Habr•September 30, 2026•🇷🇺Translated from Russian

Yandex Deploys OPRF Protocol to Protect Phone Numbers in Mandatory Audience Measurement Data Sharing

Yandex has published a detailed technical account of how Russian audiovisual services are meeting new legal requirements to share user identifiers derived from phone numbers while avoiding a single point of compromise.

Regulatory Background

Under recent legislation, 23 registered audiovisual platforms must transmit an additional user identifier to an authorized research organization. The identifier must be consistent across services for the same normalized phone number so that the same individual can be counted once regardless of device or platform.

Why Simple Hashing Failed

An initial proposal relied on a shared secret key combined with Argon2 or HMAC-SHA256 over normalized numbers. While functionally correct, any leakage of the common key would allow an attacker to reverse all identifiers from every participating service. Yandex assessed this risk as unacceptable given the number of independent companies involved.

OPRF Construction

The chosen solution is based on Oblivious Pseudorandom Function as specified in RFC 9497. Each phone number is first normalized to E.164 format, mapped to an elliptic-curve point via hash-to-curve, and blinded with a fresh random scalar. Two independent third parties, each holding its own secret scalar, successively multiply the blinded point. After unblinding and final hashing, the service obtains a stable identifier without ever learning either secret key.

Operational Properties

  • Raw phone numbers never leave the originating service or reach the research organization.
  • Compromise of one third party is insufficient for offline dictionary attacks.
  • Rate limits and request-volume monitoring deter malicious clients from building full lookup tables.
  • Key rotation remains possible without changing identifiers already issued.

The final architecture requires each audiovisual service to interact with exactly two third-party OPRF endpoints before sending the resulting identifier to the research organization.

Related articles

Securitylab•Privacy & Surveillance

Can Wi-Fi Owners See Your Google Search History? HTTPS, DNS, SNI and ECH Explained

A viral social media video sparked widespread concern that Wi-Fi owners could view users' search history and visited sites simply by knowing the router password. Security experts from Cybernews and Surfshark clarified that modern HTTPS encryption prevents reading of actual search queries or page content. However, metadata such as DNS requests, SNI fields in TLS handshakes, and device MAC addresses remain visible to the network administrator. The introduction of Encrypted Client Hello (ECH) under RFC 9849 aims to hide domain names, yet Russian authorities have blocked many ECH-enabled connections since November 2024. Corporate or school-managed devices with installed root certificates represent the main real-world exception where full traffic inspection is possible. VPNs hide destinations from the local router but transfer visibility to the VPN provider. The article emphasizes that password-protected Wi-Fi grants access only to connection metadata, not browser history.

Habr•Privacy & Surveillance

CookieTin Extension Manages Partitioned Cookies Across Firefox, Chrome and Edge

Developer Perruer2 has released CookieTin, an open-source browser extension that fully supports partitioned cookies under Firefox Total Cookie Protection and Chrome CHIPS. The tool addresses limitations in older managers like Cookie Quick Manager by correctly retrieving and deleting cookies stored with partitionKey values. It works across Firefox, Chrome and Edge using a single Manifest V3 codebase written in TypeScript and Preact. Key features include accurate cookies.txt export compatible with curl and yt-dlp, protected cookies that survive explicit deletion, and pre-save validation of browser rules for __Host- prefixes and SameSite attributes. E2E tests using Puppeteer verify handling of HttpOnly, partitioned and container cookies in all three browsers.

AntiMalware•Privacy & Surveillance

Kaspersky Premium for macOS Gains App Uninstall Feature to Remove Residual Files

Kaspersky Premium now includes an App Uninstall tool for macOS that locates and deletes leftover files such as caches, cookies, settings, and logs after applications are removed. The feature also identifies duplicate copies of programs and lets users remove all instances or select specific ones while preserving shared components used by other software. Survey data from Kaspersky shows that only 44 percent of macOS users delete unused applications, even though 56 percent regularly clear browser data and 54 percent remove unwanted media files. Residual files can contain sensitive information including account tokens, passwords, IP addresses, event logs, and personal documents, creating privacy risks especially when a device is sold or accessed by unauthorized parties. Deleted files can be restored from the trash or directly within Kaspersky Premium before the application session ends. The company also warns that malicious programs are frequently disguised as legitimate macOS cleaning utilities.

Securitylab•Privacy & Surveillance

Bypassing VPN Detection on iPhone: Detailed Methods to Avoid App Blocks

Many iPhone users encounter apps that detect and block active VPN connections even after switching servers or protocols. The detection often occurs locally on the device by inspecting network interfaces rather than relying solely on external IP addresses. This guide explains how apps identify VPN tunnels through iOS network data and provides practical workarounds including moving the VPN to a router, configuring per-app exclusions, and using web versions of services. It also covers why protocol obfuscation and port changes fail to hide local VPN activity from applications. Additional troubleshooting addresses automatic VPN profiles, ad blockers, and iCloud Private Relay interference. The article emphasizes that no universal toggle exists in iOS to hide an active VPN from all apps.