AntiMalwareAugust 3, 2026🇷🇺Translated from Russian

Yandex Alice AI Replaces VK Marusya in Russia's Mandatory Preinstalled Apps List for 2027

Russian authorities have approved the official list of programs that manufacturers and sellers must preinstall on smartphones, tablets, and computers in 2027.

The updated requirements maintain most previous selections without major disruption to the overall structure of mandatory software.

The only notable change involves voice assistants: Yandex Alice AI will replace VK Marusya in the mandatory preinstallation category.

This policy continues Russia's long-standing approach of requiring domestic applications on devices sold within the country to support local technology developers.

Preinstallation obligations cover a range of software categories, ensuring that Russian alternatives receive default visibility on new hardware.

Related articles

HabrPolicy & Regulation

Password Rotation Policies Under Scrutiny: NIST Guidelines, Historical Origins, and Logical Flaws

The article examines the long-standing practice of mandatory password rotation every 90 days, contrasting it with modern recommendations from NIST that advocate changing passwords only upon confirmed compromise rather than on a fixed schedule. It dissects common arguments in favor of periodic rotation, such as limiting offline hash cracking time and terminating unknown sessions, and demonstrates how these rely on reverse logic that starts from the control rather than from actual threats. Historical analysis traces the 90-day rule back to the 1985 DoD Green Book (CSC-STD-002-85), revealing that its own calculations showed password lifetime has minimal impact on security when proper rate limiting is in place. The piece distinguishes between data leakage and credential compromise, emphasizing that internal organizational signals provide far better indicators for targeted password changes than public breach databases. It concludes that scheduled rotation only makes sense as a substitute for mature detection capabilities, a trade-off explicitly recognized in PCI DSS v4.0.

AntiMalwarePolicy & Regulation

FSB Russia Certifies Rutoken Chip 3127 with Five-Year Cryptographic Key Validity

Aktiv has received an FSB Russia certificate for the embedded Rutoken Chip 3127 microcontroller under security classes KS1 and KS2. The certification followed additional research that extended the validity period of the device's private cryptographic keys to five years. The chip belongs to the Rutoken ECP 3.0 3127 product line and targets long-term cryptographic protection in servers, ATMs, workstations, tablets, biometric systems, industrial equipment, and IoT devices. It stores keys in non-extractable form, performs user and device authentication, verifies component integrity, and supports trusted boot processes by controlling executable code at each stage. Additional capabilities include data encryption, derivation of session keys, secure software updates, and protected TLS and VPN connections using the CRISP protocol that complies with GOST R 71252-2024. The chip incorporates hardware-level defenses such as voltage monitoring, protective layer detection, and dummy branch execution to counter physical tampering and side-channel attacks. Pilot deployments have already occurred, including integration into the OVISION biometric access control systems, paving the way for serial use in critical infrastructure.

AntiMalwarePolicy & Regulation

Durov's Addition to Terrorist List Triggers Russian Account Blocks but Does Not Automatically Ban Telegram or Classify Transfers as Terrorism Financing

Russian financial institutions must suspend operations on Pavel Durov's domestic accounts following his inclusion in the Rosfinmonitoring terrorist and extremist list on July 30. The restrictions primarily target his personal finances and property inside Russia, as confirmed by attorney Dmitry Roshchin. Telegram itself remains unaffected as a platform because the messenger and its founder are legally distinct entities. Transfers to Durov do not automatically constitute terrorism financing; criminal liability requires proof that the funds were specifically intended for terrorist activities. The FSB has accused Durov of aiding terrorism by failing to remove channels allegedly used by Ukrainian services for sabotage planning, yet he has not been convicted by a court. Media outlets RIA Novosti and Izvestia reported these clarifications on compliance with Russian anti-terrorism legislation.

AntiMalwarePolicy & Regulation

Russian Ministry Proposes Mandatory Phone-Number Authentication for Foreign Websites and Apps

The Russian Ministry of Digital Development has drafted new rules requiring foreign websites and applications to authenticate users in Russia exclusively through phone numbers. The measure forms part of the third anti-fraud package known as Antifraud 3.0 and would eliminate email, social-media logins and other traditional methods. Foreign service operators would also be obliged to retain registration, login and account-deletion records for three years and to hand them over to Russian law-enforcement agencies upon request. Amendments are planned for Article 8 of the law On Information, with submission to the State Duma scheduled for autumn 2026. Experts warn that many international companies may refuse to build separate authentication flows for the Russian market, potentially leading some services to exit Russia entirely. The proposal also raises enforcement questions for already-blocked platforms such as Facebook and Instagram owned by Meta.