Topic
MinTsifry

Why Legitimate Russian Websites Fail to Load With or Without VPN: TSPU RKN Blocking and MinTsifry Certificates Explained
Policy & Regulation
Russia to Require Independent Lab Testing of Sovereign AI Models for Legal and Traditional Values Compliance
Policy & Regulation
Web Certificate Trust Chains and State Access Risks Explained Amid Russian Banking Sanctions
Policy & RegulationOver 20 VPN Services Hit by Outages After Russian Regulators Block Hosting Provider Subnets
Users of multiple VPN services reported widespread connection problems throughout the day as IP addresses belonging to several large hosting providers were placed under restrictions. The blocks targeted infrastructure used by VPNs to reroute traffic around content filters, causing entire ranges of servers to become inaccessible when whole subnets were affected. The Telegram channel Exploit reported that more than 20 VPN services of varying sizes experienced disruptions, though Roskomnadzor has not issued an official statement on the scope or origin of the measures. The affected providers indicated they are shifting customers to backup servers, noting that the restrictions appear selective yet still force frequent address changes during the day. The incidents coincide with ongoing discussions of new rules that would require hosting providers to independently detect and report masked VPN IP addresses to regulators. Similar large-scale subnet blocks occurred in late May, impacting numerous MTProto-based proxies and VPNs simultaneously.
Russia's MinTsifry Proposes Hosting Providers Detect and Report Disguised VPN Services
The Russian Ministry of Digital Development is discussing measures to strengthen oversight of VPN services that mask themselves as legitimate websites and hide their IP addresses from official blocklists. Hosting providers would be required to independently identify suspicious IP addresses and report them to regulators for potential blocking. The proposal also introduces a tiered trust system for hosting clients based on the strength of their identity verification. Users authenticated only via phone or bank card could have services terminated within 30 minutes upon violations, while those verified through Gosuslugi or biometric systems would receive more time to resolve issues. Non-compliant hosting providers risk being labeled as unreliable, resulting in restrictions that limit client access to a narrow whitelist of approved resources such as government portals, banks, and marketplaces. Industry participants warn that these restrictions could worsen IPv4 address shortages and drive legitimate businesses toward foreign hosting providers.
Russia to Mandate Gosuslugi Authentication for Hosting Providers, Further Reducing Anonymity in Runet
The Russian Ministry of Digital Development (MinTsifry) is advancing plans to require all hosting providers to identify clients exclusively through the Gosuslugi portal and the ESIA system. The measure aims to ensure that every allocated IP address is linked to a verified individual, going beyond current methods such as email or bank card verification. This approach mirrors the identification rules already enforced since September for .ru, .рф, and .su domain registrations and renewals. Industry reactions are divided: while some providers like Turbo Cloud support the initiative for combating fraud, others warn of high implementation costs and significant client losses. Smaller users, including students and independent developers, may migrate to foreign hosting services, and foreigners could face restricted access without alternative verification options.