AntiMalware•July 30, 2026•🇷🇺Translated from Russian

Russian Ministry Proposes Mandatory Phone-Number Authentication for Foreign Websites and Apps

The Russian Ministry of Digital Development (MinTsifry) has put forward a proposal that would force foreign websites and mobile applications to authenticate users inside Russia solely by mobile-phone number. Traditional login methods such as email or social-network accounts could be removed under the new rules.

The requirement appears in the draft third package of anti-fraud measures titled Antifraud 3.0, according to business daily Vedomosti. In addition to phone-based authentication, owners of overseas resources would have to store registration data, login records and account-deletion information for three years and supply these records to Russian law-enforcement bodies on request.

The changes are intended to be introduced into Article 8 of the federal law On Information. The draft is currently undergoing inter-agency coordination; the government aims to submit the full legislative package to the State Duma in autumn 2026.

Industry observers note that international companies may be reluctant to redesign their authentication systems for a single market. They would need to identify Russian users and implement a separate login flow, an effort some services may decide is not worth the cost. As a result, certain platforms could withdraw from Russia, while some users may choose not to register at all if a phone number is mandatory.

A further complication concerns the definition of a foreign resource operating in Russia. Services such as Facebook and Instagram, both owned by Meta, have already been blocked and declared extremist organisations; their legal operation in the country has ceased, making enforcement of the new obligations practically difficult.

Antifraud 3.0 contains additional provisions, including a ban on disclosing the recipient’s personal data in SMS messages and an expansion of the data sets that telecommunications operators must retain for three years and disclose to special services.

Related articles

Habr•Policy & Regulation

RWB Deploys Enterprise-Wide Database Access Control with Trino and Open Policy Agent

RWB has replaced fragmented manual database access processes with a centralized architecture built on Trino as the single entry point and Open Policy Agent for policy enforcement. The system enforces least-privilege access, mandatory auditing, and automated revocation tied to HR records while eliminating anonymous and password-based logins. Access requests now complete in 3–10 minutes instead of an average of four days, with 92 percent handled automatically. Key components include Keycloak for OIDC authentication, Vault for secrets, Kafka for security event streaming to SOC, and Kubernetes orchestration. Responsibility is split across AI & Data Security, Core DevOps, Access Management, SOC, and Trust & Safety teams. More than 1,250 PostgreSQL clusters and 90 projects are now connected, with real-time dashboards tracking adoption and policy health.

AntiMalware•Policy & Regulation

Russia Moves to Allow Biometric Data Processing for Suspects and Convicts Without Consent

Russian law enforcement agencies may soon gain the legal right to process biometric data of suspects, accused individuals, and convicted persons without requiring their personal consent. A corresponding draft bill has already been submitted to the government and is scheduled for review at the next cabinet meeting, according to TASS. The measure covers fingerprints, facial images, voice recordings, and other physiological or behavioral characteristics used for identification. If approved, prior permission from the individual will no longer be needed when biometrics are used in criminal proceedings. The change applies not only to those already convicted but also to suspects and accused persons whose guilt has not yet been established by a court. For ordinary citizens, enrollment in the Unified Biometric System remains voluntary and is used for remote identity verification when accessing financial and government services.

AntiMalware•Policy & Regulation

FAS Clears Russian Operators on 'Unlimited' Internet Claims Despite Speed Throttling to 128 Kbit/s

The Federal Antimonopoly Service has declined to investigate complaints regarding promises of unlimited internet and unrestricted roaming access made by major Russian mobile operators. The Association of Professional Users of Social Networks and Messengers argued that operators including Vimpelcom, MegaFon, MTS, and T2 Mobile mislead customers by advertising unlimited plans while throttling speeds to 128-512 Kbit/s after data caps are reached. FAS determined that information on official company websites does not qualify as advertising under Russian law. Operators maintain that the term unlimited remains accurate because no total data volume limit exists, only speed reductions detailed in service descriptions. The complainants and legal experts contend that FAS reviewed only technical parameter pages and ignored banners, promotional news, search ads, SMS, and push notifications that may meet legal criteria for advertising. The decision leaves consumers facing slow connections unsuitable for video or file downloads after initial allowances are exhausted.

Habr•Policy & Regulation

Merkle Tree Certificates Proposed to Enable Lightweight Post-Quantum HTTPS in Chrome

Google Chrome developers, together with industry partners and the IETF PLANTS working group, are introducing Merkle Tree Certificates (MTC) as the first HTTPS change designed to address performance challenges of post-quantum cryptography. The new format replaces parts of traditional X.509 certificate chains with compact inclusion proofs inside a Merkle tree whose root is signed by a certificate authority. This approach significantly reduces the size of authentication data exchanged during TLS handshakes while preserving strong post-quantum security properties. MTC also enforces Certificate Transparency by design, making it impossible to issue a public certificate without recording it in a publicly verifiable log. Performance evaluations are currently underway with Cloudflare, and initial public MTC logs operated by experienced CT log providers are planned for early 2027. A dedicated post-quantum Chrome Root Store supporting only MTC is scheduled for the third quarter of 2027 and will run in parallel with the existing root store.