AntiMalwareJuly 28, 2026🇷🇺Translated from Russian

One Underscore, 18 Months in Prison: Username Typo Sends Innocent Man to Jail

A single missing underscore in a username request caused an innocent Canadian man to spend 18 months in prison. Brandon Klaym, a resident of Nova Scotia, was arrested, tried, and incarcerated after police confused two nearly identical Kik accounts.

The case began in 2018 in Wisconsin when investigators discovered 125 messages between a 12-year-old girl and an adult man on the messaging app Kik. The real suspect used the handle fus__ro_dah, a reference to the dragon shout from The Elder Scrolls V: Skyrim. When police submitted a legal request to Kik, one underscore was omitted, producing the username fus_ro_dah.

Kik returned subscriber details belonging to Klaym. His IP address pointed investigators to Halifax, Nova Scotia. Local police executed a search warrant, seizing phones and laptops. No chat logs, images, or any other evidence linked to the Wisconsin case were found, and investigators could not confirm that Klaym had even logged into Kik during the relevant timeframe.

Nevertheless, Klaym was charged with internet luring of a child, transmitting explicit material to a minor, and possessing child pornography. In 2023 he was convicted; in 2024 he began serving an 18-month sentence and completed it in full.

The mistake surfaced only during preparation of an appeal. Prosecutors acknowledged that the original Kik request had targeted the wrong account. The correct username pointed to a man named Jay located in California. The Nova Scotia Court of Appeal quashed the conviction, stating that Klaym was factually innocent and should never have been prosecuted.

Related articles

HabrPrivacy & Surveillance

Bypassing Blocks, Privacy, and Anonymity Remain Separate Challenges for Decentralized Networks

The developers of the decentralized circumvention tool Tunnel Cat have clarified that their service addresses only traffic delivery and does not guarantee privacy or anonymity. Transport-layer TLS encryption protects data in transit between nodes but provides no end-to-end protection for conversation content. The team explicitly recommends using separate E2E-encrypted messengers such as Signal or Matrix rather than relying on Telegram. Operational telemetry is retained to comply with legal obligations in multiple jurisdictions and to monitor blocking patterns inside Russia. Because client devices relay traffic for others, the architecture inherently prevents strong anonymity guarantees comparable to Tor. The project deliberately separates the circumvention function from messaging and anonymity tools to avoid overpromising security properties.

SecuritylabPrivacy & Surveillance

How to Detect and Remove Stolen Photos from Fake Profiles, Listings and Ads

Photos are frequently stolen from social networks, old listings, building chats and review sites, then reused in fake profiles, advertisements and rental scams. Russian law under Article 152.1 of the Civil Code protects the right to one's image, while separate copyright rules protect the photographer. Victims are advised to gather strong evidence including full-page screenshots, PDF copies and original files before contacting platforms. Search tools such as Yandex Images, Google Lens and TinEye help locate copies across multiple services. Complaints can be filed directly with site administrators on VKontakte, Odnoklassniki, Avito and Telegram, or escalated to Roskomnadzor and police when personal data or fraud is involved. Preventive steps include lowering image resolution, adding watermarks and restricting album visibility through privacy settings.

HabrPrivacy & Surveillance

Configuration Drift Silently Breaks Multi-Hop Chains in sing-box Reality Fleet

A post-mortem analysis of a censorship circumvention network using sing-box and Reality revealed that four out of seven nodes were unreachable due to outdated allowlists, even though all monitoring reported green status. The fleet consisted of 14 endpoints across seven machines and four providers, with traffic routed in two hops where entry nodes only knew client identities and exit nodes only knew destinations. White-list rules on entry nodes permitted only five addresses instead of all required relays, causing urltest to silently discard most chains without logging failures. Canary checks, external probes, and the relay-lockdown.sh script all passed because none compared the allowlist against the full signed configuration. Two private paid nodes lacked any route section entirely, exposing them to potential abuse. The issue stemmed from configuration drift over time, with no single person maintaining an overview of the entire system. Automated fixes were implemented with safeguards to prevent fleet-wide lockouts.

HabrPrivacy & Surveillance

Why Distributed Mesh Architectures Resist IP Blocking Better Than Centralized Servers

The article explains the fundamental limitations of single-server or small-server setups when facing IP-based censorship and DPI systems. A centralized infrastructure relies on a finite, relatively static list of addresses that can be discovered, tracked, and blocked over time. In contrast, a client-side mesh turns user devices into active transport nodes that relay traffic peer-to-peer, creating a constantly changing set of endpoints. This architectural shift transforms address blocking from a one-time list-maintenance task into an ongoing discovery problem. The design still requires an auxiliary trust and coordination layer called the backbone network, while anti-DPI techniques such as ClientHello rotation and decoy traffic protect individual connections. The approach carries real costs in battery life, bandwidth, and operational complexity on client devices.