AntiMalware•August 31, 2026•🇷🇺Translated from Russian

Russian Firms Accumulate Digital Clutter: 35% of Corporate Files Unused for Years, Weak Passwords Expose Sensitive Data

Russian businesses continue to accumulate digital clutter while granting overly broad access rights across corporate storage systems. Garda, a company within IKS Holding, analyzed repositories belonging to more than 100 organizations and uncovered multiple serious concerns.

The dataset included over 157 TB of data and more than 511,000 user accounts. Approximately 35% of files had remained untouched for more than five years. Duplicate copies may account for another 35% of stored volume. In some sectors, up to one-third of the space was occupied by personal photographs, videos, archives, and other non-business content.

Paying to store this digital waste is only part of the problem. The larger the number of uncontrolled copies scattered across folders and resources, the harder it becomes to determine where confidential information resides and who can access it.

Access management practices also raised alarms. More than 33% of accounts used critically weak passwords or passwords that had not been rotated for a long time. Auditors discovered numerous contractor and temporary employee accounts inactive for over 90 days. In large organizations, direct permissions issued outside security groups were common. Folders with wide access rights often contained passport scans, client registries, database exports, and other sensitive documents.

Garda concludes that manual remediation of such volumes is no longer practical. The company advises organizations to regularly inventory and classify information, manage access centrally, and automate the full data lifecycle from creation to deletion.

Related articles

Habr•Privacy & Surveillance

ONYX 2.0 Removes Central Servers for Fully Decentralized Tor-Based Messaging and Calls

ONYX 2.0-beta marks a major shift from its previously centralized design to a serverless architecture that relies entirely on Tor for all communications. Each user account is now represented solely by a cryptographic key pair generated on first launch, with recovery handled through a 12-word seed phrase. Devices connect directly via onion services, and the application bundles its own Tor daemon on desktop platforms while using tor-android on mobile devices. Voice calls are supported through an embedded local TURN server, delivering acceptable quality with 1-3 second latency despite the anonymity overhead. Message delivery now depends on recipient availability, with undelivered messages stored locally on the sender and retried automatically. The update deliberately removes features such as HTTP or SOCKS5 proxies and link previews to prevent IP leaks or external traffic. Developers released the beta to gather feedback on stability across network changes and multi-device scenarios.

Habr•Privacy & Surveillance

Privacy-Focused Browser Tool Compresses PDFs Locally Without Uploading Sensitive Documents

A developer created a PDF compression tool that runs entirely inside the browser to protect sensitive personal and professional documents from third-party servers. The solution addresses repeated situations where embassy submissions, financial presentations, contracts, and internal reports exceeded size limits, forcing users to choose between installing desktop software or risking data exposure through online services. The tool reduces scanned and photographic PDFs by 66 to 97 percent depending on quality settings while honestly reporting weaker performance on text-heavy files compared with Ghostscript. It works on both desktop and mobile platforms, including iPhone and Android, requires no installation, and continues functioning offline after the first page load. On mobile devices the application respects memory constraints by limiting images to four megapixels, preserving readability for A4 documents intended for printing. The project originated from a single evening script built around Ghostscript and evolved into a full web application after similar compression needs recurred across multiple devices and locations.

Habr•Privacy & Surveillance

Building Prizrak: How a Developer Created a Federated Messenger That Masks All Traffic as Legitimate HTTPS

A developer created Prizrak, a federated messenger with end-to-end encryption where all traffic, including calls, is indistinguishable from ordinary HTTPS connections. The project addresses three common limitations of existing messengers: centralized control points, mandatory phone numbers, and detectable encrypted traffic. It uses real TLS 1.3 handshakes to actual domains, multi-port listening, and a hidden token mechanism inside the encrypted channel. When servers cannot reach each other directly, messages are delivered through a network of storage nodes modeled after Ceph's RADOS system. Voice and video calls run on a native media stack with custom STUN-like functionality and careful UDP buffer sizing to avoid packet truncation. An integrated two-hop VPN reuses the same stealth transport while keeping messenger traffic outside the tunnel.

Habr•Privacy & Surveillance

GrapheneOS Setup Guide: Configuring Pixel Phones for Corporate Surveillance-Free Daily Use

This comprehensive engineering guide explains how to deploy GrapheneOS on supported Google Pixel devices to eliminate corporate telemetry collection. It follows three core principles: rejecting proprietary ecosystems, applying Zero Trust through cryptography and open-source audits, and enforcing strict compartmentalization via isolated user profiles. The tutorial covers official installation via the Web Installer, basic owner profile hardening with PIN shuffling and automatic reboot, and the use of Obtainium for direct FOSS app management from GitHub repositories. Detailed recommendations include privacy-focused tools such as KeePassDX, Aegis Authenticator, AmneziaVPN, Signal, and Fossify applications, along with VPN kill-switch configuration. Regional profiles are created for sandboxed Google Play, Aurora Store, RuStore, and Huawei AppGallery to safely run banking, marketplace, and social apps without cross-profile tracking.