Уровень 0 · материалов: 5
В кластер включаются документы о технических сбоях и проблемах кибербезопасности в государственных или общественно-политических цифровых проектах, но не общих принципах защиты данных.
Общие признаки: технический анализ безопасности, утечка персональных данных, критические уязвимости ПО, цифровые государственные сервисы
Группа выше: Уязвимости российских и государственных систем
Смысл: The text aims to expose the severe lack of basic cybersecurity practices in the 'Smart Voting' project, contrasting the organizers' public assurances of security with evidence of critical technical vulnerabilities.
A technical teardown revealing critical security failures and exposed databases in the 'Smart Voting' infrastructure, contradicting public claims of high security.
Смысл: The text serves as a critical technical review of a regional government's attempt to digitize movement permits during a pandemic, illustrating how rushed development and poor security auditing can lead to system instability and the exposure of personal data.
A technical critique of Nizhny Novgorod's COVID-19 QR-permit system reveals severe bugs, data leaks, and vulnerability to phishing.
Смысл: The main idea is that a severe lack of basic security hygiene (exposed Kubernetes dashboard and secrets in ConfigMaps) left the personal data of thousands of political activists vulnerable to theft, potentially facilitating the leak of 'Smart Voting' user data.
A technical user discovered that FBK accidentally left its Kubernetes management panel and sensitive API keys open to the public via search engines, potentially leading to a massive data leak of 'Smart Voting' participants.
Смысл: The main idea is that the 'Smart Voting' project compromised user anonymity and security by using Yandex Metrica, potentially exposing sensitive political activity data to a company heavily influenced by the Russian state.
The 'Smart Voting' website's use of Yandex Metrica creates a critical security vulnerability by leaking user data to Yandex, potentially enabling state surveillance.
Смысл: The main idea is to expose the technical instability and organizational chaos behind the implementation of the election surveillance system in 2012, suggesting that the project was rushed and poorly managed.
A technician shares his experience installing election surveillance systems, detailing widespread hardware failures, software bugs, and organizational dysfunction.