Habr•August 1, 2026•🇷🇺Translated from Russian

TSPU Filtering Disrupts Timeweb Cloud Servers: Diagnosis, CDN Failures, and Reverse Proxy Bypass

Russian hosting provider Timeweb Cloud began experiencing selective TSPU filtering in early June that prevented clients from accessing WordPress sites without a VPN. Two commercial sites hosted on the same VPS stopped opening for users in the same city and later for the administrator connecting over a wired connection.

Initial troubleshooting ruled out fail2ban, Google Captcha, registry blocks by Roskomnadzor, and judicial decisions. Competitors on other providers remained accessible, pointing to a provider-specific issue. The observed behavior showed TCP connections on port 443 establishing successfully, followed by a missing Server Hello and a 20-second timeout, while SSH on port 22 and ICMP traffic continued without loss.

The filtering proved dynamic: it initially blocked by SNI at night, later switched to IP-based blocking by midday, and intermittently relaxed in the evening. Timeweb support acknowledged the problem on June 5 in ticket 12068181, attributing it to changes in TSPU settings and noting that the issue varied by operator, region, and browser. Similar reports appeared from Beget and Selectel around the same period.

Obtaining new IP addresses proved ineffective, with filtered behavior recurring on fresh addresses. DNS record updates after IP changes also caused extended outages. Attempts to place Yandex Cloud CDN in front of the origin succeeded for static content but failed for any POST requests, returning 405 errors for wp-login.php, cart operations, and AJAX calls.

A stable workaround used a minimal nginx reverse proxy on a separate Russian cloud VPS. The configuration correctly forwards the Host header and SSL server name, supports all HTTP methods, and includes tuned proxy buffers to prevent 502 errors on large cookie responses from logged-in WordPress administrators. ACME challenge paths are explicitly proxied to allow Let's Encrypt certificate issuance, and a synchronization script copies updated certificates from the origin server.

Testing with curl --resolve allowed validation of both GET and POST functionality before DNS cutover. Additional community suggestions include disabling TLS 1.3 or requesting subnet whitelisting through legal entities, though these were not tested in this case.

Later tickets submitted to Timeweb in July received requests for mtr traces, which cannot detect selective DPI interference because the mechanism allows TCP establishment before dropping TLS packets. Support closed the tickets claiming resolution despite ongoing symptoms reported by clients.

Related articles

Securitylab•Privacy & Surveillance

Can Wi-Fi Owners See Your Google Search History? HTTPS, DNS, SNI and ECH Explained

A viral social media video sparked widespread concern that Wi-Fi owners could view users' search history and visited sites simply by knowing the router password. Security experts from Cybernews and Surfshark clarified that modern HTTPS encryption prevents reading of actual search queries or page content. However, metadata such as DNS requests, SNI fields in TLS handshakes, and device MAC addresses remain visible to the network administrator. The introduction of Encrypted Client Hello (ECH) under RFC 9849 aims to hide domain names, yet Russian authorities have blocked many ECH-enabled connections since November 2024. Corporate or school-managed devices with installed root certificates represent the main real-world exception where full traffic inspection is possible. VPNs hide destinations from the local router but transfer visibility to the VPN provider. The article emphasizes that password-protected Wi-Fi grants access only to connection metadata, not browser history.

Habr•Privacy & Surveillance

Yandex Deploys OPRF Protocol to Protect Phone Numbers in Mandatory Audience Measurement Data Sharing

Yandex has detailed a cryptographic scheme using Oblivious Pseudorandom Function (OPRF) to help Russian audiovisual services comply with new legislation requiring transmission of user identifiers linked to phone numbers. The approach replaces a naive shared-secret hashing method that created a single point of compromise across dozens of competing companies. Instead, two independent third parties each hold separate secret keys and process blinded elliptic-curve points derived from normalized E.164 phone numbers. Services obtain deterministic identifiers without learning the third-party keys and without exposing raw numbers to the authorized research organization. The design distributes trust, limits offline brute-force attacks to scenarios requiring both keys plus final identifiers, and adds rate limits plus key-rotation capabilities to deter abuse. Yandex positions the solution as a practical compromise between regulatory demands, competitive secrecy, and user privacy.

Habr•Privacy & Surveillance

CookieTin Extension Manages Partitioned Cookies Across Firefox, Chrome and Edge

Developer Perruer2 has released CookieTin, an open-source browser extension that fully supports partitioned cookies under Firefox Total Cookie Protection and Chrome CHIPS. The tool addresses limitations in older managers like Cookie Quick Manager by correctly retrieving and deleting cookies stored with partitionKey values. It works across Firefox, Chrome and Edge using a single Manifest V3 codebase written in TypeScript and Preact. Key features include accurate cookies.txt export compatible with curl and yt-dlp, protected cookies that survive explicit deletion, and pre-save validation of browser rules for __Host- prefixes and SameSite attributes. E2E tests using Puppeteer verify handling of HttpOnly, partitioned and container cookies in all three browsers.

AntiMalware•Privacy & Surveillance

Kaspersky Premium for macOS Gains App Uninstall Feature to Remove Residual Files

Kaspersky Premium now includes an App Uninstall tool for macOS that locates and deletes leftover files such as caches, cookies, settings, and logs after applications are removed. The feature also identifies duplicate copies of programs and lets users remove all instances or select specific ones while preserving shared components used by other software. Survey data from Kaspersky shows that only 44 percent of macOS users delete unused applications, even though 56 percent regularly clear browser data and 54 percent remove unwanted media files. Residual files can contain sensitive information including account tokens, passwords, IP addresses, event logs, and personal documents, creating privacy risks especially when a device is sold or accessed by unauthorized parties. Deleted files can be restored from the trash or directly within Kaspersky Premium before the application session ends. The company also warns that malicious programs are frequently disguised as legitimate macOS cleaning utilities.