AntiMalwareAugust 3, 2026🇷🇺Translated from Russian

Russia's FAS Opens Antitrust Case Against Apple for Failing to Pre-Install Domestic Software on iOS Devices

Federal Antimonopoly Service has opened an antitrust case against Apple after the corporation failed to implement a formal warning regarding the mandatory pre-installation of Russian software on iPhone and iPad devices.

The dispute centers on iOS compliance with Russian legislation that requires device manufacturers to enable the use of search services from Russia or other Eurasian Economic Union countries. Initially, Apple devices shipped with a foreign search engine set as default, prompting regulatory action.

Although Apple later stated that an updated version of its software added the option to pre-install a Russian search engine, this measure proved insufficient. According to the FAS, the company still did not fulfill requirements to install the national messenger application and the domestic app store on its devices.

The official warning was issued to Apple on July 1. Because the demands remained unmet, the authority escalated from a warning to formal proceedings. If the violation of competition protection law is confirmed, the company will face an administrative fine under the Code of Administrative Offenses of the Russian Federation, with the amount potentially reaching 4 billion rubles.

In parallel, the Russian government has already approved the official list of domestic applications that must be pre-installed on smartphones and tablets beginning January 1, 2027. The mandatory list for mobile devices includes RuStore, Max, Yandex Browser, Alice AI, VKontakte, Gosuslugi, Mir Pay, Mail.ru, 2GIS and additional services.

Related articles

HabrPolicy & Regulation

Why Sending an MDM Command Does Not Mean It Has Been Executed

MDM operations such as policy assignment and device lock appear synchronous in the console but actually trigger complex asynchronous delivery chains involving backends, queues, vendor infrastructure, and device agents. The article explains that request acceptance, queue storage, external API confirmation, and actual device execution represent four distinct states that must be tracked separately. Aitera MDM implements an Outbox pattern to ensure transactional consistency between policy changes and command delivery while supporting at-least-once semantics with idempotency. Android Enterprise relies on the Android Management API and Google-controlled synchronization through Android Device Policy, whereas iOS uses APNs only for wake-up and pull-based command retrieval with statuses including Acknowledged, Error, and NotNow. The system maintains separate desired, delivery, and observed states to avoid misleading applied flags and provides detailed command history for administrators. Metrics focus on policy confirmation rates, queue age, and divergence between intended and actual device configurations rather than simple device counts.

AntiMalwarePolicy & Regulation

Russia Drafts Rules Letting Users Choose AI Assistant at Smartphone First Boot

The Russian Ministry of Digital Development has published a draft government resolution that would replace the existing voice assistant pre-installation requirement with a broader category called system assistant. The new rules would allow users to select a domestic, foreign, or no AI assistant when first powering on a smartphone. The system assistant is defined as an AI program capable of controlling the device, operating system, and applications through voice, text, and visual commands. Manufacturers would be required to give the chosen assistant equal treatment regarding updates, settings, and interface visibility, and the pre-installed version must remain free and persist after factory resets. Search services could also incorporate AI technologies under the updated list. The ministry states the changes aim to increase competition between Russian and foreign platforms while preserving user access to modern AI services even if certain foreign products face restrictions.

HabrPolicy & Regulation

Password Rotation Policies Under Scrutiny: NIST Guidelines, Historical Origins, and Logical Flaws

The article examines the long-standing practice of mandatory password rotation every 90 days, contrasting it with modern recommendations from NIST that advocate changing passwords only upon confirmed compromise rather than on a fixed schedule. It dissects common arguments in favor of periodic rotation, such as limiting offline hash cracking time and terminating unknown sessions, and demonstrates how these rely on reverse logic that starts from the control rather than from actual threats. Historical analysis traces the 90-day rule back to the 1985 DoD Green Book (CSC-STD-002-85), revealing that its own calculations showed password lifetime has minimal impact on security when proper rate limiting is in place. The piece distinguishes between data leakage and credential compromise, emphasizing that internal organizational signals provide far better indicators for targeted password changes than public breach databases. It concludes that scheduled rotation only makes sense as a substitute for mature detection capabilities, a trade-off explicitly recognized in PCI DSS v4.0.

AntiMalwarePolicy & Regulation

Yandex Alice AI Replaces VK Marusya in Russia's Mandatory Preinstalled Apps List for 2027

Russian authorities have approved the official list of software that device manufacturers and sellers must preinstall on smartphones, tablets, and computers starting in 2027. The updated requirements maintain most of the previous selections without major disruption. The only notable change involves voice assistants, where Yandex Alice AI will now take the place previously held by VK Marusya. This adjustment reflects ongoing government efforts to promote domestic software through mandatory preinstallation policies. The regulation continues to focus on ensuring Russian-developed applications receive prominent placement on new devices sold in the country.