Russia to Mandate Gosuslugi Authentication for Hosting Providers, Further Reducing Anonymity in Runet
The Russian Ministry of Digital Development (MinTsifry) has resumed efforts to tighten control over hosting providers by proposing mandatory client identification through the Gosuslugi portal. The initiative would apply not to selected services but to virtually all hosting offerings, requiring every customer to authenticate via a confirmed ESIA account.
Under the proposed rules, each allocated IP address must be tied to a specific individual with a verified government-linked profile. Current identification methods—such as email addresses, bank cards, or other indirect verifications—are considered insufficient by regulators seeking greater transparency across the Russian internet segment known as Runet.
This policy builds directly on measures introduced in September for domain registrations. Owners of domains in the .ru, .рф, and .su zones must now confirm their identity through ESIA both when registering new domains and when renewing existing ones. Regulators intend to extend the same verification standard to hosting services.
Reactions within the hosting industry remain sharply divided. Turbo Cloud supports the change, arguing that mandatory identification will help combat phishing attacks and fraudulent schemes. The company has already integrated ESIA authentication and states that the associated expenses remain manageable for providers.
Other companies express more cautious or negative views. Runity estimates that preliminary implementation costs will reach at least 5 million rubles. RUVDS warns that the new requirements could severely damage the retail segment of the market, particularly affecting students, independent developers, and private individuals who may find the additional Gosuslugi verification step overly burdensome.
According to RUVDS assessments, providers could lose between 20% and 35% of such retail customers. These users are expected to migrate not to offline alternatives but to foreign hosting providers operating outside Russian jurisdiction.
A separate concern involves foreign clients. Without an alternative identification mechanism, non-Russian users may lose access to hosting services, servers, and domains. Overall, the push for greater transparency risks accelerating both the decline of online anonymity and the outflow of clients beyond Russia’s borders.
Related articles
FSB Russia Certifies Rutoken Chip 3127 with Five-Year Cryptographic Key Validity
Aktiv has received an FSB Russia certificate for the embedded Rutoken Chip 3127 microcontroller under security classes KS1 and KS2. The certification followed additional research that extended the validity period of the device's private cryptographic keys to five years. The chip belongs to the Rutoken ECP 3.0 3127 product line and targets long-term cryptographic protection in servers, ATMs, workstations, tablets, biometric systems, industrial equipment, and IoT devices. It stores keys in non-extractable form, performs user and device authentication, verifies component integrity, and supports trusted boot processes by controlling executable code at each stage. Additional capabilities include data encryption, derivation of session keys, secure software updates, and protected TLS and VPN connections using the CRISP protocol that complies with GOST R 71252-2024. The chip incorporates hardware-level defenses such as voltage monitoring, protective layer detection, and dummy branch execution to counter physical tampering and side-channel attacks. Pilot deployments have already occurred, including integration into the OVISION biometric access control systems, paving the way for serial use in critical infrastructure.
Durov's Addition to Terrorist List Triggers Russian Account Blocks but Does Not Automatically Ban Telegram or Classify Transfers as Terrorism Financing
Russian financial institutions must suspend operations on Pavel Durov's domestic accounts following his inclusion in the Rosfinmonitoring terrorist and extremist list on July 30. The restrictions primarily target his personal finances and property inside Russia, as confirmed by attorney Dmitry Roshchin. Telegram itself remains unaffected as a platform because the messenger and its founder are legally distinct entities. Transfers to Durov do not automatically constitute terrorism financing; criminal liability requires proof that the funds were specifically intended for terrorist activities. The FSB has accused Durov of aiding terrorism by failing to remove channels allegedly used by Ukrainian services for sabotage planning, yet he has not been convicted by a court. Media outlets RIA Novosti and Izvestia reported these clarifications on compliance with Russian anti-terrorism legislation.
Russian Ministry Proposes Mandatory Phone-Number Authentication for Foreign Websites and Apps
The Russian Ministry of Digital Development has drafted new rules requiring foreign websites and applications to authenticate users in Russia exclusively through phone numbers. The measure forms part of the third anti-fraud package known as Antifraud 3.0 and would eliminate email, social-media logins and other traditional methods. Foreign service operators would also be obliged to retain registration, login and account-deletion records for three years and to hand them over to Russian law-enforcement agencies upon request. Amendments are planned for Article 8 of the law On Information, with submission to the State Duma scheduled for autumn 2026. Experts warn that many international companies may refuse to build separate authentication flows for the Russian market, potentially leading some services to exit Russia entirely. The proposal also raises enforcement questions for already-blocked platforms such as Facebook and Instagram owned by Meta.
Google's Android Developer Verification Rollout: Implications for Russian Devices and MDM-Managed Phones
Google is introducing mandatory Android Developer Verification on certified devices starting in select countries in September 2026, requiring developers to register and sign apps with verified identities. The policy aims to curb fraudulent and malicious applications by linking package names to registered developer signatures checked via the new Android Developer Verifier system component. Devices without Google services, including many Russian and Chinese firmware builds as well as AOSP variants, remain completely unaffected since the verification mechanism relies on Google Play services. Russia is explicitly excluded from the initial rollout and subsequent waves due to sanctions, allowing continued distribution of in-house and third-party applications. Corporate MDM deployments are also exempt because administrators are considered to have already vetted the apps for safety. Google plans to offer both full registration requiring D-U-N-S numbers for organizations and a limited option for hobbyists capped at 20 devices. The company has already registered SafeMobile as a verified developer, ensuring seamless installation of its client on supported devices.