{"id":5150,"date":"2024-12-17T07:21:47","date_gmt":"2024-12-17T07:21:47","guid":{"rendered":"https:\/\/filter.watch\/english\/?p=5150"},"modified":"2024-12-17T09:30:52","modified_gmt":"2024-12-17T09:30:52","slug":"investigative-report-december-iranian-messaging-apps","status":"publish","type":"post","link":"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/","title":{"rendered":"Open Technology Fund\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Iran is consistently ranked \u201cnot free\u201d in Freedom House\u2019s annual <\/span><i><span style=\"font-weight: 400;\">Freedom on the Net<\/span><\/i><span style=\"font-weight: 400;\"> research reports. The country received a dismal score of 12 (on a scale of 1 to 100, with 100 being the most free) in the <\/span><a href=\"https:\/\/freedomhouse.org\/country\/iran\/freedom-net\/2024\"><span style=\"font-weight: 400;\">2024 report<\/span><\/a><span style=\"font-weight: 400;\">, amid wide-reaching censorship and surveillance. In a bid to restrict access to the global, free internet and tightly control the domestic cyberspace, the Iranian government has blocked many foreign or independent applications, and is encouraging people in the country to use state-approved domestic apps. To increase usage, authorities are shifting essential online public services (e.g., banking, education, pension funds) to these homegrown platforms (which are often funded by the state), enabling interoperability between major Iranian messenger apps, and offering lower rates for domestic internet bandwidth while restricting international bandwidth.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">According to the Iranian government, <\/span><span style=\"font-weight: 400;\">as many as <\/span><a href=\"https:\/\/www.voanews.com\/a\/as-net-tightens-iranians-pushed-to-take-up-homegrown-apps\/7092968.html\"><span style=\"font-weight: 400;\">89 million<\/span><\/a><span style=\"font-weight: 400;\"> people have signed up to use Iranian messaging apps<\/span><span style=\"font-weight: 400;\"> and Eitaa, Rubika, and Bale, in particular, are gaining in popularity. All three are interoperable and claim to use end-to-end encryption (E2EE)\u2014whereby only the sender and receiver of messages are able to read their contents. With E2EE, third-parties (including the application server) are unable to read or modify the data. Do these apps truly use E2EE, though? And are there other privacy and security vulnerabilities that users should be aware of?\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Open Technology Fund (OTF)\u2019s <\/span><a href=\"https:\/\/www.opentech.fund\/labs\/security-lab\/\"><span style=\"font-weight: 400;\">Security Lab<\/span><\/a><span style=\"font-weight: 400;\"> performed an audit of these apps in December 2023 and October 2024 to try and answer these questions. All three apps were confirmed not to use E2EE. Auditors also identified that all three apps\u2019 backend servers monitor which websites users access, a mechanism for censorship and surveillance. Several other privacy and security vulnerabilities were uncovered in all the apps. Unlike the majority of OTF\u2019s <\/span><a href=\"https:\/\/www.opentech.fund\/impact\/security-safety-audits\/\"><span style=\"font-weight: 400;\">Security Audit Reports<\/span><\/a><span style=\"font-weight: 400;\">, the auditors asked to remain anonymous given the sensitive nature of the inquiry.\u00a0<\/span><\/p>\n<h4><strong>More About Eitaa, Rubika, and Bale Messaging Apps<\/strong><\/h4>\n<p><b>Eitaa<\/b><span style=\"font-weight: 400;\"> was developed at the University of Qom\u2019s Incubation Center, an institution with close ties to the Iranian political establishment. According to the Iranian Communication Minister, <\/span><span style=\"font-weight: 400;\">the app grew from three million to <\/span><a href=\"https:\/\/tejaratnews.com\/%D8%A8%D8%AE%D8%B4-%D8%AA%DA%A9%D9%86%D9%88%D9%84%D9%88%DA%98%DB%8C-28\/752716-%D8%B1%D8%B4%D8%AF-%D9%85%DB%8C%D9%84%DB%8C%D9%88%D9%86%DB%8C-%DA%A9%D8%A7%D8%B1%D8%A8%D8%B1%D8%A7%D9%86-%D8%A7%DB%8C%D8%AA%D8%A7\"><span style=\"font-weight: 400;\">19 million users<\/span><\/a><span style=\"font-weight: 400;\"> in just three months, from late September to late December 2023<\/span><span style=\"font-weight: 400;\">. In a <a href=\"https:\/\/filter.watch\/english\/2023\/11\/23\/domestic-messaging-apps-leading-in-surveillance-lagging-in-service\/\">poll<\/a> conducted by the <\/span><a href=\"https:\/\/www.miaan.org\/\"><span style=\"font-weight: 400;\">Miaan Group<\/span><\/a><span style=\"font-weight: 400;\"> in 2023, many respondents said they had to use Eitaa and other domestic messaging apps for education purposes.<\/span><\/p>\n<p><b>Rubika<\/b><span style=\"font-weight: 400;\"> is a product of Hamrah-e-Aval (MCI), one of Iran\u2019s major mobile telecommunication service providers, which is majority owned by the state\u2019s Telecommunication Company of Iran. Features include banking services and access to a domestic version of Instagram. In May 2023, the Iranian Minister of Communications and Information Technology announced that <\/span><span style=\"font-weight: 400;\">Rubika has nearly <\/span><a href=\"https:\/\/www.isna.ir\/news\/1402020502312\/%D8%A2%D8%AE%D8%B1%DB%8C%D9%86-%D8%A2%D9%85%D8%A7%D8%B1-%D8%A7%D8%B2-%D8%AA%D8%B9%D8%AF%D8%A7%D8%AF-%DA%A9%D8%A7%D8%B1%D8%A8%D8%B1%D8%A7%D9%86-%D9%BE%DB%8C%D8%A7%D9%85-%D8%B1%D8%B3%D8%A7%D9%86-%D9%87%D8%A7%DB%8C-%D8%A7%DB%8C%D8%B1%D8%A7%D9%86%DB%8C\"><span style=\"font-weight: 400;\">40 million <\/span><\/a><span style=\"font-weight: 400;\">monthly active users<\/span><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The features in <\/span><b>Bale<\/b><span style=\"font-weight: 400;\"> (\u201cYes\u201d in Persian) include banking services and many users are obligated to use the app in order to access e-government resources. It was reportedly created by <\/span><a href=\"https:\/\/sadad.co.ir\/\"><span style=\"font-weight: 400;\">Sadad Informatics Corporation<\/span><\/a><span style=\"font-weight: 400;\">, which receives investment from the state-owned National bank of Iran (Bank Melli). Per the Iranian Minister of Communications and Information Technology, <\/span><span style=\"font-weight: 400;\">Bale had <\/span><a href=\"https:\/\/www.isna.ir\/news\/1402020502312\/%D8%A2%D8%AE%D8%B1%DB%8C%D9%86-%D8%A2%D9%85%D8%A7%D8%B1-%D8%A7%D8%B2-%D8%AA%D8%B9%D8%AF%D8%A7%D8%AF-%DA%A9%D8%A7%D8%B1%D8%A8%D8%B1%D8%A7%D9%86-%D9%BE%DB%8C%D8%A7%D9%85-%D8%B1%D8%B3%D8%A7%D9%86-%D9%87%D8%A7%DB%8C-%D8%A7%DB%8C%D8%B1%D8%A7%D9%86%DB%8C\"><span style=\"font-weight: 400;\">16.5 million<\/span><\/a><span style=\"font-weight: 400;\"> monthly active users as of May 2023<\/span><span style=\"font-weight: 400;\">.<\/span><\/p>\n<h4><strong>Audit Description<\/strong><\/h4>\n<p><span style=\"font-weight: 400;\">Auditors conducted a multi-phased audit. Phase I, which occurred in December 2023, entailed static analysis (this entails examining the code without executing the program) and reverse engineering to evaluate encryption methods and platform-level privacy concerns. Project time was limited to the following questions in order to inform a more robust second-phase audit:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Do the apps use E2EE encryption for user-to-user messaging, as is publicly claimed?<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Are there notable security and privacy concerns for app users?<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Phase II, conducted in October 2024, entailed dynamic analysis (a technique that involves analyzing a program\u2019s behavior while it is running to gain insight into real-world behavior) to validate findings from Phase I. Auditors considered operational security risks as they planned the dynamic analysis, such as the risk posed to the individuals whose phone numbers were used to run the applications. Phase II explored the following concerns:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Encryption:<\/b><span style=\"font-weight: 400;\"> What types of encryption are used in the apps overall?<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Interoperability: <\/b><span style=\"font-weight: 400;\">Are communications between the target applications secure? What type of encryption is used to enable this interoperability?<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Unexpected Transmission of Private Data:<\/b><span style=\"font-weight: 400;\"> Do the apps activate any sensors (e.g., a user\u2019s microphone) or send any user data (e.g., location) in an unexpected way?<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Changes from Telegram: <\/b><span style=\"font-weight: 400;\">Two of the apps rely heavily on Telegram code. How closely do the applications\u2019 implementations match that of the official Telegram app, and what\u2014if any\u2014significant changes have been made?<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Use of Artificial Intelligence (AI):<\/b><span style=\"font-weight: 400;\"> Rubika\u2019s public-facing documentation claims that it uses AI for image analysis (e.g., to detect women who are not wearing a hijab). Is there evidence this process occurs on client devices?<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Security Review:<\/b><span style=\"font-weight: 400;\"> Do the apps contain design or implementation vulnerabilities that could be exploited by mobile application hackers?<\/span><\/li>\n<\/ul>\n<h4><strong>Scope<\/strong><\/h4>\n<p><span style=\"font-weight: 400;\">Auditors investigated the Android Package Kits (a package file that contains all the files and resources an Android app needs to install and run) below.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eitaa <\/span><span style=\"font-weight: 400;\">(v6.4.2, SHA256:943d25d2cb842ee91e404922c9eeb7433158ba14ee5da821de3870cd92676731)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rubika <\/span><span style=\"font-weight: 400;\">(v3.7.5, SHA256:9f4ca46bbcec994063376f18cc3c3f7adcdf7c41fd5de9eabaafc4c050d4da6d)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bale <\/span><span style=\"font-weight: 400;\">(v9.41.5, SHA256:9bb94f028bb34e97123b26ca7baefd10c7191fa61b3c6ecbd1f4928a75bc3f8f)<\/span><\/li>\n<\/ul>\n<h4><strong>Key Findings<\/strong><\/h4>\n<p><span style=\"font-weight: 400;\">In addition to the absence of E2EE in any of the apps, the most interesting findings include the monitoring of websites accessed and the use of <\/span><a href=\"https:\/\/en.ito.gov.ir\/news\/34\/fifth-iranian-domestic-messenger-joined-the-mxb\"><span style=\"font-weight: 400;\">Message Exchange Bus<\/span><\/a><span style=\"font-weight: 400;\"> (MXB), a state-owned, backend process to exchange messages between the three apps.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In all three apps, when users clicked URLs in messages sent to them, they were redirected to the application\u2019s backend server with the original URL in the query string. This would effectively allow the servers to monitor which websites are viewed by users within the app.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Given the lack of E2EE, it\u2019s likely that MXB servers (in addition to the app-specific backend servers) can read every message sent through it\u2014which would be a clear privacy violation.<\/span><\/p>\n<h4><strong>Summary of Important Discoveries<\/strong><\/h4>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Encryption:<\/b><span style=\"font-weight: 400;\"> All three apps employed different forms of client-server encryption, but none had E2EE enabled to keep conversations between users protected from the backend servers, despite government claims.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Insecure Interoperability: <\/b><span style=\"font-weight: 400;\">All three apps could exchange messages with each other through a backend process called Message Exchange Bus (MXB), which is a state-owned service. MXB maintains a directory of participating users and its servers could potentially view plaintext messages due to the lack of E2EE in any of the apps.<\/span><\/li>\n<li aria-level=\"1\"><b>Unexpected Transmission of Private Data:\u00a0<\/b>\n<ul>\n<li aria-level=\"1\"><span style=\"font-weight: 400;\">Given the lack of E2EE in the apps, all chats and information about users (e.g., names, phone numbers) were readable by the applications\u2019 backend servers.\u00a0<\/span><\/li>\n<li aria-level=\"1\"><span style=\"font-weight: 400;\">In the case of Eitaa, unsent draft messages were additionally reported to the application\u2019s backend server.\u00a0<\/span><\/li>\n<li aria-level=\"1\"><span style=\"font-weight: 400;\">Auditors did not find sensor-based cases of unexpected data sent, such as unexpected enabling of a user\u2019s microphone or camera.<\/span><\/li>\n<li aria-level=\"1\"><span style=\"font-weight: 400;\">In all three apps, when users clicked URLs in messages that were sent to them, they were redirected to the application\u2019s backend server with the original URL in the query string unless the URL was contained in a short allowlist of \u201csafe\u201d URLs. This would effectively allow the servers to monitor which websites were viewed by users within the app. This also adds a layer of censorship, as the apps are forcing users to go through their own web page to access unapproved external domains, and they could block them at any time. A user could easily circumvent this, though, by pasting the link into a separate web browser.<\/span><\/li>\n<\/ul>\n<\/li>\n<li><b>Changes from Telegram: <\/b><span style=\"font-weight: 400;\">Only Eitaa and Rubika are based on Telegram source code. Key findings include the removal of Telegram\u2019s secret chats (which have E2EE) in Eitaa. Bale was forked from the Actor Messaging Platform, an abandoned open source codebase developed by an ex-Telegram engineer.<\/span><\/li>\n<li><b>Use of Artificial Intelligence (AI): <\/b><span style=\"font-weight: 400;\">No evidence of the use of AI to analyze message content in app code.<\/span><\/li>\n<li><b>Security Review:<\/b><span style=\"font-weight: 400;\"> Auditors were unable to conduct a thorough security review of the applications in the second phase of the assessment, primarily due to time constraints and challenges related to reverse engineering Bale\u2019s messaging protocol and defeating its obfuscation. Some of the notable privacy and security concerns were discovered in Phase I include:<\/span><\/li>\n<li><b>Eitaa:<\/b>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"3\"><b>Attempts to include the user\u2019s International Mobile Equipment Identity <\/b><span style=\"font-weight: 400;\">(a unique 15- or 17-digit number that identifies a mobile device and can be used to track it) in the messages that are sent to the app server. In Android versions 10 and newer, due to protections added by Google, a random unique identifier is generated and sent instead.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"3\"><b>Attacker with physical access to the phone can download all private app data<\/b><span style=\"font-weight: 400;\">.<\/span> <span style=\"font-weight: 400;\">This data may include cleartext message history and personal information about contacts.<\/span><\/li>\n<\/ul>\n<\/li>\n<li><b>Rubika:<\/b>\n<ul>\n<li><b>Permits cleartext (unencrypted) traffic to all domains.<\/b><span style=\"font-weight: 400;\"> This vulnerability allows anyone monitoring the network to intercept and read sensitive data such as passwords or personal information if transmitted in cleartext.<\/span><\/li>\n<\/ul>\n<\/li>\n<li><strong>Bale:<\/strong>\n<ul>\n<li><b>Usage of one form of encryption that could be easily reversed<\/b><span style=\"font-weight: 400;\"> in the context of encrypting a user\u2019s credit card data.\u00a0<\/span><\/li>\n<li><b>User location was sent to the app server<\/b><span style=\"font-weight: 400;\"> during authentication.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h4><strong>Conclusion<\/strong><\/h4>\n<p><span style=\"font-weight: 400;\">This engagement points to the need to conduct more analyses of state-sponsored applications in contexts where censorship and surveillance is common, especially as authoritarian governments increasingly pressure citizens to use domestic technology to access public services.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The alternative messaging apps listed below employ better encryption than Eitaa, Rubika, and Bale. While they cannot grant users access to Iranian government services like Iranian messenger apps, they offer much greater privacy and security for communications. Signal, Session, and Wire provide E2EE.<\/span><b><\/b><\/p>\n<ul>\n<li aria-level=\"1\"><a href=\"https:\/\/www.newnode.com\/\"><b>NewNode<\/b><\/a><b><\/b><\/li>\n<li aria-level=\"1\"><b>Signal<\/b><span style=\"font-weight: 400;\"> (using their <\/span><a href=\"https:\/\/support.signal.org\/hc\/en-us\/articles\/360056052052-Proxy-Support#proxy_find\"><span style=\"font-weight: 400;\">anti-censorship proxy service<\/span><\/a><span style=\"font-weight: 400;\">)<\/span><\/li>\n<li aria-level=\"1\"><a href=\"https:\/\/getsession.org\/\"><b>Session\u00a0<\/b><\/a><\/li>\n<li aria-level=\"1\"><a href=\"https:\/\/wire.com\/en\/\"><b>Wire<\/b><\/a><\/li>\n<li aria-level=\"1\"><a href=\"https:\/\/delta.chat\/en\/\"><b>Delta Chat<\/b><\/a><b>\u00a0<\/b><\/li>\n<\/ul>\n<p><b>Link to report:<\/b><\/p>\n<ul>\n<li><a href=\"https:\/\/www.opentech.fund\/wp-content\/uploads\/2024\/12\/Phase_I_Report.pdf\">Phase One<\/a><\/li>\n<li><a href=\"https:\/\/www.opentech.fund\/wp-content\/uploads\/2024\/12\/Phase_II_Iranian_Msgs_Apps_Report.pdf\">Phase Two<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Iran is consistently ranked \u201cnot free\u201d in Freedom House\u2019s annual Freedom on the Net research reports. The country received a dismal score of 12 (on a scale of 1 to 100, with 100 being the most free) in the 2024 report, amid wide-reaching censorship and surveillance. In a bid to restrict access to the global,<a class=\"more-link\" href=\"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/\">Continue reading <span class=\"screen-reader-text\">\"Open Technology Fund\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe\"<\/span><\/a><\/p>\n","protected":false},"author":13,"featured_media":5152,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[3],"tags":[155,237,238,236,156],"class_list":["post-5150","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-investigations","tag-bale","tag-eitaa","tag-freedom-house","tag-otf","tag-rubika","entry"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"Iran is consistently ranked \u201cnot free\u201d in Freedom House\u2019s annual Freedom on the Net research reports. The country received a dismal score of 12 (on a scale of 1 to 100, with 100 being the most free) in the 2024 report, amid wide-reaching censorship and surveillance. In a bid to restrict access to the global,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Filterwatch\"\/>\n\t<meta name=\"keywords\" content=\"bale,eitaa,freedom house,otf,rubika,investigations\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Filterwatch -\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Open Technology Fund\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe\" \/>\n\t\t<meta property=\"og:description\" content=\"Iran is consistently ranked \u201cnot free\u201d in Freedom House\u2019s annual Freedom on the Net research reports. The country received a dismal score of 12 (on a scale of 1 to 100, with 100 being the most free) in the 2024 report, amid wide-reaching censorship and surveillance. In a bid to restrict access to the global,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2024\/12\/Website-MAIN-Banner-1.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2024\/12\/Website-MAIN-Banner-1.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"2041\" \/>\n\t\t<meta property=\"og:image:height\" content=\"1020\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-12-17T07:21:47+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-12-17T09:30:52+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@filterbaan\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Open Technology Fund\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Iran is consistently ranked \u201cnot free\u201d in Freedom House\u2019s annual Freedom on the Net research reports. The country received a dismal score of 12 (on a scale of 1 to 100, with 100 being the most free) in the 2024 report, amid wide-reaching censorship and surveillance. In a bid to restrict access to the global,\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@filterbaan\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2024\/12\/Website-MAIN-Banner-1.png\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"Filterwatch\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/2024\\\/12\\\/17\\\/investigative-report-december-iranian-messaging-apps\\\/#blogposting\",\"name\":\"Open Technology Fund\\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe - Filterwatch\",\"headline\":\"Open Technology Fund\\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe\",\"author\":{\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/author\\\/filterbaan2\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/filter.watch\\\/wp-content\\\/uploads\\\/sites\\\/2\\\/2024\\\/12\\\/Website-MAIN-Banner-1.png\",\"width\":2041,\"height\":1020},\"datePublished\":\"2024-12-17T07:21:47+00:00\",\"dateModified\":\"2024-12-17T09:30:52+00:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/2024\\\/12\\\/17\\\/investigative-report-december-iranian-messaging-apps\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/2024\\\/12\\\/17\\\/investigative-report-december-iranian-messaging-apps\\\/#webpage\"},\"articleSection\":\"Investigations, Bale, Eitaa, Freedom House, OTF, Rubika\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/2024\\\/12\\\/17\\\/investigative-report-december-iranian-messaging-apps\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/filter.watch\\\/english#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/filter.watch\\\/english\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/category\\\/investigations\\\/#listItem\",\"name\":\"Investigations\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/category\\\/investigations\\\/#listItem\",\"position\":2,\"name\":\"Investigations\",\"item\":\"https:\\\/\\\/filter.watch\\\/english\\\/category\\\/investigations\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/2024\\\/12\\\/17\\\/investigative-report-december-iranian-messaging-apps\\\/#listItem\",\"name\":\"Open Technology Fund\\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/filter.watch\\\/english#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/2024\\\/12\\\/17\\\/investigative-report-december-iranian-messaging-apps\\\/#listItem\",\"position\":3,\"name\":\"Open Technology Fund\\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/category\\\/investigations\\\/#listItem\",\"name\":\"Investigations\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/#organization\",\"name\":\"FilterWatch\",\"url\":\"https:\\\/\\\/filter.watch\\\/english\\\/\",\"telephone\":\"+12025603853\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/filter.watch\\\/en\\\/wp-content\\\/uploads\\\/sites\\\/2\\\/2020\\\/05\\\/Logo-Watch.jpg\",\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/2024\\\/12\\\/17\\\/investigative-report-december-iranian-messaging-apps\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/2024\\\/12\\\/17\\\/investigative-report-december-iranian-messaging-apps\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/filterbaan\",\"https:\\\/\\\/instagram.com\\\/filterbaan\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/author\\\/filterbaan2\\\/#author\",\"url\":\"https:\\\/\\\/filter.watch\\\/english\\\/author\\\/filterbaan2\\\/\",\"name\":\"Filterwatch\",\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/filter.watch\\\/english\\\/wp-content\\\/litespeed\\\/avatar\\\/2\\\/ddbef0c070c9674792e5f1bb773f2a4d.jpg?ver=1781618819\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/2024\\\/12\\\/17\\\/investigative-report-december-iranian-messaging-apps\\\/#webpage\",\"url\":\"https:\\\/\\\/filter.watch\\\/english\\\/2024\\\/12\\\/17\\\/investigative-report-december-iranian-messaging-apps\\\/\",\"name\":\"Open Technology Fund\\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe - Filterwatch\",\"description\":\"Iran is consistently ranked \\u201cnot free\\u201d in Freedom House\\u2019s annual Freedom on the Net research reports. The country received a dismal score of 12 (on a scale of 1 to 100, with 100 being the most free) in the 2024 report, amid wide-reaching censorship and surveillance. In a bid to restrict access to the global,\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/2024\\\/12\\\/17\\\/investigative-report-december-iranian-messaging-apps\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/author\\\/filterbaan2\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/author\\\/filterbaan2\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/filter.watch\\\/wp-content\\\/uploads\\\/sites\\\/2\\\/2024\\\/12\\\/Website-MAIN-Banner-1.png\",\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/2024\\\/12\\\/17\\\/investigative-report-december-iranian-messaging-apps\\\/#mainImage\",\"width\":2041,\"height\":1020},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/2024\\\/12\\\/17\\\/investigative-report-december-iranian-messaging-apps\\\/#mainImage\"},\"datePublished\":\"2024-12-17T07:21:47+00:00\",\"dateModified\":\"2024-12-17T09:30:52+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/#website\",\"url\":\"https:\\\/\\\/filter.watch\\\/english\\\/\",\"name\":\"Filterwatch\",\"alternateName\":\"\\u0641\\u06cc\\u0644\\u062a\\u0631\\u0628\\u0627\\u0646\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/filter.watch\\\/english\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Open Technology Fund\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe - Filterwatch<\/title>\n\n","aioseo_head_json":{"title":"Open Technology Fund\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe - Filterwatch","description":"Iran is consistently ranked \u201cnot free\u201d in Freedom House\u2019s annual Freedom on the Net research reports. The country received a dismal score of 12 (on a scale of 1 to 100, with 100 being the most free) in the 2024 report, amid wide-reaching censorship and surveillance. In a bid to restrict access to the global,","canonical_url":"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/","robots":"max-image-preview:large","keywords":"bale,eitaa,freedom house,otf,rubika,investigations","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/#blogposting","name":"Open Technology Fund\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe - Filterwatch","headline":"Open Technology Fund\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe","author":{"@id":"https:\/\/filter.watch\/english\/author\/filterbaan2\/#author"},"publisher":{"@id":"https:\/\/filter.watch\/english\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2024\/12\/Website-MAIN-Banner-1.png","width":2041,"height":1020},"datePublished":"2024-12-17T07:21:47+00:00","dateModified":"2024-12-17T09:30:52+00:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/#webpage"},"isPartOf":{"@id":"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/#webpage"},"articleSection":"Investigations, Bale, Eitaa, Freedom House, OTF, Rubika"},{"@type":"BreadcrumbList","@id":"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/filter.watch\/english#listItem","position":1,"name":"Home","item":"https:\/\/filter.watch\/english","nextItem":{"@type":"ListItem","@id":"https:\/\/filter.watch\/english\/category\/investigations\/#listItem","name":"Investigations"}},{"@type":"ListItem","@id":"https:\/\/filter.watch\/english\/category\/investigations\/#listItem","position":2,"name":"Investigations","item":"https:\/\/filter.watch\/english\/category\/investigations\/","nextItem":{"@type":"ListItem","@id":"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/#listItem","name":"Open Technology Fund\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe"},"previousItem":{"@type":"ListItem","@id":"https:\/\/filter.watch\/english#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/#listItem","position":3,"name":"Open Technology Fund\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe","previousItem":{"@type":"ListItem","@id":"https:\/\/filter.watch\/english\/category\/investigations\/#listItem","name":"Investigations"}}]},{"@type":"Organization","@id":"https:\/\/filter.watch\/english\/#organization","name":"FilterWatch","url":"https:\/\/filter.watch\/english\/","telephone":"+12025603853","logo":{"@type":"ImageObject","url":"https:\/\/filter.watch\/en\/wp-content\/uploads\/sites\/2\/2020\/05\/Logo-Watch.jpg","@id":"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/#organizationLogo"},"image":{"@id":"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/#organizationLogo"},"sameAs":["https:\/\/twitter.com\/filterbaan","https:\/\/instagram.com\/filterbaan"]},{"@type":"Person","@id":"https:\/\/filter.watch\/english\/author\/filterbaan2\/#author","url":"https:\/\/filter.watch\/english\/author\/filterbaan2\/","name":"Filterwatch","image":{"@type":"ImageObject","url":"https:\/\/filter.watch\/english\/wp-content\/litespeed\/avatar\/2\/ddbef0c070c9674792e5f1bb773f2a4d.jpg?ver=1781618819"}},{"@type":"WebPage","@id":"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/#webpage","url":"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/","name":"Open Technology Fund\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe - Filterwatch","description":"Iran is consistently ranked \u201cnot free\u201d in Freedom House\u2019s annual Freedom on the Net research reports. The country received a dismal score of 12 (on a scale of 1 to 100, with 100 being the most free) in the 2024 report, amid wide-reaching censorship and surveillance. In a bid to restrict access to the global,","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/filter.watch\/english\/#website"},"breadcrumb":{"@id":"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/#breadcrumblist"},"author":{"@id":"https:\/\/filter.watch\/english\/author\/filterbaan2\/#author"},"creator":{"@id":"https:\/\/filter.watch\/english\/author\/filterbaan2\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2024\/12\/Website-MAIN-Banner-1.png","@id":"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/#mainImage","width":2041,"height":1020},"primaryImageOfPage":{"@id":"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/#mainImage"},"datePublished":"2024-12-17T07:21:47+00:00","dateModified":"2024-12-17T09:30:52+00:00"},{"@type":"WebSite","@id":"https:\/\/filter.watch\/english\/#website","url":"https:\/\/filter.watch\/english\/","name":"Filterwatch","alternateName":"\u0641\u06cc\u0644\u062a\u0631\u0628\u0627\u0646","inLanguage":"en-US","publisher":{"@id":"https:\/\/filter.watch\/english\/#organization"}}]},"og:locale":"en_US","og:site_name":"Filterwatch -","og:type":"article","og:title":"Open Technology Fund\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe","og:description":"Iran is consistently ranked \u201cnot free\u201d in Freedom House\u2019s annual Freedom on the Net research reports. The country received a dismal score of 12 (on a scale of 1 to 100, with 100 being the most free) in the 2024 report, amid wide-reaching censorship and surveillance. In a bid to restrict access to the global,","og:url":"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/","og:image":"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2024\/12\/Website-MAIN-Banner-1.png","og:image:secure_url":"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2024\/12\/Website-MAIN-Banner-1.png","og:image:width":2041,"og:image:height":1020,"article:published_time":"2024-12-17T07:21:47+00:00","article:modified_time":"2024-12-17T09:30:52+00:00","twitter:card":"summary_large_image","twitter:site":"@filterbaan","twitter:title":"Open Technology Fund\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe","twitter:description":"Iran is consistently ranked \u201cnot free\u201d in Freedom House\u2019s annual Freedom on the Net research reports. The country received a dismal score of 12 (on a scale of 1 to 100, with 100 being the most free) in the 2024 report, amid wide-reaching censorship and surveillance. In a bid to restrict access to the global,","twitter:creator":"@filterbaan","twitter:image":"https:\/\/filter.watch\/wp-content\/uploads\/sites\/2\/2024\/12\/Website-MAIN-Banner-1.png","twitter:label1":"Written by","twitter:data1":"Filterwatch","twitter:label2":"Est. reading time","twitter:data2":"8 minutes"},"aioseo_meta_data":{"post_id":"5150","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":"#post_title","og_description":"#post_excerpt","og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":true,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"open_ai":"{\"title\":{\"suggestions\":[],\"usage\":0},\"description\":{\"suggestions\":[],\"usage\":0}}","ai":null,"created":"2024-12-17 07:05:34","updated":"2025-05-30 02:45:45"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/filter.watch\/english\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/filter.watch\/english\/category\/investigations\/\" title=\"Investigations\">Investigations<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\tOpen Technology Fund\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/filter.watch\/english"},{"label":"Investigations","link":"https:\/\/filter.watch\/english\/category\/investigations\/"},{"label":"Open Technology Fund\u2019s Security Lab Finds Three Widely Used Iranian Messaging Apps Are Not Safe","link":"https:\/\/filter.watch\/english\/2024\/12\/17\/investigative-report-december-iranian-messaging-apps\/"}],"_links":{"self":[{"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/posts\/5150","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/comments?post=5150"}],"version-history":[{"count":0,"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/posts\/5150\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/media\/5152"}],"wp:attachment":[{"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/media?parent=5150"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/categories?post=5150"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/filter.watch\/english\/wp-json\/wp\/v2\/tags?post=5150"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}