docker, databases, and OWASP Top 10, he initially approached real-world targets with the same scanner-heavy mindset used in labs. Months of fruitless results led to burnout and a six-month break working in construction. Returning with a new focus, he studied hundreds of public HackerOne reports to understand researcher reasoning and anomaly detection. This shift enabled his first valid, unreported finding and fundamentally changed his methodology. Today the 18-year-old university student balances Bug Bounty with reconnaissance, machine learning, and personal projects while emphasizing deep application understanding over tool volume.