Data Protection Day, Minsk, 2019. Organizer: the human rights organization Human Constanta.
Host (hereinafter – H): – Is Arthur Khachuyan engaging in... Can we say he’s on the ‘dark side’ in the context of our conference?
Arthur Khachuyan (hereinafter – AK): – On the side of corporations – yes.
Q: – He collects your data and sells it to corporations.
AK: – Actually, no…
Q: – He will explain how corporations can use your data and what happens to it once it goes online. He probably won’t talk about what to do with it. We’ll think about that later…

AK: – I will talk about it, I will. I won’t spend long on it, but at the last event, I was introduced to a person whose ‘Facebook’ account even blocked their dog.
Hello everyone! My name is Arthur. I am indeed involved in data processing and collection. Of course, I don’t sell any personal data to anyone publicly. Just kidding. My field of work is extracting knowledge from data in public sources. When something is legally not considered personal data, but knowledge can still be extracted from it, making it as valuable as if it came from personal data. There’s really nothing scary to share. This is mainly about Russia, but I also have numbers for Belarus.

What are the real scales?
Just the day before yesterday, I was in Moscow at one of the leading ruling parties (I won’t say which one), and we discussed implementing some project. And then the IT director of this party stands up and says: “You mentioned numbers and so on, you know, the 2nd FSB Department prepared a note for me stating that there are 24 million Russians on social media. And you say – 120 something. Actually, more than thirty [million] do not use the internet at all.” I said: “Really? Well, okay.”

People really do not realize the scope. It's not only government agencies that probably do not fully understand how the internet works; even my mom, for example, has only just begun to understand that the card she gets at 'Perekrestok' is not simply given for meager discounts offered by 'Perekrestok', but because her data is later used in OFD, purchases, forecasting models, and so on.
In general, there are this many residents, and there is information about so many in open sources. For some, only the last name is known, for others, everything is known, even down to the adult content they like (I always joke about this, but it’s really true); and all kinds of information: how often people travel, who they date, what purchases they make, who they live with, how they move around – there are a lot of different information that can be used by bad, not very bad, and good people (I don’t even know what scale to come up with right now, but nonetheless).
There are social networks that are, of course, a gigantic collection of open data, playing on the vulnerabilities of people who seem to shout about privacy. But in reality: if you imagine a graph over the last 5 years – the level of hysteria concerning personal data is rising, but at the same time, the number of closed accounts on social networks decreases year after year. Perhaps it’s not entirely correct to draw conclusions from this, but: the first thing that stops any company collecting data is simply a closed account on social networks, because the opinions of a person within their closed account, if they don't have 100 thousand followers, are not really interesting for any analysis; but such cases do exist.

Where do they get information about us?
Have you ever been contacted by old school friends with whom you haven't spoken in ages, only for that account to disappear? There's a tactic used by some bad actors who collect phone numbers: they analyze friends (and the friend list is almost always public, even if a person sets their profile to private, or the friend list can be reconstructed ‘in reverse’ from other users), take a dormant friend of yours, create a copy of their page, send you a friend request, you add them, and two seconds later the account gets deleted; meanwhile, a copy of your page remains. This is how some individuals operated recently when 68 million profiles from Facebook vanished somewhere—they were adding everyone as friends, copying this information, even messaging some people and doing things like that…
Social media is a huge source of information; in about 80% of cases, information is not obtained directly about a specific person, but rather from their nearest circle—these are various indirect insights and signals (we call this the ‘Ex’ Algorithm), inspired by a brilliant idea from a friend of mine. She never monitored her boyfriend directly—instead, she kept tabs on five of his friends, always knowing where he was. This could actually serve as the basis for an entire scientific article.
There are countless bots that engage in various kinds of good and bad activities. Some are harmless, simply following you to later promote cosmetics; while others are serious networks trying to impose their opinions, especially before elections. I don't know about Belarus, but here in Moscow, just before municipal elections, I inexplicably gained a plethora of strange new friends, each advocating for different candidates—and they don't analyze the content I consume at all—they’re just trying to impose some unclear reform, considering that I'm not even registered in Moscow and won't be voting.

A garbage dump is a source of dangerous information
Moreover, there is the "Dark Web," which is not so much underestimated—everyone thinks you should only go there to buy drugs or learn how to assemble weapons. But in reality, there are many data sources available. Practically all of them are illegal (or semi-legal) because someone might have hacked an airline database on some hacker site and dumped it there. Legally, you cannot use that data, but if you gain some knowledge from it (as in an American court), for example, an audio recording made without a warrant—while you can't use it, the knowledge you gained from that audio recording is something you won't forget, and it's roughly the same here.
This is actually a very dangerous thing, so I always joke about it, but it's true. I always order food from the neighboring house because "Delivery Club" gets hacked very often and really has serious issues. Recently, I was very surprised: I ordered groceries, and on the box that I was taking to the trash, there was a sticker with "Arthur Khachuyan", a phone number, apartment address, intercom code, and an email. We even tried to negotiate with the Moscow municipality to gain access to the trash: essentially, to go to the waste facility to see, purely out of curiosity, if we could find any mention of personal data—something like a mini-research project. But we were refused when they found out we wanted to come with the Roskomnadzor officials.
But that is actually how it is. Have you seen the amazing movie "Hackers"? They were digging through trash to find a piece of a virus. This is also a popular thing—people forget about things they throw into open sources. It could be some school website where they wrote a dissertation on the superiority of the white race, and then they went to the State Duma and completely forgot about it. Such cases have actually happened.
What are the "United Russia" supporters liking?
If you visit the 'top' section on the 'Lifnews' website... Two years ago, my students conducted a study: they took all the participants of the 'United Russia' primaries (they all officially submitted their social media accounts to the Central Election Commission), looked at what they liked – child pornography, trash, bizarre ads from strange adult women… In general, it seems people have forgotten about this.

Then they wrote a letter stating that twenty people's accounts were stolen. However, their accounts were stolen two weeks ago, they submitted them to the election commission eight months ago, and the likes were from two years ago… So, you understand, right? There is actually a vast amount of information that can always be utilized even for research purposes.
Mini-offtopic: yesterday I saw the news that Roskomnadzor blocked the research of 'Higher School' students from two years ago. Has anyone seen this news? This was done by my students: they gathered information on 'Tor', from the 'Hydra' website, where drugs are sold (I apologize – from 'Ramp'), regarding pricing and regions in Russia, and conducted a study. It was titled 'The Consumer Basket of a Partygoer'. It's certainly a funny topic, but from the perspective of data analysis, it's actually an interesting dataset – I later attended various hackathons for another two years. This is a real thing – there’s a lot of interesting material.
How Get Contact 'bought the souls' of curious users and why it’s important to read the user agreement
Usually, when you ask someone what data breach they fear (especially if the person has a webcam covered), they always prioritize it like this: hackers, government, corporations.

This is, of course, a joke. But in reality, active data analysts and various data researchers have actually stolen much more than, I think, the scary Russians, Americans, or any other hackers (insert any, depending on your political beliefs). In general, everyone usually fears this – you all probably have your webcams covered, right? You can even keep your hands down.
But if hackers do something illegal and the government needs a court order to obtain data, then these guys [corporations] don't need anything at all, because they have something called a user agreement, which no one ever reads in their life. And I really hope that such events will make people read agreements. I don't know how it is in Belarus, but in Moscow, in the middle of that year, there was a wave around the 'GetContact' app (you probably heard about it), when a mysterious app appeared that says: you give the app access to all your contacts, and we’ll show you how funny you were recorded by others.

It didn't come up in the media, but many high-ranking officials complained to me that everyone started calling them constantly. Apparently, the administrators decided to find Shoigu's phone number in this database, or someone else... Volchkova... A harmless thing. But for those who read the 'GetContact' license agreement – it states: unlimited spam at any time, sale of your data uncontrollably to third parties, without limitation of rights or statutes of limitations, and generally everything that can be imagined. And this is actually not such a rare story. While I was on 'Facebook', it showed me notifications 15 times a day: 'Sync your contacts, and I’ll find all your friends for you!'
Corporations don’t care. Federal Law 152 and GDPR
But in reality, the priorities are the opposite, because corporations are protected by private law, making it almost impossible to prove they are wrong in most cases. Given that they are large, intimidating, and very expensive, this is practically impossible. And if you are still in Russia, with outdated legislation, then it’s really quite bleak.

Do you know what distinguishes Russian law (which is practically Belarusian) from GDPR, for example? The Russian Federal Law No. 152 protects data (a relic of the Soviet past) – a document that safeguards data from leaking somewhere. GDPR, on the other hand, protects users' rights – the rights concerning losing certain freedoms, privileges, or anything else because their data might leak (they even introduced such a concept directly in the "data-leak"). Here, all you can get penalized for is a fine for not having a certified "open" Excel for processing personal data. I hope this will change someday, but I think not anytime soon.
What are the real targeting capabilities today?
The first, probably frightening story that everyone constantly thinks about is reading personal messages. Surely there's someone among you who once said something out loud and later received targeted ads. Yes, have there been such cases? Raise your hands.

I actually don't believe in the story that an imaginary "Yandex Navigator" recognizes audio directly from the stream for all users, because those who have done a bit with voice recognition understand that, for starters, Yandex's data center would need to be five times bigger; but most importantly, the cost of attracting such a person would be enormously high (to recognize audio in the stream and understand what a person is saying). But! There really are algorithms that tag you based on certain keywords, so that later they can carry out some advertising communication.
Numerous studies have been conducted, and I have created clean accounts a hundred times, messaging someone, only to suddenly receive ads seemingly unrelated to it. There are actually two conclusions here. Against this narrative – it's believed that a person simply lands in some statistical sample; for instance, you are a 25-year-old man who, at that very moment, should have encountered English language courses just when you messaged someone. At least, Facebook always argues in court: that there is a behavioral model which we won't show you, built on data that we won’t show you, we have internal studies which we definitely won't show you (because everything is a trade secret); basically, you ended up in some statistical sample, which is why we showed this to you.
How Facebook Infuriated Users Over Privacy
Unfortunately, it is entirely impossible to prove this unless you have someone inside the company who can somehow confirm these actions. However, under American law, in such cases, an employee's non-disclosure agreement takes precedence over their desire to help you, which means no one will do this. It’s also interesting – about a year or a year and a half ago – a trend began to emerge in America where people installed browser extensions to encrypt Facebook messages: you write something to someone, it encrypts it with a device key and sends gibberish in open access.

So Facebook has been suing this company for a year and a half, and it’s quite unclear on what grounds (since I don’t fully understand American law) they forced them to remove this app and then made an amendment to the user agreement: if you look, there’s a clause stating that you cannot transmit messages in encrypted form – it’s worded in such a tricky way that you cannot use cryptographic algorithms to modify messages – well, that’s the case. This means they said: either you use our platform, messaging in open access, or you don’t message at all. And this raises the question: why on earth do they even need personal messages?
Personal messages are a source of absolutely reliable information.
This is a very simple thing. Everyone who is engaged in analyzing digital footprints, human activity, tries to use this data somehow for marketing or something else – they have a metric called reliability. That is, a certain image of a person – you understand perfectly, this is not the person themselves – this image is always slightly more successful, slightly better. Personal messages contain real knowledge that can be obtained about a person; they are almost always 100% reliable. Because rarely does someone write something to someone else in personal messages to deceive, and this can all be verified very easily – accordingly, based on other messages (you understand what I mean). The point is that the knowledge extracted in this way is almost 100% reliable; that’s why everyone always tries to obtain it.

However, this is still a very difficult story to prove. And those who believe that there is such access for law enforcement agencies to personal messages on platforms like "VKontakte" – that’s not quite true. If you simply look at the history of judicial requests for disclosure of information – how "VKontakte" very cleverly (in this case Mail.ru) deflects these requests.
Their main argument is always: by law, law enforcement agencies must justify why they need access to personal messages. As a rule, if it’s a murder case, the investigator will always say that the person probably indicated where they hid the weapon (in personal messages). But we understand that no rational criminal would ever write to their accomplices on "VKontakte" about where they hid a firearm. But this is one of the common explanations officials give.

Here's another frightening example (I was asked to provide scary examples today) – about Russia (I hope this won’t happen in Belarus): according to the law, the investigator must have sufficiently valid reasons to compel the operator to disclose this information. Naturally, these verifiable parameters are not described anywhere (what they are, in what form they should be), but in Russia, there are increasingly more precedents where such a basis for court emerges if there is a model that predicts certain, good or bad, behavior.
So, nobody can be imprisoned (and that's a good thing) for being part of a statistical sample of pure murderers – and that’s good because it violates the presumption of innocence; however, there are precedents where the results of such predictions have been used to obtain court permission to access data. Not only in Russia, by the way. This kind of thing exists in America too. There, 'Palantir' has long been scoring everyone as well; similar practices are in use. It's a scary story.

This is my research. We conducted a study: we walked around St. Petersburg, at the locations of green dots we sent some key points to friends from 'clean' accounts – like 'I want to have coffee', 'where can I buy laundry detergent?' and so on. Then, as a result, we received geo-targeted ads. By what magical means… Or as they used to say: 'Coincidence? I don't think so!' These were personal messages on 'VKontakte'. Forgive me, Mail.ru, but that's how it is. Anyone interested can repeat such an experiment.
By the way, regarding this, when we filed a support request, Mail mentioned that there were Wi-Fi points that captured your MAC address. That's a thing too.
Methods of obtaining and common variants of personal data 'leakage'.
The next story is about extracting additional knowledge, a piece of which I actually touched upon. In fact, a filled-out social media profile holds about 15–20% of the real knowledge that a data operator keeps about a person. The rest comes from some very interesting things. Why do you think Google is strongly developing libraries for computer vision? In particular, they were among the first to develop libraries specifically for analyzing and categorizing objects – whether in the background or foreground, it doesn't matter. Because this is a huge source of additional information about what kind of apartment a person has, what car they drive, where they live, luxury items, etc.

There were a bunch of "hacker" leaks when trained neural networks from Google were released (I don’t know whose they were, but nevertheless). There was a lot of interesting stuff about breast size, waist measurements – people tried to find out all sorts of things about others based on photo analysis. Because when a person takes a photo, they don’t always think about how much interesting information can be gleaned from it. And how many passports of newborns have been posted in Russia? Or: "Hooray, my little one got a visa!" This is a real pain of modern society.
Here’s a bit of an off-topic (I will be sharing facts with you today): in Moscow, the most common leak of personal data is from public housing services, where a list of debtors is posted on the door, and those debtors then go to court because their personal data was made public without their consent. This could happen to you… The point is, when a person does something, they don’t always know what was in that photograph and what wasn’t. There are many car numbers now.
We once conducted a study – trying to understand how many people have public photos of their cars (which have subsequent violations and so on) – unfortunately, this could only be done through leaked traffic police databases, where there was only a number (not very reliable information), but it was still interesting.
Your next advertisement depends on how you "consumed" the previous one.
This is the first story. The second story is about behavior models, the content that a person consumes, because one of the main metrics that social networks try to establish about you is how you interact with advertising. No matter how accurate or amazing the algorithms are, and how wonderfully artificial intelligence works, the real priority of social networks is always to make money. Therefore, if a company like 'Coca-Cola' comes along and says, 'I want my post to be seen by all the residents of Belarus' – they will see it, regardless of what the algorithms think about that person or how to target them. You have probably received ads that are not just super-targeted but completely unrelated. Because a lot of money was paid for that unrelated nonsense.
But one of the main metrics is to understand which content you interact with best, specifically how you react to it, in order to show you similar advertising stories. Accordingly, it's a metric of how you interact with ads: who blocks them, who doesn't, how a person clicks, whether they only read the headlines or fully delve into the material; and then based on that, to keep you engaged in what is now referred to as a 'filter bubble', so you continue interacting with that content.

If you ever find yourself interested, try blocking all the ads on social media for a long time, perhaps a week or even a month: when an ad pops up, simply close it. If you analyze this and overlay it on a graph, an interesting story emerges: if you block ads for a week, the following week they will show you ads at an increased rate and from different categories; for instance, if you love dogs and you block all dog ads, then they will start showing you various unrelated nonsense from different categories to try to understand what you need.
And then, eventually, they will give up, marking you as someone who does not engage with advertising, putting a metaphorical cross on you, and at that moment, you will start seeing ads only from wealthy brands. Meaning, at that point, you will only see ads for "Coca-Cola," "Kit Kat," "Unilever," and all those who are pouring in huge amounts of money to inflate views. Conduct an experiment for a month: block all ads for a week or two, then see everything randomly, and block them again – in the end, you will only see ads, as it later turns out (and as advertising agencies say), from clients who pay for views, because it’s impossible to understand how you interact with that advertising.
Porn is more often watched by those who tend to deeply engage with content.
Accordingly, this is a story about all kinds of behavior tracking. I have an interesting example – visitors of a certain government website. The funniest thing is that the deeper people go in their browsing, the more they prefer viewing porn to traditional relationships. "Sorry" for always bringing up this topic, but I actually have very good relations with "Pornhub," and it’s always very interesting research, because it’s a topic that seems forbidden but reveals a lot about a person. And the resulting points about traffic return... We'll remember about "Pornhub" later!
What is considered personal data, and is it possible to unlock an iPhone with a 3D face model?
My favorite topic is circumventing personal data laws. If you read the technical documentation of the same "Facebook," which provided some internal documents (for example, in court), you won't find any mention of face recognition or voice analysis. There will be very complex formulations that no qualified lawyer would find within the legislation. In Russia, it works pretty much the same way – let me show you something right now.

What do you see here? Any reasonable person would say it's a face. By the way, this is Sasha Grey, I believe. Legally, however, it's a matrix of some three-dimensional points, of which there are 300,000 here. Whether this is good or bad, by law, it is not considered personal data. In general, the Russian Federal Service for Supervision of Communications, Information Technology, and Mass Media does not consider a single photograph as personal data – it considers it personal data only if there is something else nearby (for example, a full name or phone number), and by itself, this photograph is worth nothing. Once the law on biometrics was introduced, and biometric data was equated to personal data (very roughly speaking), everyone immediately began saying: this is not biometric data, it's an array of points! Especially considering that if you take a direct or inverse Fourier transform of this array of points, you can't anonymize a person back from this transformation, but you can identify them. Theoretically, this law does not violate anything.
I also conducted another study: this algorithm constructs a three-dimensional reconstruction of a face from open sources – we take an Instagram account and can then print a little face on a 3D printer. By the way, if anyone is interested, I have a link available; if someone wants to unlock someone’s iPhone... Just joking – iPhones can’t be unlocked; the quality is reduced.

A closed profile is a plus for security.
This is the first point, and the second... I have already touched on the fact that information is mainly obtained from the user's environment. I drew this picture in 2017: the average user of Russian social networks is inside, with an average of 200-300 friends, their friends, and their friends' friends.

Thanks to social networks for introducing the algorithms of 'smart' e-feeds, supposedly to increase the likelihood of your encounter with interesting content. At any random moment, this number of people can see the content you produce, even if your account is limited only to the top levels of privacy (only for friends' friends, and so on). Here are the friends of friends:

If someone thinks that when they choose to see 'friends of friends' in 'My posts' on VK, three degrees of separation means about 800 thousand people, which is not insignificant but depends on your content. Perhaps you are streaming inappropriate content, and all these friends of friends may interact with that content. Someone might repost something somewhere; everyone has a feed of likes, which will likely be canceled because it’s not very appealing. Therefore, at any moment, the content can reach somewhere.
VK launched super-private profiles last year, but very few people have used them (I won't say how many, but it’s small!). Perhaps someday people will figure it out – I genuinely hope for that. All research is constantly aimed at helping people understand the scale of the problems. Because as long as no one personally experiences something terrible, they will never think about it. Let’s move on.
Government agencies don't know what personal data is and are not in a hurry to provide a definition.
Any legal expert in the field of personal data will always say this: you should never combine different sources of data because you have emails here (which are one kind of personal data with some anonymized identifiers), and full names there... If you combine them all, they can become personal data. In general, it would be right to address this topic first, but I think you are already immersed in it and are aware, maybe of how the law works.

In reality, no one knows what personal data is. It's an important concept! When I go to government agencies, I say, 'A bottle of cognac for the one who can tell me what personal data is.' And no one can say anything. Why? Not because they are stupid, but because no one wants to take responsibility. Because if Roskomnadzor says that this is personal data, tomorrow someone will do something, and they will be at fault; and they are executive authorities and really shouldn’t be held accountable for anything.
The essence is that the law clearly states that personal data is information that can identify an individual. An example is given: full name, home address, phone number. But we know that a person can also be identified by how they interact with buttons, how they engage with the interface, and through other indirect parameters. If anyone is interested: in almost every field, there are numerous loopholes.
Identifiers that reveal us
For instance, everyone started placing dots to capture MAC addresses (have you encountered this?)—smart (or perhaps greedy) manufacturers of mobile equipment, like Apple and Google, quickly introduced algorithms that generate random MAC addresses so that you cannot be identified while walking around the city and sending your MAC address to everyone. But the clever folks took it a step further.
For example, you can obtain a mobile operator's license; by getting a mobile operator's license, you gain access to a thing called the SS7 protocol, which allows you to see some mobile operators' spectrum; there are numerous identifiers there that are not considered personal data. Previously this was the IMEI, and now, quite literally, someone has picked up the idea and decided to establish a unified database of these 'IMEIs' in Russia. It seems to exist, but still.

There are also many identifiers—like the IMCI (mobile equipment identifier)—which are neither personal data nor tied to any other items and, accordingly, can be stored without any legal repercussions, and later exchanged with someone to communicate with a person.
The culture of working with personal data is at a low level
In general, the essence is that everyone is now very concerned about merging data from one source to another, and most companies that do this merging sometimes don't even think about it. For example, a bank comes, signs a non-disclosure agreement with a company that does scoring, and dumps 100,000 of its clients' data onto them...
And not always does this bank's agreement contain a clause about transferring data to third parties. These clients did something to expedite their processes, and it's unclear where this database went or didn’t go—as most companies in Russia lack a culture of data deletion... that 'Excel' is bound to be somewhere on a secretary's computer lingering.
Our data can be sold with every purchase in the store.
There are many schemes that seem somewhat legal (meaning they are legal). For example, the following story: out of the 15 largest Russian banks, only two are actually SMS gateways—'Tinkoff' and 'Alfa', meaning they send their own SMS messages. The other banks use SMS gateways to send messages to end clients. These SMS gateways almost always have the right to analyze content (for safety purposes and their own conclusions) to later sell aggregated statistics. These SMS gateways are 'friends' with fiscal data operators who handle receipts.

And it results in the following: you arrive at the checkout, the fiscal data operator (whether or not you provided your phone number – it’s somehow linked there)... you receive an SMS at your phone number, and the gateway for these messages sees the last 4 digits of your card and phone number. We know at what moment you made a transaction from the fiscal data operator, and in the SMS messages, we know (now) which number received the information about the deduction of a certain amount from the last four digits of the card. The last four digits of the card do not identify you, they don’t violate the law, because you cannot be de-anonymized by them; the transaction amount cannot either.
But if you've agreed with the fiscal data operator—you know within what time window (plus or minus 5 minutes) this SMS should arrive. Thus, you are quickly linked in the fiscal data operator's system to your phone number, and your phone number is connected to advertising identifiers, basically everything and anything. So later they can catch up with you: you go to a store, and then they send you some nonsense without your permission. I doubt there’s anyone in this room who has ever filed a complaint with the FAS about spam. Probably not... Except for me, I guess.
Paperwork is an archaic but effective way to fight for your rights.
This works really well. True, you will have to wait a year and a half, but the Federal Antimonopoly Service will actually conduct an investigation: who, how, to whom the data was transmitted, why, and so on.
Question from the audience (hereinafter – Q): – There is no Federal Antimonopoly Service in Belarus. This is a different country.
AK: – Yes, I understand. There must be some kind of equivalent…

Objections arise from the audience.
AK: – Okay, poor example, ‘sorry’. It doesn’t really matter. Among my friends, I don’t know anyone who even knows about the existence of such a procedure – that you can go and write, and they will continue to work on it for another year.
The second story, which is also developing rapidly in Russia, but I think you will find an equivalent in your country. I really love doing this when a government agency is not communicating well with you, like some bank or something else – you say: ‘Give me a document’. And you write on the paper: ‘According to clause 14 of Federal Law 152, I request to process personal data in written form’. I don’t know exactly how this is done in Belarus, but it must be done somehow. According to Russian laws, they cannot refuse to provide a service based on this.
I even know many people who have sent similar requests to Mail.ru asking for their personal data to be accounted for in written form. Mail.ru resisted this for a long time. I even know a developer from Yandex, who was joked about: they deleted his account on VK and sent him a bunch of printed screenshots, saying they would send him screenshots every time he wanted to update his page.
Funny, but nevertheless this is a real alternative if someone is genuinely concerned about their data, on one hand… On the other hand, the same Russian Communications Supervision Service told me that this personal data processing agreement is formal, and the law provides for several other options to give this consent. For example, I was invited here to an event, and if, for instance, Human Constanta doesn’t need to conclude a personal data processing agreement with me according to Russian laws (because the very fact that I came and agreed to speak constitutes consent to the processing of personal data), still everyone takes these paper permissions. But the Russian Communications Supervision Service told me such things, that it's not guaranteed they won’t eventually drop this requirement.
I hope that a single operator of personal data will never be created in Russia, God forbid, because the only thing worse than putting all personal data in one basket is putting it in a government basket. Because who knows what will happen with all of this afterwards.
Companies exchange personal data, and the laws weakly regulate this.
Most companies exchange certain data or identifiers with each other. It could be a store with a bank, and then the bank with a social network, the social network – with something else… And eventually, these people have a critical mass of knowledge that can somehow be used, and all this knowledge is currently trying to be retained on their side. Nevertheless, it still ends up in some advertising traffic or somewhere else.

The transfer of data to third parties is the most amusing thing possible because the laws do not specify who these third parties are, and who should be considered 'thirds' at all. This is, by the way, a very common phrase among American lawyers – they call it Third parties – who do you consider third parties: a grandmother, a great-grandmother? There was even a precedent in America when someone’s data was disclosed, the person sued, and they proved that this individual is connected to the data owner through several friends – after a number of handshakes, they cited some strange sociological studies – thus proving that these people cannot be considered third parties to each other. Funny. But the fact of such data transfer is very common.
Even if you visit a website with a counter for identification – this counter has the right to send this traffic data somewhere (to 'Clickstream', for example, or to the owners of advertising platforms, or even to 'Pornhub'). If any of you are web developers, check how many tracking pixels are on the 'Pornhub' site. You just visit – an enormous amount of JavaScript loads to 'improve' the site's performance. In reality, there are cross-domain cookies being set, and who knows what else, because this information is always highly valued in the 'Clickstream' market.

Facebook is evasive and has no intention of removing its mask.
Of course, none of the major players ever tell anyone who and how they sell data. Because of this, for example, Europe is currently trying to sue Facebook. After the introduction of GDPR, the European Union is trying to force Facebook to disclose its algorithms for reselling data to third parties.
Facebook does not do this and publicly claims that it does not, because they are a 'corporation of the world' (I am quoting from a letter they sent me), they are 'against the malicious use of technology' (especially if you are selling facial recognition to the Kremlin). In general, the essence is that Facebook does this somewhat unfairly: its main goal and what will happen once such a mechanism is revealed - one can really calculate the profitability of advertising, one can understand the actual cost of advertisements.
Conditionally, if Facebook currently tells you that the cost of an ad impression is 5 rubles, and they sell it to you for 3 (and, like, two rubles remain with us), and they supposedly earn 5% profit from these ad impressions. In reality, it's not 5%, but 505, because if this algorithm comes to light (who and how many times Facebook has passed on clickstream data, visit data, pixel data to various ad networks), it will turn out they make much more money than they say. And the issue here is not the money itself, but that the click cost is one ruble, but in reality, it's a fraction of a penny.
In general, the point is that everyone is trying to conceal such transfers, whether it’s advertising or non-advertising traffic, but it exists. Unfortunately, you cannot legally find out this information because companies are private, and everything they have internally is their private right and commercial secret. But such stories often surface there.
Drug traffickers are predictable and get 'caught' on Avito.
The last image from this presentation. It's funny, and its essence is that there are certain categories of people who care a lot about their personal data. And this is good, actually! This example is about such a category of people as drug traffickers. It seems that these are people who should be very concerned about their personal data...

This is a study that was conducted at the beginning of this year under the supervision of competent authorities. Yes, this is a script that was funded to buy drugs in Telegram and on Tor, but only from individuals who could be identified.
In fact, almost all drug dealers in Moscow get caught because their phone numbers are not found in any open sources, but sooner or later they will sell something on Avito, which will allow us to determine their approximate location. The essence is that the red dots represent where people live, and the green ones indicate where they go to leave what you know. This was part of an algorithm that predicted the deployment of patrol services, but these guys from Moscow always try to find a diagonal route to stay further away.
They believe that if they live in the top left, they should go to the top right, where they think they will never be found. I'm mentioning this because if you are trying to hide from omnipresent algorithms, the most effective option is to change your behavior: install some kind of 'guest' tool to randomize visits and holdings, and so on. There are even algorithms and plugins that change browser sizes by a couple of pixels to prevent your browser's fingerprint from being counted and to make it harder to identify you.
That's all from me. If you have any questions, let's discuss. Here’s a link to the presentation.
Question from the audience (Q): – Please tell us, from the perspective of using Tor and tracking traffic… would you recommend it?

It's hard to hide, but it is possible.
AK: – "Tor"? There’s no "Tor" in any form. I don't really know about Belarus – in Russia, under no circumstances should you go there, because practically all verified "greynodes" suddenly add some packages to your traffic. I don't know what those are, but if you look: there are "nodes" that mark traffic – it’s unclear who does this, for what purposes – but someone is marking it in the header so that it can be understood later. Right now, all traffic in Russia is stored, even if it's stored in encrypted form, and everyone is trolling about the "Yarovaya Package" concerning the encrypted traffic, but it remains marked, meaning it can't be decrypted and used...

Z: – In Europe, it's been stored for a long time, probably ten years.
AK: – Yes, I understand. Everyone laughs at this – like, you're storing HTTPS that is impossible to read. The content can't be read, but you can determine where the packets come from using certain algorithms – by the weight of the packets, by their length, and so on. And when you have all providers under control, with all the backbone equipment and all passports... In general, you understand what I'm talking about?
Z: – Which browser do you recommend using?
AK: – For "Tor"?
Z: – No, not at all.
AK: – Well, I don’t know. I actually use Chrome, but only because the developer tools there are the most convenient. If I ever need to go somewhere, I’ll go to some café. However, you shouldn’t log in using a real SIM card there.

Z: – You mentioned some students. Do you teach somewhere or run any courses?
AK: – Yes, we have master's programs in data journalism. We teach journalists to gather and analyze data – they periodically conduct such studies.
There are no safe applications.
Z: – It’s unsafe to communicate with friends on "Facebook" or "VKontakte" because you might receive contextual ads later. How can we increase security?
AK: The question is what you consider an acceptable level of security. Essentially, the term 'safe' is subjective. It depends on what you deem acceptable. Some people find it acceptable to share intimate photos via Facebook, while certain intelligence officers believe that anything said out loud, even to the closest person, is inherently unsafe. If you don’t want social media to find out about something, then yes – it’s better not to write about it. I don’t know of any safe applications. I fear that they don’t exist. And from a monetary perspective, it’s understandable that any app owner needs to monetize, even if their app or media outlet is free. It may seem free, but it still needs to generate income. Therefore, nothing is completely safe. You have to decide for yourself what is acceptable.

Z: What do you use?
AK: Social media?
Z: From messengers.
AK: From messengers, I use the main state messenger of the Russian Federation – Telegram.

Z: Is Viber safe?
AK: Listen, I don’t really know much about messengers. Honestly, I don’t believe in security or anything like that, because that would probably be very strange. Although Telegram is supposedly open source, and its encryption algorithms are disclosed. But that's a nuanced matter, because while the client is open-source, nobody has seen the servers. I don’t think so: Viber has a lot of spam, bots, and so on. Who knows? I feel like it doesn’t work very well.
Who is more dangerous – corporations or the government?
Host (H): I have a question for you. Look, you’ve hinted at this several times – about the fact that the government... Too much data isn’t good... Corporations have too much data. Well, that’s just life, right? So, who should we be more afraid of – corporations or the government? Where are the pitfalls?

AK: – This is a very complicated question. It's on the edge. A difficult ethical barrier. If a person has nothing to fear, if they haven't broken the law, why would they need privacy? Although I don't believe that – this is what the state thinks. There might be some grain of truth in that. Honestly, I'm most afraid of hackers – something like that. In fact, the most shocking thing I've seen in my life (from all this topic): about a year and a half ago, a pedophile was caught in the Moscow region, and during the investigation, they found on his computer several self-taught guides on 'Python,' scripts, API VK. He was collecting accounts of girls, analyzing who among them was nearby, gathering content that they... In short, you get it. That's the most horrifying thing I've seen. And what I really fear is that at some point, someone will pull off something like that.
Another little off-topic note: The European Organization for Security reported last year that the number of bank account thefts has increased by about 20 to 25 percent, due to hacks on secret questions. Just think about your secret question at the bank, and consider if I could find the answer from publicly available sources. If your mother's maiden name is there or your favorite dish... In general, people analyzed accounts, based on that they figured out the nickname of the beloved pet – something like that...
Z: – You mentioned that companies and corporations collect necessary information using algorithms? You must know how?
AK: – There was a movement of people who at one point ran photos through a special filter to disrupt image analysis, so those people couldn't be identified later. I gave you the example that 'Facebook' fought against encrypted messages. And if this thing becomes widespread, social networks will surely fight against it. Plus, pattern recognition is working very well now, and it borders on that sufficient level to 'break' this photograph (in order to 'break' the algorithm that recognizes these patterns) – most likely, nothing will be clear on it anymore.
All kinds of glitch filters work well if there is a strong direct shift across half of the photo. Your account will then acquire all the colors of LSD. Theoretically, I don't consider it very scary if, for example, Facebook knows what car I drive – probably as long as I don’t log into my car through Facebook.
The right to be forgotten works, but not on the internet.
Z: – Have you ever encountered a user who forced you to respect them enough to delete or access their data? You deal with large data sets, you surely notify about this. People can reach out to you. What percentage?

AK: – I’ll explain now. This will actually be interesting. Let me calculate how many people will log in because after the event, usually 15-20% log in to fill out the data deletion form — that happens. It's really about 7-8% of closed accounts, which we don’t analyze, and around 5 people out of a thousand who ask to delete their data. That's very little, even by my humble estimation.
The problem here is as follows: there is something called the right to be forgotten. But the right to be forgotten, at least in Russia, is legally applied only to search engines. It is explicitly stated: search engines. And even then, it’s only about deleting links to materials, not the materials themselves. In reality, to remove something from the internet, you would have to bypass all these sources, so I fundamentally don’t believe in it. We try to warn users that they need to think carefully before publishing.
Currently, this percentage is very low — 5-7 people out of thousands. By the way, regarding the right to be forgotten: everyone knows the cool case of "Sechin vs. RBC". The right to be forgotten worked, the article was deleted, but it still exists everywhere. You understand that if something once made it to the internet, it will never disappear from there.
Users are deleted, but they are identified by typical behavior.
Z: – Don’t you think that people who delete their accounts and try to become a "black hole" will be at a disadvantage compared to other economic agents?

AK: – Most likely, yes — this situation will be unfavorable for them. There are plenty of discounts and offers that depend on them. But, theoretically, if someone deletes their account now… It's popular among extremists to delete an account and create a fake one while still interacting with the same content — this person can still be identified (especially if it's within the same social network, from the same computer — that's a whole other question); simply by their content consumption patterns, this person can be found if that’s the objective.
I hope that within the next five years, some technology will emerge to monetize this data, where people can actually be paid — you pay yourself, and we won’t use your data. I think that if any platform like Instagram introduces a paid subscription, no one will take it up, so the alternative would be to pay users for their data. But that’s not very soon because the lobbying by those powerful corporate guys won’t allow such a law to pass, although it would be cool. The issue is that it’s impossible to assess the actual value of one person's data at any given moment in time.
Facebook is a leaky platform.
Z: – Good afternoon. Recently, there was news that Facebook intends to integrate all its projects, including Instagram, Facebook, WhatsApp, and so on. From your perspective, considering personal data, now that these programs are somewhat separate on my smartphone, but they still belong to Facebook… What will happen next?

AK: – I understand. Legally, they belong to Facebook, and it can integrate them within itself without oversight, so I think nothing will change. The only difference is that now it’s enough to hack one app to gain access to everything. And Facebook… I hope they’re monitoring this. They’re alarmingly leaky all over.

Recently, there has been a lot of information about data leaks from Facebook. This didn't happen because Facebook suddenly started losing data, but because GDPR now requires the company to notify in advance. The biggest penalty arises if a leak occurs and the company remains silent, which is why Facebook is discussing it now. This does not mean that there were no data leaks before.
Z: – Hello. I have a question regarding data storage. Now every country is implementing laws regarding the storage of citizens' data within that country's territory. What condition must be met to comply with this law for some international application? For example, Facebook: it has one database...

How can these conditions be met?
AK: – Listen, legally, you only need to rent a server in that country and store something on it. The problem is that there is no competent regulatory authority. Facebook's data is not stored in Russia. Roskomnadzor is fighting with it… Facebook has some servers where the interface of Facebook is stored, and it's impossible to verify where the data is actually located and how it is synchronized.
Z: – Check the traffic?

AK: – Check the traffic? Yes. But the traffic can ultimately go to some major point. Plus, there might be something like a VPN or other connections between the servers. Theoretically, it's impossible to control what, for instance, a system administrator might do on that server at some point and whether they might take something from there. This law is not made for data protection but to ensure companies open offices, pay taxes, and physically store data within the country. But in my opinion, this is quite a strange initiative, to be honest.
Z: – So it’s enough to simply check the interface?
AK: Someone can come to check that your data is stored there. But you can present some Excel sheet, and no one will be able to verify it; it’s unlikely anyone will check. Currently, they just look at IP addresses: whether the IP address linked to the domain is located within the country — they don't check further. Now, probably, someone will come to check on me.
There are no services you can trust 100%, but decent people have nothing to fear.
Z: – There’s this news, shared widely: a guy from Microsoft posted and created a service to check your…
AK: – Something like: have your passwords been leaked? In reality, after leaks on Facebook, Facebook always launches some backup sites where you can check if your information is in that database — again, GDPR requires this. So, if you don’t implement such a measure, it won’t end well for you. Hence, everyone represents these projects as 'this is our initiative'; in fact, the law requires it. It’s a really cool feature, but I wouldn’t trust such verification services if you need to submit anything more complex than your password, because many people have the same passwords.
Z: – You just enter an email there, and it will tell you how many times it has been compromised...
AK: – I actually don’t trust such things, because it's very easy to link you to this browser, to a real account. Especially if you’re using services from the same people who launched this site. It’s like last year when Facebook sent: if your intimate photos leaked on Facebook, send them to us, and we will check where they were mentioned.
I don’t know what PR nightmare this is and who thought of it in Facebook, but it really happened. They wanted to compare if anyone sent your nude pictures in private messages. In principle, this has good intentions, but it's incredibly strange. I wouldn’t trust it.
Z: – And one more question. For the average user, how high are the risks of leaks? The risks of damage from leaks.

AK: – I understand you. It depends on what kind of data is stored. I think the risks aren’t very high. The worst case is if emails and passwords leak somewhere, and you have that password used everywhere – then yes. I generally believe that users have little to fear. But, of course, unless they're storing something gruesome in their Google Mail. There have been many examples.
The most famous story is about ‘Google’, when a girl was kidnapped in Utah, and they couldn’t find her. At one point, the kidnappers sent her pictures in a zipped attachment. While scanning this attachment, ‘Google’ discovered signs of child pornography. They found everyone involved. Yet, the kidnappers somehow managed to sue ‘Google’ for violating their privacy. This litigation took quite a while. Nevertheless, I believe that an average user has nothing to fear if they don’t, say, post their passport publicly. It’s a dual story—depending on what kind of data and what kind of user it is. Maybe now it’s nothing serious, but in 15 years, if they become some kind of official, then certain materials might resurface.
How is it working with the government?
Z: – Thank you. You spoke a little about doing research for the government, public authorities, services, and working with them. Can you elaborate a bit on some current projects? Even more, if you could, about… Two questions: first – current projects, and second – have there been any such proposals from public services…
AK: – Indecent!

Z: – Yes. When you thought: maybe it’s not worth doing this.
AK: – I will tell you. I tell everyone about this. We had a long argument on ‘Twitter’ with this person. From Milonov’s team, I once received a question about finding teachers who watch gay porn. We immediately said no. But such requests do come, and very often they are connected to some opposition figures, protests. We don’t engage in such nonsense; we’re already getting enough backlash. I’m not ashamed of that.
Our policy regarding the government is the following: we develop software for three-dimensional reconstruction, facial recognition, data analysis. What exactly they do is very hard to say, but among the models – it’s crime forecasting, that related to state security within the city, tracking movement of people, geomarketing, and so on. From placing objects in the urban environment to identifying pedophiles, rapists, maniacs, and all sorts of unsavory individuals.
Honestly, we haven't dealt with any opposition figures. Maybe, they don't tell us this to our face. In reality, it's a very big problem—cooperation with the government, because they don't always explain what the task is. They tell you: create software for identifying housewives, but they actually want to do something entirely different with it—everything breaks down in the process.
Plus, the government is a very interesting and strange client who constantly tries to insert trivialities into your research, and often their approaches and understanding of machine learning are quite superficial. For example, I have a separate lecture on the mistakes of machine learning. I always use the case when we were developing a crime prediction system in the Moscow region. The client said: increase the coefficient fourfold for places where watermelons are sold. But it turned out that watermelon sales locations are not at all criminal. This is just a mistake of someone inserting their thoughts.
In short, the government is a fun client; there are many interesting tasks. Most of them boil down to similar predictive models. More often than not, it's about some urban infrastructure.
Z: Are there any sources where I can keep track of your research? There's a lot of information. As I understand it, much of it is still left behind. Your pages, and other things...
AK: I don't have personal pages.
Z: I suppose your Facebook account has been closed by now?
AK: About four months ago, there was a story: they all sent us these big letters saying, 'You are monsters, selling everything to the Kremlin, breaking all Facebook rules.' They even sent a letter to my dog: 'Hello, Mars Blue Corgi, you are collecting data!' and so on. Listen, we are rebranding right now. In a week or two, our website will be updated. You can keep an eye on that. But we are just very lazy about it, frankly.
How can you determine the reliability of a VPN?
Z: You mentioned that you would go into a café without identifying yourself with your phone number. But with which one?

AK: – You can't speak under someone else's identity, because that calls for a violation of identification regulations. No, no, no. I'm joking. Nowadays, almost all cafes identify everything – it's not just a phone number; there are tons of pixels, device identification, MAC addresses, and who knows what else, for purposes ranging from advertising to operational investigative activities. So you need to be very careful with such things. Not only can you write something, but something can also be written from your device, and then something might happen.
You may have seen a story about how investigations are currently being conducted into the renting of Facebook accounts, including in Belarus, supposedly for casino advertising. But in reality, it's unclear what they are actually used for, and access to the computer is granted. Such things need to be avoided as much as possible. If you decide to write something anonymously from somewhere... I would go to a cafe and turn on some great VPN. But actually (again, I’m not pointing fingers), when you're using a VPN, check who owns that VPN, which company it belongs to, and so on. Because most VPN market players aren't exactly the best guys.
Well, okay, that's not important in Belarus. In Russia, a good VPN is checked by whether azino777 is blocked or not. Because if it’s not, there's a high probability that this VPN service will be shut down within a week. In general, check everything.
About the auto-deletion of messages
Z: – You talked so much about personal messages that social networks read... But, for example, Facebook has secret personal messages that can be set (in addition to the fact that they are also encrypted) for destruction. How would you comment on that?
AK: – I can't comment at all. Firstly, I’m not a super-professional in cryptography, and secondly, the problem here is that nobody has seen Facebook's servers; nobody knows how everything works there. Hypothetically, some specification states that it's end-to-end encryption, but it may not be like that, or it can be end-to-end but with some flaws or something else. Such a feature makes sense to use if you are afraid that the person to whom you sent it might try to do something at some point.
Telegram has a convenient feature for sending intimate photos that self-destruct: when you try to take a screenshot, it automatically deletes the photo. The iPhone has a screen recording feature, and you can also record video from the screen, and so on… I often receive materials with this feature (self-destruction) – I never understand why. I can just download it right away! It’s entirely up to you.
Social rating in China: myths, realities, prospects
Q: - I actually abuse it a little, even though I don't need a VPN (by the way, we have a reliable VPN). And the question of ethics comes up. We have a wonderful friend from Kazakhstan, we also brought him in for a lecture. One time we were sitting at a conference where different things were discussed, and he said (and he is involved in cybersecurity, meaning pure engineering security, a person interested in technical solutions): "I just returned from China. They have this cool thing going on – social rating." By the way, have you researched anything on this topic, how it works for them?

AK: - We sell scoring in Russia; I know a lot about it.
Q: - So, I have a question: could you tell us more about what might await all of us in the future? But there's also the question of ethics. He spoke so cheerfully: "Interesting engineering solution!" Do you have your own code of ethics?
AK: - Yes, by the way, we do. We introduced it two years ago – precisely after the story with Milonov, we decided to somehow rank these projects. Going back to the rating: this is one of the super popular questions because the media heavily demonize the whole issue – claiming that people are not allowed to leave the country, lasers from the moon kill them. I’m presenting, again, engineering aspects...
If you start digging into this story and look at the parameters that go into this social rating, you'll understand: it includes hidden alimony, criminal records, credit history—meaning from an engineering perspective it's really impressive. You live within the law, you live well—you're given a low interest rate on loans. You have an important social job (like a teacher)—you’re provided quality housing. At first, everyone was confused because stories leaked that if you write negatively about the president, your rating would be lowered. Although there was no evidence for this. In defense of the rating, I will say that the algorithm has never been seen, and no one knows which parameters are actually used.
Then there was a story that more than a million people were not allowed to travel abroad; they were prohibited from leaving. Actually, this is not quite an accurate formulation. When you get a visa (for example, to Europe), the visa is issued based on '70 euros a day' (something like that); if you don’t provide proof of income, you won’t get the visa. In China, the local Foreign Ministry decided to go a bit further: they simply warned people right away that those with insufficient funds would not have enough money if they wanted to travel abroad. Consequently, this was later directed into the concept that the poor are not allowed to travel abroad. This is a complex ethical issue that borders on a presumption of guilt or innocence, but in reality, I cannot assess it.
People kill, not weapons
The main thing to understand is this: all these algorithms that society condemns—the problem is not in the algorithms. The algorithms merely enabled the rapid analysis of a large 'volume' of people, and this social issue was brought to the forefront. For example, the Microsoft bot that was trained on tweets and became racist—it’s not the bot's fault, but the tweets it read. Or a company that decides to build a model of the ideal employee by analyzing the current ones, only to find that it’s a white, male individual with a higher education.
This is not a model – racist, sexist, or something else; these are people who hired those individuals (whether they were right or wrong – it doesn't matter). Everything borders on the idea that artificial intelligence is evil, bad, and will destroy the world, but in reality... For example, if the Russian government were to pass a law that denies free education to opposition members, and they write software that identifies and deprives them of this education – the algorithm wouldn't be to blame. Although no one supports this concept of mine, because when I say that it’s not weapons that kill people, but people, I get called a 'fascist,' and so on.
Overall, this is a really cool engineering solution. One needs to understand why this won't be implemented in Russia, for example. You [in Belarus] won’t have this because you’re a European state, everything is fine for you. In Russia, it won’t happen for many reasons: first of all, we don’t have the same level of trust in law enforcement as in China; we are far from having the same level of digitalization. Why did it work in China? Because the government there has digital medicine, digital insurance, digital policing. And someone clever thought: let’s put all this together and make it – essentially, it's a loyalty program. There are more perks than 'non-perks'.
Therefore, yes – I think this won’t be implemented in Russia. First, it’s necessary to digitize the entire Ministry of Health (and that’s a 50-year task) – someone has to dedicate their life to this, but naturally, no one will do it. On the other hand, Russian banks are leading in the world in terms of scoring people; they are doing all sorts of things: 'Oh, you’re a guy? You like young women? Here’s a credit card for your mistress.' Everything is very advanced there. For instance, in America, similar scoring is practically banned everywhere because there are laws that require banks to explain to you why: 'Ah! Because the company Social Data Hub has stored history for 10 years, and here’s what it has revealed about you!' And then you can sue both parties! We don’t have such stories here.
Why is the statistics being kept silent?
I generally support scoring, provided it isn't some sort of 'totalitarian' scheme. The real issue is that it's impossible to predict or assess. This is the most challenging aspect of the ethics of big data – forecasting the social impact that will be felt in 15 years. For instance, I've been long pleading with the prosecutor's office to open up crime data. Criminal statistics are one of the cornerstones of any statistics; everyone wants that data. However, in Russia, they do not disclose criminal statistics for a very simple reason: they fear disrupting the demographics within cities. They believe people will stop living in certain areas, and even within the city, everything will somehow redistribute. For the same reason, they do not reveal the statistics for the Unified State Exam (EGE) – you understand that people will choose which schools to attend based on that data.

Perhaps that's right, perhaps it's not, but there have been many initiatives… For example, Yandex, at one point (again, based on 'rumors', I haven't seen it, I don't know), decided to include in their real estate forecasting model the number of attacks on taxi drivers, essentially using that as a metric for crime levels by counting complaints from taxi drivers about harassment, threats, and so on. They quickly shut that down internally to avoid pursuing such matters.
Z: – You interact with students and your audience in your country, our country. Have you noticed from the number of questions from the audience that we are still at that stage of development where we think we need privacy, that we can hide from someone, protect our data without providing it, concealing it, encrypting it? If the European Union has already moved to the next stage, the stage of privacy which involves control over data – making sure that anyone who collects your data gives you effective control over it… In terms of demographics, across social strata – which category of citizens has more obviously moved to the second stage, and who is still largely stuck on the first?
Who is most concerned about the security of personal data?
AK: The vast majority... I would say: everyone doesn't care! This is concerning top managers right now. The cities in Russia are Moscow and St. Petersburg. The active center consists of IT specialists, designers, and creative professions, anyone who can filter content, gain new knowledge, and has a high level of interest in international issues. Mainly this involves top managers; yes, IT specialists (excluding security experts); bankers – essentially all the people who could be affected by data leaks.
For example, if the data of some housewife from Kaluga is stolen: it’s unlikely her life will change significantly if someone steals access to her Gmail, where she stores her access to TV shows. The issue is that the law protects everyone equally, and that's correct because... from the legal standpoint, everyone is equal – ha-ha... but the main point is that it’s impossible to determine how much anyone's data will be worth until it's lost – unfortunately, it's very hard to predict. But generally, this is a category of citizens.
Phone – in foil!
The only time in my life I saw a blanket storage of everything and anything was in two companies. One is the largest integrator in information security: everything there is even glued shut with tape inside the office; and the people there are the same – I met someone there who had their phone in a little foil bag. I found out there are companies that sell such special bags. The second time I saw a similar situation was at Bloomberg among employees: we were standing in the smoking area, and someone was taking a photo somewhere, and one of them said, 'Hey, make sure we aren't visible in the background!' I thought, 'Wow, that's something!'
"Better us than the FSB"
I wouldn't want to say this is less than one percent of the population, but unfortunately, in the general mass, practically everyone doesn't care. But on the other hand, I have a controversial service for monitoring the actions of minors (we launched it a while ago under the slogan 'Better us than the FSB') to warn parents if a minor is doing something inappropriate before our algorithm, installed somewhere, sends someone to them.
When verifying a child, you need to send a scan of the passport (this is generally normal practice), but we mentioned that you can cut out the passport number, as we are not interested in that; we only need your photo, the hologram, and your name. And practically 100% of people – well, about 95 out of 100 passports – carefully trimmed these numbers in Photoshop and sent only the necessary part. So they understood – ah, since they don't need it, then I don't need to send it. In my opinion, this is a real breakthrough that has been prompted by their distrust of us.
Z: – The sample is a specific one. The people who reach out are already advanced.
People do not want to be monitored, but they do not read the agreements.
AK: – Yes. And the second similar thing: at the end of last year, we launched a dating application for testing (we will soon relaunch it). There was a control group of 100,000 people. And according to GDPR approaches in the personal account, there were 15 checkboxes – I give permission for analyzing interaction with the interface, for access to my demographics, for access to the three-dimensional reconstruction of the face, for access to my personal messages, and so on. We detailed all possible accesses. There’s even some statistics on what people checked. 98% left all checkboxes selected by default (despite the fact that they logged onto this page and saw all of it, they just didn't care), but it was interesting to analyze these 2% to see what was a priority for them.
Everyone removed the permission for access to personal messages and practically all removed the permission for access to sexual test data (what they like, what they filled out, their kinks – just kidding). But this pushed people into this, nudged them: the interface tells them – read this carefully, it allows scrolling through the agreement to the end. But this was done solely because it was a research project, and everyone was warned. No company, including ours, when we release this application to the public, will force a person to read this message to the end because... well, sorry, that's just how it works.
Given that they came to us knowing what the company does, knowing that they entered a service that would offer them candidates based on their porn preferences – even based on that, only 2% read these checkboxes and did something at all. And practically none of them removed the checkbox for "Access to traffic and data on visits to other web pages." Mostly, they were concerned about personal messages.
Nudity and arrests for likes – interesting laws of the brotherly republics
Z: – I have a question about data protection. You can carry your phone in foil, pretend it’s not there… Then it turns out that you seem to be saving it, but then you have to hand over your data to the state because they demand it from you, and you can't… And it turns out that state contractors are all full of holes. And in Belarus, there’s also such a norm: if I check the security of my personal data (fix something and gain access to it), I immediately become a criminal. The same article was used to accuse journalists in the 'BelTa case' of having unauthorized access to data (you can read about it yourself). So, my question is: are such restrictions an effective measure for privacy, and for the security of private data in general?

AK: – I understand. There are many very interesting laws in Belarus. I just found out recently… I joke about transmitting nudity, but it turns out that it is actually prohibited there.
Z: – Demonstration is prohibited!
AK: – This is rather strange.
Z: – You can watch but can’t transmit, you can’t like. You can’t watch together!

AK: – I’ll answer your question. I’ll return to the topic of 'being arrested for likes' in Moscow. In Russia, this is the number one topic. I don’t know how it is in Belarus, but honestly, the state… If you analyze the statistics, in Moscow, 95 out of 100 arrests for likes happen when people complain about others, someone files a complaint with the prosecutor against another person. The state very rarely initiates such cases. It seems to me that this law is absolutely absurd. I don’t know any real criminal who has been jailed for this. But this measure is used to at least pin something on a person. It seems very strange to me. I think this will be canceled someday.
Z: – This is called keeping someone under a dome.

AK: Well, okay… I can't really say. I'm not exactly a government monster, but my perception has been somewhat altered, you know, by the people who come to us and say, "I’ve lost my child, help me find them." I say, "I can’t do anything without a court order." You look at those parents who would give anything in their lives, would provide access to any data – just to solve their problem. So it's very hard for me to have such a discussion: on one hand, I think the state does the right thing when it captures real people, but on the other hand, granting uncontrolled access is a terrible story altogether.
Getting back to your thing, sorry for getting sidetracked. I don’t believe in foil bags at all. Having a mobile phone wrapped in foil is just silly. What’s the point? So that the phone doesn’t connect to Wi-Fi? It’s easier just to turn it off. So that the mobile operator can’t identify you? They can still trilaterate the signal somehow. For me, the only effective security measures are a protected storage system, like a local network – maybe in an apartment, where you can store something.
Z: The question here is about legislation. Is the legislation repressive towards a person who wants to check their own data?

AK: I see, yes. I didn't even know about that thing, so I can't give you a definite answer. There’s nothing like that in Russia, although it's all very complicated there. Perhaps you could consult qualified lawyers, and maybe there’s some loophole – maybe you could submit something to a European court… No? I can't tell you about that. My knowledge of law is superficial, at the level of a company executive. I know what not to do so that no one says anything to you. That's, of course, very sad.
Z: What I mean is that in other countries (for example, in the States) it's standard practice that you can test some vulnerability and then report it, but not disclose it.
AK: Yes, "bug bounty". I understand, that exists.
Z: And companies have no mechanism to get rid of you, because it’s cheaper.

AK: This issue also exists at the legal level. It depends on how you find this vulnerability. I think that a large amount of money paid for this vulnerability in America was given under non-disclosure agreements and under threats to sue the person. I can't say for sure. We always risk this kind of thing. My employees have found similar vulnerabilities in various government applications a couple of times – I always tell them: "Send an anonymous letter rather than telling them there’s a hole there." And then some research institute that provided this service might come... I won't go on further.

You cannot check a business for honesty: if you don't like it, don’t use it.
Z: I have a question. You said you conducted an experiment – it required checking 15 boxes... Let’s say the user unchecks all the boxes. Who and how will monitor this? How can it be checked at all?
AK: Honestly, I’ll tell you: no one and no way. Seriously. The fact that you checked or unchecked the box for "Prevent ad tracking" with Google doesn't mean anything at all. Unfortunately, even when you set the restriction on indexing for search engines with VKontakte, they still index it, but just don’t show these results to certain people. This all comes down to the lack of competent bodies that cannot verify this. Plus, the companies that do this are private. Facebook's position, whether right or wrong, is clear: if you don’t like it, don’t use it.
On Regulation
Z: I have only one simple question. How do you feel about the regulation of data processing, self-regulation?

AK: As a representative of a company, I believe that the market, businesses need self-regulation. I believe that the big data association can regulate everything itself, without the government. I really do not trust government regulation and do not trust any scenarios where the government wants to store something, because every case has shown that it is very bad. Someone will inevitably stick their login and password on a yellow sticky note on the monitor and so on.

In general, I believe in self-regulation. Furthermore, I believe that in the next 5 years we will achieve a certain level of transparency. Even now, you can see this in the news, where it's very difficult for the government to lie to users, and for users to deceive the system. And this is probably a good thing. Since we have intelligence agents figuring things out from public photos.
All of this will likely lead to a decrease in the crime rate. Well, purely mathematically. If anyone is interested in discussing the reduction of crime levels, there are many conclusions that can be drawn. Overall, I am in favor of market self-regulation. Thank you!


A little advertisement 🙂
Thank you for staying with us. Do you enjoy our articles? Want to see more interesting content? Support us by placing an order or recommending us to your friends, , a unique entry-level server alternative that we have created for you: (options available with RAID1 and RAID10, up to 24 cores and up to 40GB DDR4).
Dell R730xd at half the price in the Equinix Tier IV data center in Amsterdam? Only with us in the Netherlands! Dell R420 — 2x E5-2430 2.2GHz 6C 128GB DDR3 2x960GB SSD 1Gbps 100TB — from $99! Read about how
Source: habr.com
