Topic
Yandex

Yandex Details Alice Voice Assistant Audio Buffering and Data Handling in Android Apps
Privacy & Surveillance
Yandex Go Develops Custom DSL to Handle Complex Dynamic Ride Pricing Logic
Other
Yandex Alice AI Replaces VK Marusya in Russia's Mandatory Preinstalled Apps List for 2027
Policy & RegulationYandex Apps Leak Pre-Trigger Audio Buffers, Payment Data, and Contacts via Reverse Engineering
Reverse engineering of Yandex Search and Yandex Browser APKs reveals extensive data collection practices on Android devices. The apps maintain a server-controlled pre-trigger audio buffer that captures up to three seconds or more of microphone input before the wake word Alice is detected. WiFi fingerprinting, full contact book synchronization via ContentObserver, and transmission of PAN and CVV details to mobpayment.yandex.net occur before tokenization. Additional findings include 94 JavaScript Bridge methods, logcat exfiltration with AES encryption, hardcoded Yandex DNS servers, and a native surveillance library named libquarkenstein_daemons.so. The analysis also covers passive geolocation, cell tower data collection, and inventory of installed applications including competitors such as Chrome, Firefox, WhatsApp, and Telegram. These mechanisms operate under remote configuration flags and bypass several Android privacy restrictions through manifest queries.
Yandex Rolls Out Universal Anti-Fraud Platform to Block Bots and Manipulation Schemes
Yandex has begun deploying its Universal Anti-Fraud system, a single AI-driven platform designed to detect bots, ticket scalping, and other forms of digital fraud across multiple services. The new solution can be integrated into a service within two to four days, replacing the previous months-long process of building separate defenses for each product. Dozens of Yandex services, including Eda, Afisha, Puteshestviya, and applications powered by Alice, are already connected to the platform. In Afisha the system identifies bots that mass-book tickets for popular events to create artificial scarcity, while in Eda it flags repeated fraudulent complaints aimed at obtaining compensation. The platform combines neural networks, analytical methods, and more than one hundred attack-pattern rules, analyzing traffic in real time and applying service-specific parameters. A key advantage is centralized updating: once a new fraud scheme is identified, protections are distributed instantly to all connected products.
Personal Digital Resilience: Strategies to Secure Access Chains and Preserve Data Portability
The article explores how individuals can strengthen their digital infrastructure against service outages, lost access, and data loss without turning maintenance into a full-time project. It defines digital resilience through two pillars: security against unauthorized access and reduced dependence on any single provider, especially when regulators in different jurisdictions interfere. The author maps real-world processes to digital services, access methods, and stored data, then outlines recovery formulas for each failure scenario. Practical steps include auditing password-manager entries, eliminating circular dependencies, separating recovery roots by jurisdiction, and exporting data in portable formats. Special attention is given to secrets such as TOTP seeds and recovery codes, which are stored in an encrypted offline archive whose master password exists only on paper. The resulting structure features two independent trees rooted at Yandex and Google, with all critical services backed by verifiable exports and tested recovery paths.
DeepSeek User Conversations Appear in Google Search Results via Publicly Shared Links
Conversations between users and the Chinese AI service DeepSeek, including Russian-language exchanges, have surfaced in Google search results. The exposed pages belong to Shared Conversations that users themselves made public through shareable links. These pages display full question-and-answer histories along with the names of any uploaded documents. No actual breach of DeepSeek occurred, and security researchers note that search engines indexed similar public chatbot dialogues more than a year ago. MWS AI confirmed that no closed chat histories or account access were exposed. Meanwhile, Yandex stated that links to conversations with its Alice AI assistant are blocked from indexing, remain active for only 14 days, and do not transmit attached files to recipients.