In the age of digital capitalism, user information has become the most valuable currency. We are used to paying for free services with our data, but few people stop to think when exactly this collection begins. An experiment analyzing traffic from browser versions of three popular platforms in Russia—Telegram, VKontakte, and the messenger "Max" (formerly Mail.ru Agent)—allowed researchers to look under the hood of the apps and find out who starts tracking users and at what stage.
The most shocking discovery was how the services behaved even at the account-login stage. It turned out that some systems start “listening in” long before the user enters a password or scans a QR code.
Silence on the air: Telegram and VKontakte before authorization
First, the services’ behavior on the start page was checked. What do the apps send when the user has simply opened a browser window and sees the login form?
-
Telegram proved to be maximally closed-off. All requests sent from the user boil down to establishing a secure persistent connection (WebSocket). This is a technical necessity for the messenger to work in real time.
-
VKontakte, as a social network, immediately begins identifying the browser (by linking cookies) and collecting diagnostics. This seems logical, given the platform’s enormous functionality, which requires loading the interface, music, videos, and recommendations even before login.
-
Messenger Max behaved differently. Even while the page with the QR code was loading, it began aggressive reconnaissance.
Digital fingerprint: how Max sees you without scanning the code
The key difference between “Max” and its competitors is fingerprinting digital fingerprinting. While the user looks at the QR code, the browser, at the command of the server mail.ru performs a series of hidden tests.
Here is what is sent to Max’s servers in the first seconds after the page is opened:
-
Canvas and WebGL tests: The browser is made to render invisible shapes. A unique device identifier is generated based on how the graphics card and processor handle this task.
-
Audio tests: The sound card and its settings are checked.
-
Font collection: The full list of fonts installed on the system is scanned.
-
Browser extensions: The presence of plugins and ad blockers is inferred indirectly.
A super-fingerprint is assembled from all these parameters. This is supposedly done for anti-fraud protection (to combat bots and DDoS attacks), but in fact, even an unauthenticated user has already become an object of surveillance with a unique ID. Neither Telegram nor VKontakte collects this volume of data in a “clean” browser before login.
Authorization and life online: who transmits what
Once the user logs into the account, the picture becomes even more interesting. For clarity, let’s present the data in a table.
| Criterion | Telegram | VKontakte | Messenger Max |
|---|---|---|---|
| Primary communication channel | WebSocket (MTProto) | HTTP API + WebSocket | WebSocket (unencrypted) |
| Message encryption | End-to-end (in secret chats) / Client-server in cloud chats. In the browser—binary code. | Client-server (keys stored on servers). In the browser—standard HTTPS. | Absent in the web version. Messages are visible in plain text inside the frame. |
| What is transmitted in the feed | Only encrypted data. No POST requests. | Tons of data sent via POST: behavioral logs, viewing times, clicks, authorization keys. | Active telemetry. Location based on IP, performance data, and device ID are sent. |
| Typing | The “typing” function exists, but the text itself is not transmitted until it is sent. | The fact that the window has been touched is recorded, but character-by-character transmission of the text is absent. | The “typing” status appears, packets are sent, but the message content is hidden (as with everyone else). |
| Session security | Authorization keys are hidden. The IP address was not found in open requests. | Actively logs every movement, creating an advertising profile. | Critical vulnerability: An authorization token and phone number were found in plain text in the code, making it possible to hijack the session. |
Voice calls and strange findings
The architecture of the apps also differs when transmitting voice messages and making calls.
-
Telegram uses a division into binary chunks (blobs) and encrypts them.
-
VKontakte uses WebRTC (P2P connection) for calls, but simultaneously continues to send activity statistics from the interface nonstop via HTTP. The encryption keys are most likely stored on the server, which complies with legal requirements (the Yarovaya package).
-
Messenger Max is technically similar to VKontakte when it comes to calls, but a code review revealed disturbing artifacts. For example, the page’s source code contained a Russian flag and an audio transcriber for voice messages, even though the web version has no voice-message function. This points to “immaturity” or deep integration of legacy code.
Conclusions: observability as the new norm
The analysis revealed three different philosophies of handling user data:
-
Telegram serves as a benchmark for secrecy at the transport level. Thanks to the MTProto protocol and binary encryption, an ordinary user or traffic interceptor simply cannot see what exactly is being transmitted. Everything is packed into a “black box.”
-
VKontakte lives by the laws of social networks. It collects literally every behavioral metric (clicks, timings, views) to feed recommendation and advertising algorithms. This is intrusive, but expected.
-
Messenger Max proved to be the most contradictory. On the one hand, it uses sophisticated anti-bot protection systems ( fingerprinting). On the other, its web version leaves messages in plain text, and access tokens are available for theft.
The study’s main conclusion: the level of intrusion into privacy often does not depend on loud claims in advertising. Max starts tracking you before you have even become its user, while Telegram simply gives an observer no information, packing everything into a secure container. As always, the choice remains with the user: comfortable advertising or total privacy.