Habr•August 27, 2026•🇷🇺Translated from Russian

HTTPS Lock Icon Present but List of Visited Sites Remains Visible

Public Wi-Fi prompts two common reactions: either passwords are stolen so avoid it, or HTTPS makes everything safe. Both views are imprecise and obscure what actually occurs on the wire.

Passwords remain safe under working HTTPS. However, the list of visited sites stays visible to the access point owner, the ISP, or any neighbor on an open network. No cracking is required; the information travels in plaintext.

First: DNS

Before loading a site, the device queries a DNS server for the IP address. Classic DNS uses UDP without encryption, so the domain name travels openly. A capture with tshark -i any -f "udp port 53" immediately shows requested names such as habr.com or example.org. The access point owner sees every domain from every connected device. Background queries from updates and messengers continue even after sites are closed, allowing usage patterns to be reconstructed.

Second: SNI

Encrypting DNS does not solve the next step. During TLS setup the client sends the Server Name Indication (SNI) in the first handshake message, before encryption is established. A capture filtered on tcp port 443 and the tls.handshake.extensions_server_name field reveals both the destination IP and the hostname. This plaintext field powers domain-based blocking and filtering without any decryption.

What stays hidden includes full request paths, parameters, page content, files, messages, passwords, and cookies. Certificate mismatches also trigger browser warnings, preventing content tampering.

The outdated warning about stolen bank passwords on café Wi-Fi is roughly ten years old. The real exposure is metadata: which services are used, when, and how often. Packet sizes and timing can further distinguish specific videos from a known set, though this requires more effort.

How to close DNS leaks

Modern browsers support DNS over HTTPS. In Firefox the setting is under Privacy & Security; in Chrome it appears under Security. After activation, UDP port 53 queries from the browser disappear. System-wide resolvers must be configured separately. The change simply moves visibility from the local network to the selected resolver operator.

How to close SNI leaks

Encrypted Client Hello encrypts the SNI field but needs support from both the browser and the destination site plus its CDN. Firefox offers the toggle in network settings; Chrome lists it among experimental flags. Coverage remains incomplete, so unprotected sites still leak the name in plaintext.

The only reliable method today is a VPN tunnel, which again relocates observation to the tunnel provider. DNS leaks outside the tunnel, traffic before the tunnel connects, and the mere fact of tunnel use remain visible to the local network.

Related articles

Habr•Privacy & Surveillance

Building Prizrak: How a Developer Created a Federated Messenger That Masks All Traffic as Legitimate HTTPS

A developer created Prizrak, a federated messenger with end-to-end encryption where all traffic, including calls, is indistinguishable from ordinary HTTPS connections. The project addresses three common limitations of existing messengers: centralized control points, mandatory phone numbers, and detectable encrypted traffic. It uses real TLS 1.3 handshakes to actual domains, multi-port listening, and a hidden token mechanism inside the encrypted channel. When servers cannot reach each other directly, messages are delivered through a network of storage nodes modeled after Ceph's RADOS system. Voice and video calls run on a native media stack with custom STUN-like functionality and careful UDP buffer sizing to avoid packet truncation. An integrated two-hop VPN reuses the same stealth transport while keeping messenger traffic outside the tunnel.

Habr•Privacy & Surveillance

GrapheneOS Setup Guide: Configuring Pixel Phones for Corporate Surveillance-Free Daily Use

This comprehensive engineering guide explains how to deploy GrapheneOS on supported Google Pixel devices to eliminate corporate telemetry collection. It follows three core principles: rejecting proprietary ecosystems, applying Zero Trust through cryptography and open-source audits, and enforcing strict compartmentalization via isolated user profiles. The tutorial covers official installation via the Web Installer, basic owner profile hardening with PIN shuffling and automatic reboot, and the use of Obtainium for direct FOSS app management from GitHub repositories. Detailed recommendations include privacy-focused tools such as KeePassDX, Aegis Authenticator, AmneziaVPN, Signal, and Fossify applications, along with VPN kill-switch configuration. Regional profiles are created for sandboxed Google Play, Aurora Store, RuStore, and Huawei AppGallery to safely run banking, marketplace, and social apps without cross-profile tracking.

Habr•Privacy & Surveillance

Following the White Rabbit: Developer Builds Custom Rust VPN PAYPHONE Using QUIC and Obfuscation to Evade Detection

A Russian developer has released PAYPHONE, an experimental IPv4 VPN written entirely in Rust that uses QUIC datagrams and optional TLS-over-TCP transport with custom obfuscation. The project aims to provide an alternative to AmneziaWG and Xray/VLESS+REALITY stacks that are commonly used to bypass Russian internet filtering. The article details the full packet path from TUN interface through a 16-byte PAYPHONE header, session management with Ed25519 tokens, and multiple post-launch bugs including MTU miscalculations, self-routing loops on macOS, and timer lifetime issues in Tokio. Key technical choices include RFC 9221 datagram support to avoid head-of-line blocking for multiplexed TCP flows and token-bucket rate limiting tied to subscription tokens. The author also describes route monitoring every 400 ms and interface-bound sockets to prevent the tunnel from swallowing its own control traffic.

AntiMalware•Privacy & Surveillance

WhatsApp Introduces Parental Controls for Teen Privacy Settings

WhatsApp, owned by Meta (recognized as an extremist organization and banned in Russia), has rolled out new parental control tools for family accounts. Parents can manage privacy settings, group participation, channel access, status visibility, and Meta AI usage for teens, but cannot read personal messages due to end-to-end encryption. All controls are voluntary and require joint setup with the teenager, protected by a single PIN code that prevents easy reversal of restrictions. Notifications alert parents when teens join or leave groups or when group sizes change significantly. Separate options cover channel usage, viewable statuses, and audience controls for teen posts. Meta AI access can be set to a standard 13+ mode or a stricter Limited Content mode with undisclosed restrictions. The company plans to expand these features gradually based on family feedback while maintaining encryption protections.