Habr•October 7, 2026•🇷🇺Translated from Russian

Russian Websites Remain Dependent on Foreign SSL Certificates and Analytics Despite Sanctions

A Russian security researcher tested how many domestic websites would break if foreign service providers suddenly stopped serving Russian clients. The project examined 50 large Russian sites across banking, retail, telecom, aviation, delivery, online education and government sectors.

The motivation stems from real incidents such as Namecheap terminating services for Russian customers in 2022 and foreign certificate authorities revoking or refusing to renew certificates. Additional pressure comes from the March 2023 regulation requiring advance notification to Roskomnadzor for any cross-border transfer of personal data.

The researcher created an open-source browser-based scanner that checks main pages and key internal sections for foreign dependencies. Each detected dependency lowers the site’s score, resulting in a final grade from A to F.

Results showed the following distribution: 19 sites received A, 19 received B, 5 received C, 6 received D and 1 received F. Most infrastructure has moved to Russian servers, yet peripheral services remain exposed.

SSL certificates represent the largest single dependency. 43 of the 50 sites still use foreign certificates, most commonly GlobalSign (29 sites) and Let's Encrypt (12 sites). Only four sites employ the Russian NUC certificate issued by the Ministry of Digital Development. Because major browsers do not trust NUC by default, complete removal of foreign certificates is impractical; rapid replacement capability is the realistic goal.

Other common foreign elements include analytics platforms, font services and CAPTCHA solutions that transmit visitor IP addresses abroad. Many site owners installed these tools years ago and have not reassessed the resulting legal and operational exposure.

Related articles

Habr•Policy & Regulation

Digitizing Cyber Risks: How to Communicate Cyber Threats to Boards in the Language of Money

The article from Solar details a hybrid methodology for quantifying cyber risks by converting technical threats into financial metrics such as probability and expected losses. It explains that cyber risks represent a specialized form of operational risk characterized by rapid propagation, scalability across IT infrastructure, and heavy dependence on third-party vendors and cloud providers. The process involves four stages: asset and threat identification, incident and vulnerability analysis, translation into monetary values using formulas like ALE, and ongoing monitoring with updates. Qualitative expert assessments are combined with quantitative techniques including Monte Carlo simulations and statistical modeling when data is available. The resulting metrics support investment prioritization through ROSI calculations, integration of cyber risks into enterprise risk management frameworks, and clear communication with directors and investors using business language. Regulatory pressure and the direct impact of incidents on revenue, costs, and business continuity make this approach increasingly essential.

AntiMalware•Policy & Regulation

Russian Interior Ministry Accuses Telegram of Ignoring Drug Trafficking Requests

The Russian Ministry of Internal Affairs has publicly stated that Telegram completely ignores requests from law enforcement agencies aimed at combating illegal drug trafficking. According to the ministry, the messenger has become one of the main platforms, alongside darknet markets, for involving teenagers in narcotics-related crimes. Acting head of the Main Directorate for Drug Trafficking Control Kirill Smurov highlighted that Telegram administration does not respond to official inquiries and refuses to share necessary information. In contrast, Yandex promptly removes prohibited content either independently or upon the first police request. Since 2022, approximately 153,000 crimes have been committed using Telegram, while Roskomnadzor has issued more than 150,000 content removal demands that received no response. Founder Pavel Durov, who is included in the Rosfinmonitoring list of terrorists and extremists, has not engaged with Russian authorities on these matters.

AntiMalware•Policy & Regulation

UK Regulator Ofcom Investigates Meta Over Instagram Instants Compliance With Online Safety Act

Britain's communications regulator Ofcom has opened an investigation into Meta to determine whether the company properly assessed risks before launching the Instagram Instants feature. The probe focuses on compliance with the Online Safety Act, specifically the potential for illegal content distribution and harms to minors. Instants, introduced in May 2026, allows users to exchange images that disappear after viewing. Under UK rules, platforms must update risk assessments before rolling out significant changes. Ofcom will first gather evidence and, if violations are found, issue a preliminary decision allowing Meta to respond. Penalties for non-compliance can reach 18 million pounds or 10 percent of global turnover, whichever is higher. Meta maintains it conducted risk analysis and implemented safeguards such as forwarding restrictions and teen account protections before launch.

AntiMalware•Policy & Regulation

Russia Plans Additional Security Checks for Gosuslugi Portal Access

Prime Minister Mikhail Mishustin has directed the Ministry of Digital Development to develop extra authentication measures for the Gosuslugi portal used by 120 million citizens. The new controls would apply both to initial logins and to account recovery procedures. Details on the exact checks and implementation timeline remain unspecified as the ministry must first propose a concrete mechanism. In parallel, officials are preparing a third package of anti-fraud measures that includes a unified consent platform inside Gosuslugi for managing personal data processing permissions. The platform would let users view which organizations access their data, revoke prior consents, and report violations. Russian police have separately warned that fraudsters are already exploiting the topic of account protection by sending messages that threaten blocking or data leaks and urge victims to call provided numbers.