Habr•August 23, 2026•🇷🇺Translated from Russian

Trusting Russian Root Certificates and Monitoring Domestic CT Logs

The discussion around trust in Russian root certificates issued by the Ministry of Digital Development and Communications has intensified following recent issues with GOST certificates on Gosuslugi. Users are weighing the security implications of adding these roots to system stores, browser profiles, or relying on Yandex Browser where they are pre-installed.

Root certificates themselves do not compromise systems, yet placing them in trusted stores creates a pathway for traffic interception. Entities with access to network flows via the TSPU system can issue intermediate certificates signed by the Russian root and perform real-time MitM attacks against sites such as gmail.com or telegram.org.

Defensive measures remain limited. One approach involves isolating the Russian roots to a dedicated browser profile used only for domestic sites that require them. Advanced configurations can further restrict the roots to specific domains such as *.ru.

Certificate Transparency as a Mitigation

Certificate Transparency logs record every issued certificate in an append-only structure, embedding proof of inclusion inside the certificate. Yandex Browser refuses certificates lacking a valid SCT from approved logs, significantly raising the bar for undetected MitM operations and leaving forensic traces.

Other browsers automatically disable CT verification for chains anchored to manually added roots, treating them as corporate environments. This behavior reduces visibility into potential abuse of Russian intermediates.

Domestic CT Logs

Three primary logs are recognized by Yandex:

  • Yandex Agate Log (2026 and 2027 instances)
  • VK NCA Log (2026 and 2027 instances)
  • Ministry of Digital Development and Communications Log (2026 and 2027 instances)

Log endpoints rotate yearly, and the authoritative list is published at browser-resources.s3.yandex.net/ctlog/ctlog.json.

Verification Tools

Public monitors such as ct.tlscc.ru have shown gaps in coverage for newer log addresses and certain active certificates. A Python utility was developed to fetch the current log list, parse embedded SCTs, reconstruct precertificates, and query each domestic log via the standard CT HTTP API for inclusion proofs.

Related articles

Habr•Policy & Regulation

OBEP Raids on Russian IT Firms: How to Safeguard Source Code, Servers and Blockchain Assets During Searches

Russian IT companies, Web3 projects and fintech services now face frequent visits from OBEP operatives conducting pre-investigative checks or searches under criminal cases. The article details the legal distinction between operational-search measures and formal searches, emphasizing article 164.1 of the UPK RF that prohibits seizure of physical servers in economic crime investigations. It explains how companies can demand data mirroring instead of hardware removal and how to invoke article 51 of the RF Constitution when pressured for encryption keys. Commercial secret regimes are presented as a tool to raise criminal liability for leaks and to request closed court proceedings. Practical checklists cover document verification, staff instructions, password retention and immediate calls to specialized criminal counsel. The guidance aims to prevent business paralysis while preserving evidence integrity during raids.

Habr•Policy & Regulation

RWB Deploys Enterprise-Wide Database Access Control with Trino and Open Policy Agent

RWB has replaced fragmented manual database access processes with a centralized architecture built on Trino as the single entry point and Open Policy Agent for policy enforcement. The system enforces least-privilege access, mandatory auditing, and automated revocation tied to HR records while eliminating anonymous and password-based logins. Access requests now complete in 3–10 minutes instead of an average of four days, with 92 percent handled automatically. Key components include Keycloak for OIDC authentication, Vault for secrets, Kafka for security event streaming to SOC, and Kubernetes orchestration. Responsibility is split across AI & Data Security, Core DevOps, Access Management, SOC, and Trust & Safety teams. More than 1,250 PostgreSQL clusters and 90 projects are now connected, with real-time dashboards tracking adoption and policy health.

AntiMalware•Policy & Regulation

Russia Moves to Allow Biometric Data Processing for Suspects and Convicts Without Consent

Russian law enforcement agencies may soon gain the legal right to process biometric data of suspects, accused individuals, and convicted persons without requiring their personal consent. A corresponding draft bill has already been submitted to the government and is scheduled for review at the next cabinet meeting, according to TASS. The measure covers fingerprints, facial images, voice recordings, and other physiological or behavioral characteristics used for identification. If approved, prior permission from the individual will no longer be needed when biometrics are used in criminal proceedings. The change applies not only to those already convicted but also to suspects and accused persons whose guilt has not yet been established by a court. For ordinary citizens, enrollment in the Unified Biometric System remains voluntary and is used for remote identity verification when accessing financial and government services.

AntiMalware•Policy & Regulation

FAS Clears Russian Operators on 'Unlimited' Internet Claims Despite Speed Throttling to 128 Kbit/s

The Federal Antimonopoly Service has declined to investigate complaints regarding promises of unlimited internet and unrestricted roaming access made by major Russian mobile operators. The Association of Professional Users of Social Networks and Messengers argued that operators including Vimpelcom, MegaFon, MTS, and T2 Mobile mislead customers by advertising unlimited plans while throttling speeds to 128-512 Kbit/s after data caps are reached. FAS determined that information on official company websites does not qualify as advertising under Russian law. Operators maintain that the term unlimited remains accurate because no total data volume limit exists, only speed reductions detailed in service descriptions. The complainants and legal experts contend that FAS reviewed only technical parameter pages and ignored banners, promotional news, search ads, SMS, and push notifications that may meet legal criteria for advertising. The decision leaves consumers facing slow connections unsuitable for video or file downloads after initial allowances are exhausted.