securitylab_n•July 13, 2026•🇷🇺Translated from Russian

Tired of Instant Messaging, Users Flock to Virtual Pigeons: Roost App Revives Postal Delivery with Birds and Animals

Users press the send button, yet the recipient receives nothing for seconds or even minutes. Instead, a virtual bird appears on screen, picks up the letter, and flies across a real-world map toward the addressee. The journey can last several hours or even days. This built-in delay is not a server error but the central feature of the Roost messenger, which has rapidly gained popularity across social networks.

Before sending a message, Roost lets users choose their courier. A falcon travels faster than a hummingbird, while more relaxed users can entrust their letter to a snail or a turtle. The base speed is tied to the real capabilities of the chosen animal, so delivery time depends on both the courier and the distance between correspondents. The route is shown on a map, and the application provides an estimated arrival time in advance.

Birds can be trained in mini-games to gradually increase their speed, and every flight grants experience points. There is no hard speed cap, allowing a favorite pigeon to eventually outpace other creatures in a user’s virtual aviary. The app features more than one thousand birds and animals that users can collect, upgrade, name, and describe.

Core Features and Social Mechanics

Roost blends messaging, social networking, and a collection game. There is no traditional news feed or endless scrolling. Users add friends by name, create group chats called “nests,” and exchange messages with anonymous correspondents via the Pen Pals function. Each nest holds up to 11 participants, and a separate bird must fly to every member. According to GamesBeat, shortly after launch the app saw more than 100,000 active conversations daily.

Creator Background and Explosive Growth

Roost was developed by Logan Mendelson, who works as a product manager for trust and safety at Ticketmaster. The project began as a small experiment for friends. Mendelson first shared the concept on TikTok, and the public version launched at the end of April. The developer had not planned to turn the pigeon-themed diversion into a large social platform.

The real surge began after a post by Karen Lewis on Threads (owned by Meta Platforms Inc.). She described how her daughter and friends communicate in Roost using English from the time of Elizabeth I, with friends replying in the same style. The post received approximately 147,000 views and turned the little-known app into a viral phenomenon.

Within three days the user base grew from 10,000 to 100,000. After roughly five weeks the number approached 300,000 and then surpassed that figure. The creator states that in less than two months Roost attracted more than 300,000 users. A friend of the developer also reported that birds now deliver over one million messages per week and have collectively flown more than one billion virtual miles.

Monetization and Technical Controversies

Mendelson spent nothing on advertising. Users organically shared videos, screenshots, and invitations. The developer has not yet raised external funding and plans to sustain the service through in-app purchases. Core functions remain free, while the app sells rare birds, a subscription with extra features, and lifetime founder-club status.

The first controversy has already emerged: Mendelson used AI-generated bird images, prompting criticism from parts of the community. He acknowledged the concerns and launched a contest for artists to replace the generated illustrations with original artwork. During development he also used Claude Code and believes that without AI assistance it would have been extremely difficult for one person to maintain a service of this scale.

Privacy and Data Handling Concerns

Beneath the charming surface lie significant privacy limitations. Roost requests precise coordinates because geolocation is required to calculate routes and flight times. Users can choose to show friends their exact location, only the city, or hide the endpoint entirely. However, flight direction can still reveal the approximate district of both sender and recipient.

Conversations are not protected by end-to-end encryption. The privacy policy explicitly states that messages are stored in plaintext and remain accessible to server systems. Data transmission is protected by TLS and server storage uses Google Cloud encryption, yet employees and automated systems can technically read message content. Texts from messages, profiles, and anonymous letters are also sent to OpenAI for automated moderation, although the developer claims that names, emails, and account identifiers are not transmitted alongside the text.

Registration requires an Apple or Google account, a phone number, date of birth, and location permission. Current rules allow Roost only for users over 18, an interesting restriction given that many publications portray the service as a new teenage trend.

Availability and Philosophy

Roost is available on iPhone and Android. The iOS version requires iOS 18 or newer, supports only English, and is distributed free with in-app purchases. On Google Play the app has already exceeded 100,000 installations.

The creator describes Roost as a “slow social network.” While conventional messengers compete on instant delivery and capture attention with notifications, Roost sells the experience of waiting. The recipient is not ignoring the message, causing anxiety, or showing a “read” status. The pigeon simply has not arrived yet.

Related articles

Habr•Other

How the Lorenz SZ 42 Teleprinter Cipher Machine Worked: Nazi High Command Encryption and Its 1941 Breakthrough

The Lorenz SZ 42 was a teleprinter attachment used by the German high command for encrypting top-secret communications during World War II, operating on the Vernam cipher principle with twelve wheels generating a keystream. Unlike the portable Enigma, Lorenz integrated directly between teletypes for automatic five-bit ITA2 encryption. British interceptors at Knockholt first encountered its signals in 1940, later named Tunny. A critical operator error on 30 August 1941 allowed cryptanalysts at Bletchley Park to deduce the machine's structure. This led to the development of the Colossus computer in 1944 for automated decryption. The article details the χ, ψ, and μ wheel groups, the stuttering psi mechanism, and Python implementations of ITA2 encoding and XOR operations.

Securitylab•Other

Inside the Fortress: Why Perimeter Security Tools Fall Short and How Microsegmentation Protects Networks Internally

Companies invest heavily in perimeter defenses such as firewalls and intrusion detection systems, yet these measures no longer guarantee safety as attackers increasingly operate from within networks. Traditional L2 domains leave virtual machines unisolated, enabling traffic interception, lateral movement, and malware spread similar to an apartment building with poor soundproofing. Microsegmentation powered by SDN divides VLANs into isolated microsegments down to individual VM ports, enforcing granular policies based on ports, IP addresses, and protocols. This approach implements Zero Trust by placing virtual packet filters directly at VM network interfaces on the hypervisor, independent of guest OS actions. Performance remains high because filtering runs on powerful virtualization servers, and scaling occurs naturally as additional hypervisors absorb new workloads without extra configuration. A real-world case from the oil and gas sector shows one customer creating up to 5,000 new microsegmentation rules per week via open REST API. The technology complements rather than replaces perimeter firewalls, delivering both strict internal controls and operational agility.

Habr•Other

Good Bear 1.0 Released: Firefox-Based Browser with Isolated Russian PKI Trust Container

Good Bear 1.0 is a Russian-language browser built on Firefox 156.0 that provides an isolated container for handling Russian PKI certificates without mixing trust contexts or user data with the standard browsing session. The release includes .deb packages for Ubuntu 24.04 LTS amd64 and Windows x64 installers, using Mozilla Public License 2.0 and reproducible build processes from pinned Firefox sources. Instead of globally importing root certificates, the browser performs secondary chain validation only inside a dedicated userContextId container with strict OriginAttributes isolation for caches, storage, and connections. Password autofill and sensitive session data are disabled in the container when separation cannot be guaranteed, and POST requests trigger explicit user choice before reopening in the isolated context. The interface shows both a persistent container marker and a separate RU indicator only when Russian PKI is actively used, along with detailed security panels explaining the trust source. Updates, crash reporting, and automatic MAR mechanisms are intentionally omitted to avoid creating unverified trust chains for the distribution itself.

Habr•Other

Survey of 254 Russian Domains Shows 89% DMARC Adoption but Highlights Gaps in Reporting and Subdomain Policies

A manual review of public DNS records across 254 prominent Russian domains from 17 sectors found strong baseline adoption of email authentication mechanisms. MX records appeared in 96.1% of domains, SPF in 93.7%, DMARC in 89.0%, and DKIM records via common selectors in 62.2%. Among domains with DMARC, 40.7% published a reject policy and 42.9% used quarantine, while 16.4% remained at none. Notably, 19% of DMARC-enabled domains lacked any rua address for aggregate reports, including 33 domains enforcing reject or quarantine. The study also identified cases of inconsistent policies between parent domains and subdomains, as well as SPF records ending in ~all paired with strict DMARC settings. Researchers emphasized that DNS data alone cannot confirm actual mail flow alignment or report consumption.