HabrAugust 10, 2026🇷🇺Translated from Russian

EU Extends Chat Control 1.0 Regulation to 2028 Despite Privacy Concerns and Parliamentary Opposition

The European Council has extended the temporary Regulation (EU) 2021/1232, commonly referred to as Chat Control 1.0, until 2028. This regulation permits internet service providers to voluntarily scan unencrypted communications on platforms including Discord and Gmail for CSAM material.

What is Chat Control 1.0

Officially titled the Regulation to Prevent and Combat Child Sexual Abuse, the measure has been in force since 2021. It applies to email and messaging providers, allowing them to conduct voluntary mass scanning of user traffic. Because the regulation is time-limited, periodic extensions are required.

Chat Control 2.0 Proposal

A follow-up proposal, COM(2022) 209, would make scanning mandatory and extend it to encrypted communications. This approach directly conflicts with the principles of end-to-end encryption used in modern messaging services. Privacy advocates argue that the measure would grant authorities access to all private correspondence across Europe.

The Chat Control 2.0 draft is intended as permanent legislation rather than a temporary regime. It remains under active debate in both the European Parliament and the Council.

How the Extension Was Approved

The original deadline for the current regime was April 2026. The European Commission proposed an extension, while the Parliament sought amendments to limit scanning and protect encryption. The Council rejected these changes. A parliamentary vote scheduled for 9 July 2026, the final plenary session before summer recess, saw 112 members absent. The motion to block the extension received 314 votes in favor and 276 against, with 17 abstentions, falling short of the 361-vote threshold needed.

Investigations by Balkan Insight highlighted close links between Commissioner Ilva Johansson's cabinet and the U.S. nonprofit Thorn, a vendor of CSAM detection software, as well as the WeProtect Global Alliance. The European Data Protection Supervisor ruled that targeted advertising promoting the regulation on X in several member states violated EU data-protection rules by excluding users based on political interests.

Related articles

HabrPolicy & Regulation

NIST Bans Periodic Password Rotation While Russia's FSTEC Mandates 90-Day Changes for Government Systems

In July 2025, NIST released the final version of SP 800-63B, explicitly prohibiting periodic password changes with the requirement that verifiers and CSPs shall not require subscribers to change passwords periodically. Eight months later, in April 2026, FSTEC approved a methodological document requiring passwords in state information systems and critical information infrastructure to be changed at least every 90 days, with mobile devices limited to 30 days and no reuse of the last 12 passwords. The requirements originate from Order No. 117, which itself contains no mention of passwords, but delegates details to lower-level methodological documents including the April 2026 guide that defines measure IAF.3. Compliance is enforced through the KZI protected indicator calculation submitted to FSTEC twice a year, with penalties including zeroing of the 0.25 weight group for repeated failures and immediate zeroing during penetration testing. The policy applies to government bodies, state unitary enterprises, institutions, and CII subjects, while commercial organizations outside this scope retain flexibility to set their own policies based on threat models. NIST and FSTEC requirements align closely on minimum length, failed attempt limits, MFA for privileged accounts, and prohibition of default passwords, differing primarily on the rotation mandate.

HabrPolicy & Regulation

Web Certificate Trust Chains and State Access Risks Explained Amid Russian Banking Sanctions

The article explains the hierarchical structure of web certificates used for site authentication and traffic encryption, starting from highly protected root certificates stored in air-gapped facilities with Shamir's secret sharing for key protection. Intermediate certificates extend the chain of trust down to leaf certificates deployed on websites. Russian banks have turned to certificates issued under the MinTsifry root after Western and Chinese CAs refused service due to sanctions. The piece highlights that any nation-state with access to a root private key, whether FSB, NSA, or others, could theoretically issue fraudulent certificates for any domain. It notes the limitations of the X.509 standard, which lacks native support for multi-CA signatures, and suggests that separate browsing environments or PGP-style web-of-trust models could mitigate risks. The author concludes that security is already reduced by reliance on any state-controlled CA and that the choice is ultimately which intelligence agency one prefers to trust.

AntiMalwarePolicy & Regulation

MAX Messenger to Open Source Code and Launch Developer Program for Alternative Clients

The Russian messenger MAX is preparing to open its platform to third-party developers by launching a dedicated developer program and providing API access. Approved participants will receive the official client's source code, design system, technical documentation, and access tokens to integrate with the platform infrastructure. The initiative targets IT companies from Russia and friendly countries that demonstrate experience with large-scale projects and adherence to strict security standards. All selected developers must implement secure development practices, robust encryption mechanisms, and undergo code audits to protect user data. The program supplies ready-made user registration and anti-fraud tools, while alternative clients remain bound by API usage terms focused on security compliance. Applications will be accepted via the official developer portal, although exact launch dates have not yet been disclosed.

HabrPolicy & Regulation

InfoWatch Details ARMA Wall NGFW Development for Industrial Systems Under Russian Import Substitution Rules

InfoWatch has published the second part of its interview series describing the ongoing development of the ARMA Wall next-generation firewall for industrial control systems. The product prioritizes on-premise processing without cloud agents to meet strict customer security policies and certification requirements. Engineers combine proprietary detection feeds with external sources, including indicators from NKCKI, while maintaining hundreds of thousands of signatures without disabling legacy rules for older Siemens controllers. Migration support relies on manual pre-project audits rather than automated tools, and the company works closely with domestic SCADA vendors to embed NGFW capabilities inside long-lifecycle OT environments. ARMA Wall is positioned as a more flexible and cost-effective alternative to data diodes because it allows granular command-level filtering and can emulate one-way traffic when required. The solution is already deployed at Roscosmos subsidiary RKK Energia after full certification and categorization.