AntiMalware•September 29, 2026•🇷🇺Translated from Russian

FAS Clears Russian Operators on 'Unlimited' Internet Claims Despite Speed Throttling to 128 Kbit/s

The Federal Antimonopoly Service has decided not to pursue complaints against Russian mobile operators over their marketing of unlimited internet and roaming access without restrictions.

The Association of Professional Users of Social Networks and Messengers filed the complaint, highlighting that operators Vimpelcom, MegaFon, MTS, and T2 Mobile advertise unlimited plans while imposing speed limits of 128-512 Kbit/s once initial high-speed traffic volumes are exhausted. Additional data packages must sometimes be purchased to restore normal speeds, although the connection itself is never fully disconnected.

According to the association, this practice turns activities such as video streaming, file downloads, and access to many websites into slow, frustrating experiences resembling a meditation session with a progress bar. Operators defend the use of the term unlimited by noting the absence of any overall data volume cap; only connection speed changes, with all conditions clearly stated in service descriptions.

T2 Mobile specifically stated that 128 Kbit/s remains sufficient for messaging apps and social networks. The complainants reject the FAS position and plan to seek a substantive review of the matter.

Legal experts point out that the service examined only pages containing technical parameters, while the original complaint also covered banners, promotional news items, search advertising, SMS messages, and push notifications. These additional materials could potentially qualify as advertising under Russian law, yet they received no separate assessment.

As a result, the label unlimited continues to apply even when speeds drop to near-obsolete levels, provided the connection remains technically active. Whether such access meets practical user needs appears to remain a secondary consideration for regulators.

Related articles

Habr•Policy & Regulation

RWB Deploys Enterprise-Wide Database Access Control with Trino and Open Policy Agent

RWB has replaced fragmented manual database access processes with a centralized architecture built on Trino as the single entry point and Open Policy Agent for policy enforcement. The system enforces least-privilege access, mandatory auditing, and automated revocation tied to HR records while eliminating anonymous and password-based logins. Access requests now complete in 3–10 minutes instead of an average of four days, with 92 percent handled automatically. Key components include Keycloak for OIDC authentication, Vault for secrets, Kafka for security event streaming to SOC, and Kubernetes orchestration. Responsibility is split across AI & Data Security, Core DevOps, Access Management, SOC, and Trust & Safety teams. More than 1,250 PostgreSQL clusters and 90 projects are now connected, with real-time dashboards tracking adoption and policy health.

AntiMalware•Policy & Regulation

Russia Moves to Allow Biometric Data Processing for Suspects and Convicts Without Consent

Russian law enforcement agencies may soon gain the legal right to process biometric data of suspects, accused individuals, and convicted persons without requiring their personal consent. A corresponding draft bill has already been submitted to the government and is scheduled for review at the next cabinet meeting, according to TASS. The measure covers fingerprints, facial images, voice recordings, and other physiological or behavioral characteristics used for identification. If approved, prior permission from the individual will no longer be needed when biometrics are used in criminal proceedings. The change applies not only to those already convicted but also to suspects and accused persons whose guilt has not yet been established by a court. For ordinary citizens, enrollment in the Unified Biometric System remains voluntary and is used for remote identity verification when accessing financial and government services.

Habr•Policy & Regulation

Merkle Tree Certificates Proposed to Enable Lightweight Post-Quantum HTTPS in Chrome

Google Chrome developers, together with industry partners and the IETF PLANTS working group, are introducing Merkle Tree Certificates (MTC) as the first HTTPS change designed to address performance challenges of post-quantum cryptography. The new format replaces parts of traditional X.509 certificate chains with compact inclusion proofs inside a Merkle tree whose root is signed by a certificate authority. This approach significantly reduces the size of authentication data exchanged during TLS handshakes while preserving strong post-quantum security properties. MTC also enforces Certificate Transparency by design, making it impossible to issue a public certificate without recording it in a publicly verifiable log. Performance evaluations are currently underway with Cloudflare, and initial public MTC logs operated by experienced CT log providers are planned for early 2027. A dedicated post-quantum Chrome Root Store supporting only MTC is scheduled for the third quarter of 2027 and will run in parallel with the existing root store.

Habr•Policy & Regulation

AI Resume Screening Barriers Push Young IT Talent Toward Cybercrime

Young Russian IT graduates with relevant projects and freelance experience are struggling to secure entry-level roles in information security and antifraud due to automated resume filters demanding prior commercial experience. Data from SuperJob and Habr Careers shows only 10-11% of IT vacancies in early 2026 were open to candidates without experience, compared to 37-38% across the broader labor market, with most junior openings limited to technical support. Russian court statistics reveal that 67.9% of those convicted for computer-related crimes under Article 272 were under 30, aligning with the age when graduates first seek professional experience. International studies, including research from Harvard Business School and Accenture, highlight how overly rigid automated screening discards capable candidates lacking formal tenure. Programs like the UK's National Crime Agency Cyber Choices demonstrate that providing legal pathways in cybersecurity can reduce recidivism. The article argues that excessive reliance on AI filters without human review of projects or practical tests exacerbates the pipeline problem in a sector claiming talent shortages.