HabrJuly 30, 2026🇷🇺Translated from Russian

Six Bitrix24 Disk Migration Errors That Force Portal Redesign After Six Months

Bitrix24 Disk migration projects often appear complete after a weekend file transfer, yet six months later companies face missing contracts, unauthorized access to salary folders, and severe performance degradation. The root cause is rarely a failed copy operation; instead, the original network share structure is replicated unchanged into a platform whose storage model relies on three distinct container types: My Disk, group and project disks, and the company-wide common disk.

Ошибка 1 — copying the folder tree verbatim — produces 30–40 top-level folders with names such as “Miscellaneous 2” and eight levels of nesting. Because Bitrix24 search is under-used, employees cannot locate documents efficiently. The recommended approach is to map every top-level folder to an owner, a readership group, and a business process before any files are moved.

Ошибка 2 occurs when My Disk becomes the de-facto working repository. When an employee leaves, signed contracts disappear; when the employee is on vacation, colleagues cannot retrieve needed files. The fix is a written policy that restricts My Disk to personal drafts only, enforced by periodic REST inventory scripts that flag personal storages containing more than three top-level folders.

Ошибка 3 — granting rights to individual users rather than departments — results in access matrices containing dozens of personal entries that quickly become stale. After one reorganization the list is unreadable and auditing is impossible. Rights should be assigned via department codes (DR5) or workgroups so that personnel changes are handled automatically.

Ошибка 4 places every ambiguous document into the common disk with full access for all authenticated users. The Toyota T-Connect, G-Link and G-BOOK breach affecting 2.15 million customers between 2013 and 2023 shows how a single misconfigured open bucket can remain unnoticed for ten years. The correct default is read-only access on the common disk, with write rights granted only to specific sections and no “Miscellaneous” folder allowed.

Ошибка 5 attaches file copies to tasks and CRM records instead of links. Version history is lost, storage quotas are wasted, and the latest approved document is never visible in the deal card. The rule is simple: the authoritative copy lives on Disk; every other entity receives a link.

Ошибка 6 enables desktop synchronization for the entire tree. Offline editing on multiple machines produces conflicting copies that nobody resolves. Only folders actively edited offline should be synchronized; the rest should be accessed via mapped network drives or the online editor.

Successful teams now follow four practices: a thorough pre-migration inventory that discards 40–60 % of untouched files, a two-week pilot on a single department, named owners for every top-level section, and mandatory quarterly rights reviews. These steps convert a one-time migration into a sustainable information-security process.

Related articles

AntiMalwarePrivacy & Surveillance

Google to Add Explicit Content Warnings in Android System Photo Picker

Google is preparing a new safety feature for the system photo picker in Android that will scan images and videos for explicit or nude content. The tool is designed to warn users before they share intimate photographs, whether accidentally or due to a momentary lapse in judgment. This functionality will operate at the system level, meaning it applies across multiple apps that use the built-in photo selector. The feature aims to reduce the risk of unintended distribution of private images that could lead to embarrassment or privacy violations. By integrating the check directly into Android, Google seeks to provide a consistent layer of protection without requiring third-party applications to implement similar logic themselves.

AntiMalwarePrivacy & Surveillance

LG Smart TVs Record Audio in Standby Mode and Scan Home Networks for Advertising Data

Researchers from the Gamers Nexus YouTube channel analyzed multiple LG OLED television models, including the LG G5 series, and discovered that the devices continue to capture audio through built-in microphones even when the screen is off and the television is in standby. The TVs scan local networks to identify smartphones and smartwatches, collect internal IP addresses, available Wi-Fi network names, and location data. When internet connectivity is removed, audio recordings are stored locally and transmitted once the connection is restored. The devices also employ Automatic Content Recognition (ACR) technology to generate digital fingerprints of viewed content, with the resulting data reportedly sent to LG Ad Solutions for targeted advertising. Additional vulnerabilities were identified in webOS that could potentially allow remote code execution. LG has not yet commented on the findings, and experts recommend disconnecting the televisions from the internet and using external streaming devices until official clarification is provided.

HabrPrivacy & Surveillance

Engineer Details Six Weeks Spent Training and Testing Signature Redaction Models for Closed-Loop Document Anonymization

A detailed case study describes attempts to automatically redact handwritten signatures from scanned and text-based PDFs containing personal data such as names, phones, addresses and signatures. The work was performed inside an air-gapped environment on a single GPU machine with no internet access. Multiple approaches including color-based ink gates, pre-trained YOLO detectors, custom-trained YOLO11s models, Tesseract OCR heuristics and various vision-language OCR engines were evaluated on 492 real pages plus synthetic augmentations. Key findings include rotation handling bugs, line-assembly failures in Tesseract, the necessity of using apply_redactions instead of draw_rect for true removal, and the limited value of vision models once rule-based pipelines are mature. The final pipeline reduced expensive vision-model calls from 50 pages to 18 pages while achieving zero leaks across thousands of redactions. The author also measured twelve OCR engines and demonstrated that combining PaddleOCR detection with Tesseract recognition yields the best accuracy-to-speed trade-off.

HabrPrivacy & Surveillance

pg_anon Open-Source Tool Receives Major Updates for PostgreSQL Data Masking and Partial Database Operations

Tantor Labs has released version 1.11.0 of pg_anon, an open-source utility designed to mask personal data in PostgreSQL databases while preserving structure and relationships. The update introduces packaging as a standard Python package, support for partial dumps and restores using whitelist and blacklist dictionaries, and improved handling of complex schema elements such as partitioned tables, generated columns, and custom types. Performance improvements include switching the dump engine to asyncio, single-query metadata collection, and on-the-fly gzip compression to reduce memory usage on large databases. New CLI options allow clean or drop operations on target databases, privilege ignoring, and passthrough of pg_dump and pg_restore flags. A REST API was added to enable integration into CI/CD pipelines and automated self-service systems for nightly masked database refreshes. The tool helps organizations comply with data protection requirements by creating pseudonymized copies suitable for development, testing, and contractor environments.