Following the White Rabbit: Developer Builds Custom Rust VPN PAYPHONE Using QUIC and Obfuscation to Evade Detection
A developer has published a detailed technical account of building PAYPHONE, a custom IPv4 VPN written in Rust that uses QUIC as the primary transport and an optional TLS-over-TCP fallback. The project was created to give the author full control over packet handling, routing, and traffic shaping while exploring techniques that might resist the detection methods used against standard WireGuard in Russia.
Applications on the client send packets to a TUN interface. The client reads these packets, prepends a 16-byte PAYPHONE header containing version, type, flags, length, and sequence number, then transmits them over QUIC datagrams or an obfuscated TLS stream. On the server the header is stripped and the original IP packet is written to the server-side TUN, after which Linux routing and NAT forward it to the internet. Return traffic follows the reverse path.
The protocol deliberately uses QUIC datagrams rather than a single ordered stream so that loss of one packet does not stall unrelated TCP connections inside the tunnel, following the approach described in RFC 9221. The implementation relies on the Quinn library; an early mistake with send_datagram_wait was corrected by switching to non-blocking send_datagram calls and pre-checking datagram size.
Authentication uses short-lived Ed25519-signed tokens that encode subscription limits. The server re-validates tokens on every session event and maintains a list of revoked identifiers. Rate limiting is performed with a token-bucket algorithm tied to the subscription record.
Several practical problems surfaced after the first working connection. An initial MTU of 1280 exceeded Quinn’s available datagram budget once the 40-byte PAYPHONE header and QUIC overhead were added, producing TooLarge errors under load. The value was reduced to 1100 with dynamic adjustment based on the path’s max_datagram_size. On macOS, the /32 route to the server was occasionally removed by networksetup calls, causing the tunnel to route its own QUIC packets back into the TUN; the final solution combined a persistent /32 route with IP_BOUND_IF socket binding.
Tokio timer handling also required correction. Creating a fresh sleep inside each select! iteration prevented PING and route-check timers from ever firing. The timers are now created once before the loop and reset after each expiration. The client additionally polls routes every 400 ms to restore them after network configuration changes.
Obfuscation that rounded QUIC packet lengths to fixed sizes (128, 296, 568, 1200, 1440) was later removed because it distorted QUIC’s path-MTU discovery probes. Only random padding between 0 and 32 bytes is now applied after XOR masking.
Related articles
WhatsApp Introduces Parental Controls for Teen Privacy Settings
WhatsApp, owned by Meta (recognized as an extremist organization and banned in Russia), has rolled out new parental control tools for family accounts. Parents can manage privacy settings, group participation, channel access, status visibility, and Meta AI usage for teens, but cannot read personal messages due to end-to-end encryption. All controls are voluntary and require joint setup with the teenager, protected by a single PIN code that prevents easy reversal of restrictions. Notifications alert parents when teens join or leave groups or when group sizes change significantly. Separate options cover channel usage, viewable statuses, and audience controls for teen posts. Meta AI access can be set to a standard 13+ mode or a stricter Limited Content mode with undisclosed restrictions. The company plans to expand these features gradually based on family feedback while maintaining encryption protections.
Can Wi-Fi Owners See Your Google Search History? HTTPS, DNS, SNI and ECH Explained
A viral social media video sparked widespread concern that Wi-Fi owners could view users' search history and visited sites simply by knowing the router password. Security experts from Cybernews and Surfshark clarified that modern HTTPS encryption prevents reading of actual search queries or page content. However, metadata such as DNS requests, SNI fields in TLS handshakes, and device MAC addresses remain visible to the network administrator. The introduction of Encrypted Client Hello (ECH) under RFC 9849 aims to hide domain names, yet Russian authorities have blocked many ECH-enabled connections since November 2024. Corporate or school-managed devices with installed root certificates represent the main real-world exception where full traffic inspection is possible. VPNs hide destinations from the local router but transfer visibility to the VPN provider. The article emphasizes that password-protected Wi-Fi grants access only to connection metadata, not browser history.
Yandex Deploys OPRF Protocol to Protect Phone Numbers in Mandatory Audience Measurement Data Sharing
Yandex has detailed a cryptographic scheme using Oblivious Pseudorandom Function (OPRF) to help Russian audiovisual services comply with new legislation requiring transmission of user identifiers linked to phone numbers. The approach replaces a naive shared-secret hashing method that created a single point of compromise across dozens of competing companies. Instead, two independent third parties each hold separate secret keys and process blinded elliptic-curve points derived from normalized E.164 phone numbers. Services obtain deterministic identifiers without learning the third-party keys and without exposing raw numbers to the authorized research organization. The design distributes trust, limits offline brute-force attacks to scenarios requiring both keys plus final identifiers, and adds rate limits plus key-rotation capabilities to deter abuse. Yandex positions the solution as a practical compromise between regulatory demands, competitive secrecy, and user privacy.
CookieTin Extension Manages Partitioned Cookies Across Firefox, Chrome and Edge
Developer Perruer2 has released CookieTin, an open-source browser extension that fully supports partitioned cookies under Firefox Total Cookie Protection and Chrome CHIPS. The tool addresses limitations in older managers like Cookie Quick Manager by correctly retrieving and deleting cookies stored with partitionKey values. It works across Firefox, Chrome and Edge using a single Manifest V3 codebase written in TypeScript and Preact. Key features include accurate cookies.txt export compatible with curl and yt-dlp, protected cookies that survive explicit deletion, and pre-save validation of browser rules for __Host- prefixes and SameSite attributes. E2E tests using Puppeteer verify handling of HttpOnly, partitioned and container cookies in all three browsers.