Developer Builds Decentralized Messenger to Navigate Russian Laws 149-FZ and 152-FZ
A solo developer has released Gram, a lightweight messenger built entirely alone using the $mol framework and HyperBaza technology. The application enables encrypted messaging without logins, passwords, or any personal data collection and is intended only for home or personal use.
The project serves as a practical case study of Russian Federal Law 149-FZ, which defines an instant messaging service organizer as any entity providing systems for exchanging electronic messages where the sender selects the recipient and no public information is hosted. The developer notes that Gram can function offline, does not guarantee instant delivery, and performs all decryption exclusively on user devices.
Key features include direct dialogs by known ID, creation of invite-only conversations, and public registries that users can join voluntarily. All correspondence is end-to-end encrypted via HyperBaza, while push notifications cannot access message content. A built-in proof-of-work mechanism requires CPU effort for each message to deter spam bots.
Under 152-FZ on personal data, the application collects nothing, so no obligations arise. However, 149-FZ obligations fall on whoever operates public HyperBaza nodes because those nodes handle message relay without decryption. The law explicitly exempts citizens acting for personal, family, or household needs, allowing private use but requiring public nodes to be disabled.
The application cannot technically satisfy several legal requirements: identifying users by phone number, providing decryption keys, or storing readable message content for six months. Source code is published on GitHub, and users outside Russian jurisdiction may run their own nodes on gh-pages or local instances.
Metadata such as sender, recipient, and timestamps remains visible on servers. Due to the decentralized architecture, revocation of access to old messages in group chats is impossible. A poll on the original post showed most respondents believe the public node operator would be considered the organizer of information distribution.
Related articles
FAS Case Against Apple Will Not Brick iPhones for Russian Users
The Russian Federal Antimonopoly Service (FAS) has opened a case against Apple for failing to pre-install a national messenger and a Russian app store on iOS devices, yet officials have confirmed that no technical measures will disable or restrict existing iPhones. Deputy Chairman of the State Duma Committee on Information Policy Andrey Svintsov stated that the actions of FAS, Roskomnadzor and other agencies are limited to recording violations and collecting fines. Apple had already implemented the option to select a domestic search engine but did not meet the remaining pre-installation requirements. Svintsov emphasized that any court decisions will remain in force until Apple decides to return to the Russian market and settles accumulated penalties. The approach is designed to replenish the state budget through fines once the company resumes legal operations. Russian iPhone owners can continue using their devices without any risk of remote blocking or forced conversion into expensive paperweights.
Yandex Cloud Partners with Sogaz and Ingosstrakh to Automate Cyber Risk Assessment for Business Insurance
Yandex Cloud, through its Yandex B2B Tech division, has launched joint cyber insurance programs with Russian insurers Sogaz and Ingosstrakh. The initiative replaces traditional manual questionnaires with automated infrastructure scanning via the Yandex Security Deck service. The tool examines cloud resources, applications, and data to identify open internal information, excessive user privileges, leak risks, and potential compromise vectors. Detected issues are consolidated in a single prioritized interface and shared with insurers to refine policy terms. If critical gaps are found, Yandex Cloud also provides remediation recommendations. The move comes as demand for cyber insurance grows rapidly, with Sogaz reporting that requested coverage volume doubled year-over-year to exceed 12 billion rubles in the first half of 2026.
Over 20 VPN Services Hit by Outages After Russian Regulators Block Hosting Provider Subnets
Users of multiple VPN services reported widespread connection problems throughout the day as IP addresses belonging to several large hosting providers were placed under restrictions. The blocks targeted infrastructure used by VPNs to reroute traffic around content filters, causing entire ranges of servers to become inaccessible when whole subnets were affected. The Telegram channel Exploit reported that more than 20 VPN services of varying sizes experienced disruptions, though Roskomnadzor has not issued an official statement on the scope or origin of the measures. The affected providers indicated they are shifting customers to backup servers, noting that the restrictions appear selective yet still force frequent address changes during the day. The incidents coincide with ongoing discussions of new rules that would require hosting providers to independently detect and report masked VPN IP addresses to regulators. Similar large-scale subnet blocks occurred in late May, impacting numerous MTProto-based proxies and VPNs simultaneously.
HackerOne Ends Anonymous Era for Bug Bounty Hunters with Mandatory ID Verification
HackerOne has introduced compulsory identity verification for all researchers submitting reports to paid bug bounty programs, effective August 1. The policy requires users to complete KYC checks through Estonian firm Veriff by uploading government-issued ID and performing a live selfie, with annual renewals. Vulnerability Disclosure Programs remain open to anonymous participants, but any researcher seeking monetary rewards must now reveal their identity. The move follows similar steps by Bugcrowd and Intigriti and is driven by anti-money laundering and cross-border payment regulations. Researchers in high-surveillance regions and newcomers face new barriers, while the platform argues the change improves report quality and enterprise trust. H1 Clear adds an extra criminal background check layer for elite participants.