this post was submitted on 05 Aug 2026
73 points (92.0% liked)

Technology

86918 readers
3637 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

cross-posted from: https://scribe.disroot.org/post/10554455

This week, the websites of major Russian banks—Sber, VTB, Rosselkhozbank, T-Bank, Uralsib, Promsvyazbank and Bank Saint Petersburg—began serving TLS certificates issued by Russia’s Ministry of Digital Development, Mediazona discovered. Just last week, on July 31, all of them were still using certificates from the Chinese authority TrustAsia.

...

The migration is uneven. T-Bank moved only tinkoff.ru, which references the bank’s more common older name, leaving tbank.ru still on US-based Let’s Encrypt certificate. Levoberezhny bank switched only its business banking. Alfa-Bank made the jump last week.

...

(T-bank, widely known as Tinkoff, dropped its founder’s name in 2024, two years after Oleg Tinkov denounced the invasion of Ukraine. Tinkov says he was pressured into selling his stake at 3% of its value. He renounced his Russian citizenship later that year, left the country and was subsequently designated a “foreign agent”.)

...

No major browser trusts the Ministry’s root—so the Ministry is asking users to install it manually, describing the step as “safe” and as having no effect on how devices function.

Once a root certificate is installed, it can vouch for any domain—not just the bank a person installed it to reach, but Gmail, iCloud, a messaging service, a news site. The browser accepts the result silently, because the user told it to. And the agency making the request already operates the network the traffic crosses: TSPU deep-packet-inspection equipment sits inline at Russian ISPs while state DNS resolvers can redirect a hostname to a server of their choosing.

...

Archived

you are viewing a single comment's thread
view the rest of the comments
[–] coolasbreeze@lemmy.world 17 points 1 day ago (1 children)

This is just how root certificates work no? The assumption that the Russians will abuse this is just as valid for any US company, given what we know form the Snowden leaks.

[–] esc@piefed.social 3 points 1 day ago

That's how root certs work, m*scovians will abuse it.