Habr•August 20, 2026•🇷🇺Translated from Russian

Separating Identity and Delivery Channels for Compliant Telegram Mini App Authentication

When configuring authorization in Telegram Mini Apps, the initial flow appears straightforward: Telegram supplies initData, the server validates the HMAC-SHA-256 signature derived from the bot token, and everything works out of the box. However, services aimed at Russian users must also satisfy stricter identification requirements, prompting the team to keep Telegram primarily as a delivery channel rather than the sole login method.

The architecture explicitly separates two concepts: “who the user is” (identity) and “where to send notifications” (channel identity). Users authenticate via VK ID, Yandex ID or MAX, after which their telegram_id is linked to the account solely for message delivery. The database schema reflects this split with separate tables storing max_user_id, vk_user_id, yandex_id for identity and max_chat_id, vk_chat_id, telegram_id for delivery channels.

Three buttons labeled MAX, VK and Yandex appear inside the mini-app; no “Login with Telegram” option exists. For VK ID the team uses OAuth 2.1 with PKCE: the browser generates a code_verifier, computes the S256 code_challenge, and includes both state and challenge in the authorization request. The server stores the verifier keyed by state for later validation.

Authorization opens in a new browser tab, allowing users to complete the flow in their main browser even when the mini-app runs inside Telegram WebView or on another device. After success the tab closes itself and the main interface learns the outcome via polling. The same pattern was applied to smart-home authorization through Home Assistant.

Yandex authentication follows a similar OAuth 2.0 flow, but the authorization URL is generated on the backend. The server exchanges the received code for an access token, retrieves the user identifier, and returns the result via a /api/auth/result-by-state endpoint that clients poll (for example, 120 attempts at three-second intervals). Only a short-lived application-level code travels to the browser; the OAuth token itself never reaches client JavaScript and is instead stored in an HttpOnly cookie, reducing XSS exposure.

State values are generated with crypto.randomUUID() or crypto.getRandomValues() providing at least 128 bits of entropy and are stored server-side with a short TTL. The callback avoids placing any auth_token in the URL; a one-time code is exchanged for a session via POST. A from_extension flag is passed only for UI adjustments and carries no security meaning on the server.

MAX integration uses a deep link containing a single-use token; after binding, the bot posts a confirmation message in the chat. Consent handling differs by platform: Telegram WebApp versions display two checkboxes (general consent and separate consent for data transfer to Telegram) to meet legal requirements, while the PWA version requires only one checkbox.

The resulting system powers the project “My Anti-Social Network,” an ad-free news aggregator that includes bots in Telegram, MAX and VK, a PWA, browser extensions, mobile apps and integrations with smart-home and voice assistants. The developer notes that while the technical pattern supports compliance, final legal validity depends on specific regulatory interpretation.

Related articles

Habr•Policy & Regulation

Merkle Tree Certificates Proposed to Enable Lightweight Post-Quantum HTTPS in Chrome

Google Chrome developers, together with industry partners and the IETF PLANTS working group, are introducing Merkle Tree Certificates (MTC) as the first HTTPS change designed to address performance challenges of post-quantum cryptography. The new format replaces parts of traditional X.509 certificate chains with compact inclusion proofs inside a Merkle tree whose root is signed by a certificate authority. This approach significantly reduces the size of authentication data exchanged during TLS handshakes while preserving strong post-quantum security properties. MTC also enforces Certificate Transparency by design, making it impossible to issue a public certificate without recording it in a publicly verifiable log. Performance evaluations are currently underway with Cloudflare, and initial public MTC logs operated by experienced CT log providers are planned for early 2027. A dedicated post-quantum Chrome Root Store supporting only MTC is scheduled for the third quarter of 2027 and will run in parallel with the existing root store.

Habr•Policy & Regulation

AI Resume Screening Barriers Push Young IT Talent Toward Cybercrime

Young Russian IT graduates with relevant projects and freelance experience are struggling to secure entry-level roles in information security and antifraud due to automated resume filters demanding prior commercial experience. Data from SuperJob and Habr Careers shows only 10-11% of IT vacancies in early 2026 were open to candidates without experience, compared to 37-38% across the broader labor market, with most junior openings limited to technical support. Russian court statistics reveal that 67.9% of those convicted for computer-related crimes under Article 272 were under 30, aligning with the age when graduates first seek professional experience. International studies, including research from Harvard Business School and Accenture, highlight how overly rigid automated screening discards capable candidates lacking formal tenure. Programs like the UK's National Crime Agency Cyber Choices demonstrate that providing legal pathways in cybersecurity can reduce recidivism. The article argues that excessive reliance on AI filters without human review of projects or practical tests exacerbates the pipeline problem in a sector claiming talent shortages.

Habr•Policy & Regulation

Bill Gates Calls for Stronger External Oversight and Regulation of AI

Bill Gates stated in an NBC News interview that self-regulation by AI developers is no longer sufficient and urged Congress to pass binding laws on artificial intelligence. He warned that AI tools in the hands of malicious actors could trigger catastrophic events capable of causing up to a billion deaths, emphasizing the unprecedented power of combining bad intentions with modern AI systems. Gates advocated for mandatory rules, audits, and monitoring, particularly in critical sectors such as medicine, finance, and government infrastructure, while acknowledging that some added bureaucracy would be necessary. Leaders from Anthropic and OpenAI have similarly suggested slowing AI development, with former Anthropic employee Jacob Coxon publicly accusing companies of playing roulette with lives by pursuing self-improving superintelligence. House Speaker Mike Johnson prefers to wait for industry proposals, whereas Mark Zuckerberg opposes coordinated oversight and believes individual labs should decide on pace. Several U.S. states including California, Maryland, and New York have already begun launching their own AI regulatory initiatives and expert panels.

Securitylab•Policy & Regulation

Implementing DevSecOps in Unprepared Teams: A Practical Three-Month Roadmap

Many development teams face resistance when security tools are introduced without proper process changes, leading to bypassed checks and unresolved findings. The article outlines a structured approach for small teams of five to eight developers without a dedicated security specialist, focusing on one service as a pilot. It emphasizes assigning clear roles including a Security Champion, selecting initial checks such as secret scanning with Gitleaks and dependency analysis, and converting scanner reports into actionable tasks with owners and deadlines. The plan covers the first eight weeks of setup, including baseline handling for legacy issues, automated blocking rules, and incident rehearsal exercises. Metrics recommended include time to first triage, age of open critical defects, and false positive rates, aligned with DORA indicators for release performance. The guidance draws on OWASP SAMM practices and stresses that security requirements must be integrated into daily workflows rather than added as extra gates.