Habr•July 30, 2026•🇷🇺Translated from Russian

Six Bitrix24 Disk Migration Errors That Force Portal Redesign After Six Months

Bitrix24 Disk migration projects often appear complete after a weekend file transfer, yet six months later companies face missing contracts, unauthorized access to salary folders, and severe performance degradation. The root cause is rarely a failed copy operation; instead, the original network share structure is replicated unchanged into a platform whose storage model relies on three distinct container types: My Disk, group and project disks, and the company-wide common disk.

Ошибка 1 — copying the folder tree verbatim — produces 30–40 top-level folders with names such as “Miscellaneous 2” and eight levels of nesting. Because Bitrix24 search is under-used, employees cannot locate documents efficiently. The recommended approach is to map every top-level folder to an owner, a readership group, and a business process before any files are moved.

Ошибка 2 occurs when My Disk becomes the de-facto working repository. When an employee leaves, signed contracts disappear; when the employee is on vacation, colleagues cannot retrieve needed files. The fix is a written policy that restricts My Disk to personal drafts only, enforced by periodic REST inventory scripts that flag personal storages containing more than three top-level folders.

Ошибка 3 — granting rights to individual users rather than departments — results in access matrices containing dozens of personal entries that quickly become stale. After one reorganization the list is unreadable and auditing is impossible. Rights should be assigned via department codes (DR5) or workgroups so that personnel changes are handled automatically.

Ошибка 4 places every ambiguous document into the common disk with full access for all authenticated users. The Toyota T-Connect, G-Link and G-BOOK breach affecting 2.15 million customers between 2013 and 2023 shows how a single misconfigured open bucket can remain unnoticed for ten years. The correct default is read-only access on the common disk, with write rights granted only to specific sections and no “Miscellaneous” folder allowed.

Ошибка 5 attaches file copies to tasks and CRM records instead of links. Version history is lost, storage quotas are wasted, and the latest approved document is never visible in the deal card. The rule is simple: the authoritative copy lives on Disk; every other entity receives a link.

Ошибка 6 enables desktop synchronization for the entire tree. Offline editing on multiple machines produces conflicting copies that nobody resolves. Only folders actively edited offline should be synchronized; the rest should be accessed via mapped network drives or the online editor.

Successful teams now follow four practices: a thorough pre-migration inventory that discards 40–60 % of untouched files, a two-week pilot on a single department, named owners for every top-level section, and mandatory quarterly rights reviews. These steps convert a one-time migration into a sustainable information-security process.

Related articles

Habr•Privacy & Surveillance

CookieTin Extension Manages Partitioned Cookies Across Firefox, Chrome and Edge

Developer Perruer2 has released CookieTin, an open-source browser extension that fully supports partitioned cookies under Firefox Total Cookie Protection and Chrome CHIPS. The tool addresses limitations in older managers like Cookie Quick Manager by correctly retrieving and deleting cookies stored with partitionKey values. It works across Firefox, Chrome and Edge using a single Manifest V3 codebase written in TypeScript and Preact. Key features include accurate cookies.txt export compatible with curl and yt-dlp, protected cookies that survive explicit deletion, and pre-save validation of browser rules for __Host- prefixes and SameSite attributes. E2E tests using Puppeteer verify handling of HttpOnly, partitioned and container cookies in all three browsers.

AntiMalware•Privacy & Surveillance

Kaspersky Premium for macOS Gains App Uninstall Feature to Remove Residual Files

Kaspersky Premium now includes an App Uninstall tool for macOS that locates and deletes leftover files such as caches, cookies, settings, and logs after applications are removed. The feature also identifies duplicate copies of programs and lets users remove all instances or select specific ones while preserving shared components used by other software. Survey data from Kaspersky shows that only 44 percent of macOS users delete unused applications, even though 56 percent regularly clear browser data and 54 percent remove unwanted media files. Residual files can contain sensitive information including account tokens, passwords, IP addresses, event logs, and personal documents, creating privacy risks especially when a device is sold or accessed by unauthorized parties. Deleted files can be restored from the trash or directly within Kaspersky Premium before the application session ends. The company also warns that malicious programs are frequently disguised as legitimate macOS cleaning utilities.

Securitylab•Privacy & Surveillance

Bypassing VPN Detection on iPhone: Detailed Methods to Avoid App Blocks

Many iPhone users encounter apps that detect and block active VPN connections even after switching servers or protocols. The detection often occurs locally on the device by inspecting network interfaces rather than relying solely on external IP addresses. This guide explains how apps identify VPN tunnels through iOS network data and provides practical workarounds including moving the VPN to a router, configuring per-app exclusions, and using web versions of services. It also covers why protocol obfuscation and port changes fail to hide local VPN activity from applications. Additional troubleshooting addresses automatic VPN profiles, ad blockers, and iCloud Private Relay interference. The article emphasizes that no universal toggle exists in iOS to hide an active VPN from all apps.

Habr•Privacy & Surveillance

New Obfuscation Method Dissolves Personal Data Records in Layer of Plausible Variants

A Russian information security researcher has proposed a data protection technique that renders stolen personal records unusable even after full compromise. The approach mixes real data such as phone numbers, emails, passports, addresses, INN and SNILS with vast numbers of semantically valid alternatives. Attackers receive nearly complete information including a 361-character message containing PIN codes and word order, yet lack the secret vector space and reconstruction algorithm required to identify the correct record. Without these components, brute-force attempts produce millions of plausible results with no architectural method to verify accuracy. The method is presented as an alternative to traditional encryption when data must remain accessible yet protected against extraction. A public sandbox is available for testing the approach.