Topic

MinTsifry

🇷🇺Aug 22

Why Legitimate Russian Websites Fail to Load With or Without VPN: TSPU RKN Blocking and MinTsifry Certificates Explained

Russian internet users are experiencing widespread access issues to legitimate domestic websites both when using VPNs and when connecting directly. The problems stem from TSPU devices installed by all ISPs under Roskomnadzor requirements and the transition to national MinTsifry certificates that foreign browsers do not trust. Three distinct error scenarios are documented: ERR_CONNECTION_TIMED_OUT when accessing Russian-IP sites over VPN, ERR_CERT_AUTHORITY_INVALID on major bank sites without VPN, and partial page loading failures caused by TSPU fingerprinting. Solutions for ordinary users include split-tunneling VPN clients, installing MinTsifry root certificates, or switching to Yandex Browser and Chromium-Gost. Website owners are advised to disable TLS 1.3, enable HTTP/2 support, and consider changing server IP addresses if SSH connections are also blocked. The article explicitly excludes any discussion of circumvention methods for prohibited content and focuses only on legal Russian resources as of August 2026.

Habr•Policy & Regulation
🇷🇺Aug 13

Russia to Require Independent Lab Testing of Sovereign AI Models for Legal and Traditional Values Compliance

The Russian Ministry of Digital Development is discussing a certification scheme under which developers can submit large generative AI models to accredited independent laboratories. These labs will verify compliance with Russian legislation and traditional spiritual-moral values defined in presidential decree No. 809. Only models seeking official national or sovereign status, which unlocks state support, data access and priority procurement, will undergo the process. Developers must first conduct self-testing according to a risk-oriented methodology and supply architecture details, filtering mechanisms and other documentation. Accredited laboratories will then run benchmarks, attempt prompt-injection attacks and produce evaluation reports, while the final decision remains with MinTsifry. Separate security assessments for government systems will be performed by the FSB and FSTEC Russia. Experts have called for transparent, reproducible tests and periodic re-certification after model updates.

AntiMalware•Policy & Regulation
🇷🇺Aug 7

Web Certificate Trust Chains and State Access Risks Explained Amid Russian Banking Sanctions

The article explains the hierarchical structure of web certificates used for site authentication and traffic encryption, starting from highly protected root certificates stored in air-gapped facilities with Shamir's secret sharing for key protection. Intermediate certificates extend the chain of trust down to leaf certificates deployed on websites. Russian banks have turned to certificates issued under the MinTsifry root after Western and Chinese CAs refused service due to sanctions. The piece highlights that any nation-state with access to a root private key, whether FSB, NSA, or others, could theoretically issue fraudulent certificates for any domain. It notes the limitations of the X.509 standard, which lacks native support for multi-CA signatures, and suggests that separate browsing environments or PGP-style web-of-trust models could mitigate risks. The author concludes that security is already reduced by reliance on any state-controlled CA and that the choice is ultimately which intelligence agency one prefers to trust.

Habr•Policy & Regulation
🇷🇺Aug 4

Over 20 VPN Services Hit by Outages After Russian Regulators Block Hosting Provider Subnets

Users of multiple VPN services reported widespread connection problems throughout the day as IP addresses belonging to several large hosting providers were placed under restrictions. The blocks targeted infrastructure used by VPNs to reroute traffic around content filters, causing entire ranges of servers to become inaccessible when whole subnets were affected. The Telegram channel Exploit reported that more than 20 VPN services of varying sizes experienced disruptions, though Roskomnadzor has not issued an official statement on the scope or origin of the measures. The affected providers indicated they are shifting customers to backup servers, noting that the restrictions appear selective yet still force frequent address changes during the day. The incidents coincide with ongoing discussions of new rules that would require hosting providers to independently detect and report masked VPN IP addresses to regulators. Similar large-scale subnet blocks occurred in late May, impacting numerous MTProto-based proxies and VPNs simultaneously.

AntiMalware•Policy & Regulation
🇷🇺Aug 4

Russia's MinTsifry Proposes Hosting Providers Detect and Report Disguised VPN Services

The Russian Ministry of Digital Development is discussing measures to strengthen oversight of VPN services that mask themselves as legitimate websites and hide their IP addresses from official blocklists. Hosting providers would be required to independently identify suspicious IP addresses and report them to regulators for potential blocking. The proposal also introduces a tiered trust system for hosting clients based on the strength of their identity verification. Users authenticated only via phone or bank card could have services terminated within 30 minutes upon violations, while those verified through Gosuslugi or biometric systems would receive more time to resolve issues. Non-compliant hosting providers risk being labeled as unreliable, resulting in restrictions that limit client access to a narrow whitelist of approved resources such as government portals, banks, and marketplaces. Industry participants warn that these restrictions could worsen IPv4 address shortages and drive legitimate businesses toward foreign hosting providers.

AntiMalware•Policy & Regulation
🇷🇺Jul 13

Russia to Mandate Gosuslugi Authentication for Hosting Providers, Further Reducing Anonymity in Runet

The Russian Ministry of Digital Development (MinTsifry) is advancing plans to require all hosting providers to identify clients exclusively through the Gosuslugi portal and the ESIA system. The measure aims to ensure that every allocated IP address is linked to a verified individual, going beyond current methods such as email or bank card verification. This approach mirrors the identification rules already enforced since September for .ru, .рф, and .su domain registrations and renewals. Industry reactions are divided: while some providers like Turbo Cloud support the initiative for combating fraud, others warn of high implementation costs and significant client losses. Smaller users, including students and independent developers, may migrate to foreign hosting services, and foreigners could face restricted access without alternative verification options.

AntiMalware•Policy & Regulation