HTTPState. Seven Russian banks have moved to a certificate authority run by the state, which also helps sifting through users’ traffic

This is a proxy service. All materials and rights belong to their respective authors. Visit the original site here.

Article
3 August 2026, 20:25

HTTPState. Seven Russian banks have moved to a certificate authority run by the state, which also helps sifting through users’ traffic

Photo: Mediazona

This week, the websites of major Russian banks—Sber, VTB, Rosselkhozbank, T-Bank, Uralsib, Promsvyazbank and Bank Saint Petersburg—began serving TLS certificates issued by Russia’s Ministry of Digital Development, Mediazona discovered. Just last week, on July 31, all of them were still using certificates from the Chinese authority TrustAsia.

The migration is uneven. T-Bank moved only tinkoff.ru, which references the bank’s more common older name, leaving tbank.ru still on US-based Let’s Encrypt certificate. Levoberezhny bank switched only its business banking. Alfa-Bank made the jump last week.

No major browser trusts the Ministry’s root—so the Ministry is asking users to install it manually, describing the step as “safe” and as having no effect on how devices function.

Once a root certificate is installed, it can vouch for any domain—not just the bank a person installed it to reach, but Gmail, iCloud, a messaging service, a news site. The browser accepts the result silently, because the user told it to. And the agency making the request already operates the network the traffic crosses: TSPU deep-packet-inspection equipment sits inline at Russian ISPs while state DNS resolvers can redirect a hostname to a server of their choosing.

The state root has existed since March 2022, launched after DigiCert and Thawte began dropping sanctioned Russian customers, but amid widespread suspicion the adoption lagged (Kazakhstan tried this in 2019, issuing a state certificate and instructing citizens to install it, but Apple, Google and Mozilla blocked the certificate outright because it allowed the state to sift through users’ traffic).

The banks first moved to GlobalSign in 2022. This June, GlobalSign began revoking certificates held by sanctioned Russian companies, and they moved on to HARICA, the Greek academic authority.

A month ago, HARICA refused to revoke: its issuance is self-service and domain-validated, so its certificates identify a domain and nothing else; it was not, it argued, “the competent authority to make these legal attributions.” However, on July 27, Greece’s eIDAS supervisory body appeared to confirm the disputed certificates had been revoked and referred the case to the national financial sanctions unit. Within days, the affected companies had moved again, to China’s TrustAsia.

Russia’s banks have been running a similar playbook against Apple for four years. In 2022 Apple terminated the developer accounts of Sberbank, Alfa-Bank, VTB, Promsvyazbank, Sovcombank and others due to Western sanctions, and pulled their apps worldwide. The banks came back in disguise, repackaging their apps as coupon trackers, online games or gift advisors, published by individual developers and advertised internally to their clients to install quickly before removal.

Mediazona won’t survive without you

We are in a difficult position: we still haven’t recovered our pre-war funding levels. Our goal right now is to reach 7,500 subscriptions from international supporters. Only you, our readers, can save Mediazona

Donate now
Donate now
Load more