Topic

Roskomnadzor

🇷🇺Aug 24

Russia's Data Leak Penalties: 2.6 Million Rubles in Fines Despite 1.58 Billion Records Exposed in 2025

Russia introduced turnover-based fines for personal data leaks through Federal Law 420-FZ in late 2024, fundamentally altering the economics of information security investments. Over the first 18 months, Roskomnadzor opened 52 administrative investigations and issued 40 protocols totaling just 2.6 million rubles in penalties, with zero turnover fines applied. This occurred against a backdrop of 1.58 billion compromised records in 2025 alone. Public data leaks dropped fourfold in the first half of 2026, yet trading activity on underground forums rose nearly 60 percent as operators shifted to private sales. The law now ties penalties directly to the number of affected individuals and adds a turnover component for repeat violations under Article 13.11 of the Code of Administrative Offenses. Analysts note that the mere threat of larger fines has prompted companies to reassess data retention policies and risk models even without actual enforcement precedents.

Habr•Policy & Regulation
🇷🇺Aug 22

Why Legitimate Russian Websites Fail to Load With or Without VPN: TSPU RKN Blocking and MinTsifry Certificates Explained

Russian internet users are experiencing widespread access issues to legitimate domestic websites both when using VPNs and when connecting directly. The problems stem from TSPU devices installed by all ISPs under Roskomnadzor requirements and the transition to national MinTsifry certificates that foreign browsers do not trust. Three distinct error scenarios are documented: ERR_CONNECTION_TIMED_OUT when accessing Russian-IP sites over VPN, ERR_CERT_AUTHORITY_INVALID on major bank sites without VPN, and partial page loading failures caused by TSPU fingerprinting. Solutions for ordinary users include split-tunneling VPN clients, installing MinTsifry root certificates, or switching to Yandex Browser and Chromium-Gost. Website owners are advised to disable TLS 1.3, enable HTTP/2 support, and consider changing server IP addresses if SSH connections are also blocked. The article explicitly excludes any discussion of circumvention methods for prohibited content and focuses only on legal Russian resources as of August 2026.

Habr•Policy & Regulation
🇷🇺Aug 14

How to Detect and Remove Stolen Photos from Fake Profiles, Listings and Ads

Photos are frequently stolen from social networks, old listings, building chats and review sites, then reused in fake profiles, advertisements and rental scams. Russian law under Article 152.1 of the Civil Code protects the right to one's image, while separate copyright rules protect the photographer. Victims are advised to gather strong evidence including full-page screenshots, PDF copies and original files before contacting platforms. Search tools such as Yandex Images, Google Lens and TinEye help locate copies across multiple services. Complaints can be filed directly with site administrators on VKontakte, Odnoklassniki, Avito and Telegram, or escalated to Roskomnadzor and police when personal data or fraud is involved. Preventive steps include lowering image resolution, adding watermarks and restricting album visibility through privacy settings.

Securitylab•Privacy & Surveillance
🇷🇺Aug 5

FAS Case Against Apple Will Not Brick iPhones for Russian Users

The Russian Federal Antimonopoly Service (FAS) has opened a case against Apple for failing to pre-install a national messenger and a Russian app store on iOS devices, yet officials have confirmed that no technical measures will disable or restrict existing iPhones. Deputy Chairman of the State Duma Committee on Information Policy Andrey Svintsov stated that the actions of FAS, Roskomnadzor and other agencies are limited to recording violations and collecting fines. Apple had already implemented the option to select a domestic search engine but did not meet the remaining pre-installation requirements. Svintsov emphasized that any court decisions will remain in force until Apple decides to return to the Russian market and settles accumulated penalties. The approach is designed to replenish the state budget through fines once the company resumes legal operations. Russian iPhone owners can continue using their devices without any risk of remote blocking or forced conversion into expensive paperweights.

AntiMalware•Policy & Regulation
🇷🇺Aug 4

Over 20 VPN Services Hit by Outages After Russian Regulators Block Hosting Provider Subnets

Users of multiple VPN services reported widespread connection problems throughout the day as IP addresses belonging to several large hosting providers were placed under restrictions. The blocks targeted infrastructure used by VPNs to reroute traffic around content filters, causing entire ranges of servers to become inaccessible when whole subnets were affected. The Telegram channel Exploit reported that more than 20 VPN services of varying sizes experienced disruptions, though Roskomnadzor has not issued an official statement on the scope or origin of the measures. The affected providers indicated they are shifting customers to backup servers, noting that the restrictions appear selective yet still force frequent address changes during the day. The incidents coincide with ongoing discussions of new rules that would require hosting providers to independently detect and report masked VPN IP addresses to regulators. Similar large-scale subnet blocks occurred in late May, impacting numerous MTProto-based proxies and VPNs simultaneously.

AntiMalware•Policy & Regulation
🇷🇺Aug 1

TSPU Filtering Disrupts Timeweb Cloud Servers: Diagnosis, CDN Failures, and Reverse Proxy Bypass

Russian hosting provider Timeweb Cloud experienced widespread TSPU-based DPI filtering starting in early June that selectively blocked TLS handshakes on port 443 while leaving SSH, ICMP, and TCP connectivity intact. The issue affected multiple providers including Beget and Selectel, was publicly acknowledged by Timeweb on June 5, and proved highly variable by region, operator, and time of day. Attempts to mitigate via new IP addresses or Timeweb's own CDN failed due to poisoned caches and platform outages, while Yandex Cloud CDN blocked all POST requests required for WordPress functionality. A working solution involved deploying a minimal nginx reverse proxy on another Russian cloud VPS that preserves full HTTP methods, handles certificate synchronization, and routes ACME challenges correctly. Timeweb support later closed tickets without resolution after requesting ineffective mtr traces that cannot detect DPI behavior. The case highlights systemic challenges in diagnosing state-mandated filtering and the limitations of standard network diagnostics against selective TLS interference.

Habr•Privacy & Surveillance
🇷🇺Jul 29

Russian Users Report BiP and KakaoTalk Inaccessible Without VPN, Suspecting Roskomnadzor Filtering

Russian home users have started complaining about disruptions in BiP and KakaoTalk messenger services. Messages fail to send or receive without a VPN connection, but function normally once a VPN is enabled. The issue reportedly began three days ago and affects the author, relatives, and friends according to a Pikabu post. Beeline support denied any operator-side restrictions, and Roskomnadzor has issued no official statement on blocking the services. Similar reports have emerged from other users, including those in the Volga region, with the consistent symptom that direct connections fail while VPN routes succeed. No independent technical confirmation of traffic filtering exists yet, and complaints may relate to specific operators, regions, or service infrastructure. The pattern matches previous Russian experiences with content filtering, though official confirmation of any block on BiP or KakaoTalk remains absent.

AntiMalware•Privacy & Surveillance
🇷🇺Jul 25

Russia's Article 10.1 on Personal Data Dissemination: Apparent and Real Contradictions in Federal Law 152-FZ

Part II of the analysis examines how the rushed redrafting of Article 10.1 between the first and second readings created serious interpretive problems in Federal Law 152-FZ. The core issues include undefined terms such as 'disclosure', conflicting definitions of 'access', 'provision' and 'dissemination' between 152-FZ and 149-FZ, and the removal of the legal basis for processing publicly available data while retaining the consent mechanism that was meant to control it. Courts have consistently held that mere openness of data does not constitute a valid processing ground, forcing subsequent operators to find their own basis under Article 6. The article highlights that the mechanism for subjects to set conditions and prohibitions was preserved, yet the underlying legal foundation that would make those rules effective was eliminated. Two possible readings of the special consent are explored, with judicial practice leaning toward the narrower interpretation that leaves conditions and prohibitions as mere additional restrictions rather than a source of authorization.

Habr•Policy & Regulation
🇷🇺Jul 25

Why Deep Packet Inspection Overestimates Its Reach in Encrypted Networks

Modern encryption has fundamentally limited the effectiveness of Deep Packet Inspection systems, leaving network monitors with only metadata and behavioral patterns rather than actual content. DPI tools can still classify traffic types and apply policies based on visible flow characteristics, but they cannot read messages, files, or credentials inside properly encrypted sessions without explicit TLS inspection. The article details how TLS 1.3, Encrypted Client Hello, and QUIC further reduce passive visibility while corporate inspection remains possible only when endpoint devices trust an organizational certificate. Russian regulatory requirements around TSPU systems are discussed separately from corporate DPI use, with emphasis on the need for technical confirmation rather than assumptions. The piece also clarifies distinctions between DPI, IDS, IPS, and DLP, and explains why machine learning cannot convert metadata into decrypted payloads. Overall, the analysis shows that DPI remains useful for traffic management and known-threat detection where visibility exists, but it cannot serve as a complete security foundation.

Securitylab•Policy & Regulation
🇷🇺Jul 25

How Russia's Article 10.1 on Personal Data Dissemination Emerged: Legislative History and Reform Flaws

The article examines the origins of Article 10.1 in Federal Law 152-FZ, introduced via bill 1057337-7 by deputy Anton Gorelk in in November 2020. It traces how the reform aimed to separate publication, access, extraction, and reuse of personal data but retained outdated definitions from the original law and added exceptions that created contradictions. The piece details pre-reform court rulings, including Supreme Court decisions confirming that open internet profiles do not automatically qualify as publicly available data under Article 8. It highlights the committee's own admission that the bill failed to meet its stated goals and the Legal Department's warning about inconsistent terminology around 'access' and 'transfer'. The resulting 519-FZ law is described as an imprecise attempt to solve real control problems with unsuitable conceptual tools, leaving operators unable to apply the rules consistently.

Habr•Policy & Regulation
🇷🇺Jul 20

Russian Users Report Widespread App Store Outages as Roskomnadzor Denies Any Role in Restricting Access

Russian users began experiencing technical problems with the App Store starting early in the day, with the monitoring service Sboy.rf receiving 251 complaints about instability and failed downloads. The majority of reports originated from Moscow, accounting for 20 percent of cases, followed by Saint Petersburg at 13 percent and several other regions including Udmurtia, Kursk, Rostov, Bryansk oblasts and Stavropol Krai each contributing 5 percent. Affected users described inconsistent behavior of the App Store application itself along with difficulties downloading games and other software, where the Get button would appear but actual downloads would succeed only sporadically. In response to the growing number of reports, Roskomnadzor quickly issued a brief statement clarifying that it is not imposing any restrictions on access to the App Store. The exact cause of the disruptions remains unknown, Apple has not provided any official comment, and the scale of the incident is considered limited since only several hundred users have reported issues and not everyone is affected. Standard troubleshooting steps such as verifying internet connectivity, restarting the App Store application, and waiting for service restoration have been recommended to users.

AntiMalware•Policy & Regulation