Habr•October 6, 2026•🇷🇺Translated from Russian

Building Prizrak: How a Developer Created a Federated Messenger That Masks All Traffic as Legitimate HTTPS

A developer has built Prizrak, a federated messenger that uses end-to-end encryption and makes all traffic, including voice and video calls, appear as ordinary HTTPS connections on the wire.

The project began because existing messengers could not be configured to remove three persistent problems: a central point that can be shut down, mandatory phone number registration, and traffic that remains identifiable even when encrypted. Prizrak uses identifiers in the form name:domain, OpenPGP long-term keys for identity, X3DH and Double Ratchet for forward secrecy, and ChaCha20-Poly1305 for encryption. Federation occurs between independent homeservers that locate each other automatically.

Transport designed to resist DPI

The developer discovered that perfect encryption is useless if the first bytes of a packet reveal the protocol. Standard WebRTC calls expose the STUN magic cookie 0x2112A442 and DTLS record type 22. The solution was to stop imitating HTTPS and instead become it: clients perform genuine TLS 1.3 handshakes to real domains and present a hidden token only after the channel is encrypted. Servers listen on multiple stable ports including 443, 8801, 993 and others, silently ignoring occupied ones. Clients start at port 443 and discover a working port automatically.

Key management and multi-device support

Long-term OpenPGP keys serve as identity passports verified via QR code and sign ephemeral X25519 prekeys. Each device receives its own identity key signed by the account root. Messages are encrypted separately for every device of the recipient. Revoking a device simply stops delivering envelopes to it. The design accepts O(participants × devices) encryption cost and plans to adopt MLS (RFC 9420) for very large groups.

Resilient delivery through storage nodes

When homeservers cannot reach each other directly, messages travel through a network of storage nodes. Each node stores opaque blobs addressed by HKDF-derived identifiers. The system replicates data across four nodes using a placement model taken from Ceph RADOS, including rendezvous hashing, Merkle reconciliation, and anti-entropy. Delivery acknowledgments are the only source of truth; nodes delete blobs only after receiving a signed ACK.

Native media stack and careful buffer sizing

Calls use a fully native media stack on Android with Camera2, MediaCodec, AudioRecord and Opus. A custom address-mapping service replaces public STUN to avoid detectable signatures. After switching to direct P2P paths, video frames were being truncated because the receive buffer was only 2048 bytes. Raising the buffer to 65536 bytes, adding proper fragmentation, and implementing PLI-based recovery eliminated artifacts. Bitrate is now controlled by queue length rather than observed loss.

Ringback tones and call-state machine

Users complained that calls lacked ringback tones. The developer added a full state machine that reports presence after an offer is sent, distinguishes “subscriber unavailable,” “busy,” and “no answer” conditions, and plays 425 Hz tones with familiar cadences. The same work exposed several signaling bugs that had previously gone unnoticed.

Built-in two-hop VPN

The stealth transport is reused for a two-hop VPN. The first hop sees the user’s IP but not the destination; the exit hop sees the destination but not the user. Messenger traffic is excluded from the tunnel to avoid loops. Node selection uses Bayesian reputation with 60-day freshness and make-before-break switching.

Related articles

Habr•Privacy & Surveillance

GrapheneOS Setup Guide: Configuring Pixel Phones for Corporate Surveillance-Free Daily Use

This comprehensive engineering guide explains how to deploy GrapheneOS on supported Google Pixel devices to eliminate corporate telemetry collection. It follows three core principles: rejecting proprietary ecosystems, applying Zero Trust through cryptography and open-source audits, and enforcing strict compartmentalization via isolated user profiles. The tutorial covers official installation via the Web Installer, basic owner profile hardening with PIN shuffling and automatic reboot, and the use of Obtainium for direct FOSS app management from GitHub repositories. Detailed recommendations include privacy-focused tools such as KeePassDX, Aegis Authenticator, AmneziaVPN, Signal, and Fossify applications, along with VPN kill-switch configuration. Regional profiles are created for sandboxed Google Play, Aurora Store, RuStore, and Huawei AppGallery to safely run banking, marketplace, and social apps without cross-profile tracking.

Habr•Privacy & Surveillance

Following the White Rabbit: Developer Builds Custom Rust VPN PAYPHONE Using QUIC and Obfuscation to Evade Detection

A Russian developer has released PAYPHONE, an experimental IPv4 VPN written entirely in Rust that uses QUIC datagrams and optional TLS-over-TCP transport with custom obfuscation. The project aims to provide an alternative to AmneziaWG and Xray/VLESS+REALITY stacks that are commonly used to bypass Russian internet filtering. The article details the full packet path from TUN interface through a 16-byte PAYPHONE header, session management with Ed25519 tokens, and multiple post-launch bugs including MTU miscalculations, self-routing loops on macOS, and timer lifetime issues in Tokio. Key technical choices include RFC 9221 datagram support to avoid head-of-line blocking for multiplexed TCP flows and token-bucket rate limiting tied to subscription tokens. The author also describes route monitoring every 400 ms and interface-bound sockets to prevent the tunnel from swallowing its own control traffic.

AntiMalware•Privacy & Surveillance

WhatsApp Introduces Parental Controls for Teen Privacy Settings

WhatsApp, owned by Meta (recognized as an extremist organization and banned in Russia), has rolled out new parental control tools for family accounts. Parents can manage privacy settings, group participation, channel access, status visibility, and Meta AI usage for teens, but cannot read personal messages due to end-to-end encryption. All controls are voluntary and require joint setup with the teenager, protected by a single PIN code that prevents easy reversal of restrictions. Notifications alert parents when teens join or leave groups or when group sizes change significantly. Separate options cover channel usage, viewable statuses, and audience controls for teen posts. Meta AI access can be set to a standard 13+ mode or a stricter Limited Content mode with undisclosed restrictions. The company plans to expand these features gradually based on family feedback while maintaining encryption protections.

Securitylab•Privacy & Surveillance

Can Wi-Fi Owners See Your Google Search History? HTTPS, DNS, SNI and ECH Explained

A viral social media video sparked widespread concern that Wi-Fi owners could view users' search history and visited sites simply by knowing the router password. Security experts from Cybernews and Surfshark clarified that modern HTTPS encryption prevents reading of actual search queries or page content. However, metadata such as DNS requests, SNI fields in TLS handshakes, and device MAC addresses remain visible to the network administrator. The introduction of Encrypted Client Hello (ECH) under RFC 9849 aims to hide domain names, yet Russian authorities have blocked many ECH-enabled connections since November 2024. Corporate or school-managed devices with installed root certificates represent the main real-world exception where full traffic inspection is possible. VPNs hide destinations from the local router but transfer visibility to the VPN provider. The article emphasizes that password-protected Wi-Fi grants access only to connection metadata, not browser history.