cross-posted from: https://scribe.disroot.org/post/10554455

This week, the websites of major Russian banks—Sber, VTB, Rosselkhozbank, T-Bank, Uralsib, Promsvyazbank and Bank Saint Petersburg—began serving TLS certificates issued by Russia’s Ministry of Digital Development, Mediazona discovered. Just last week, on July 31, all of them were still using certificates from the Chinese authority TrustAsia.

The migration is uneven. T-Bank moved only tinkoff.ru, which references the bank’s more common older name, leaving tbank.ru still on US-based Let’s Encrypt certificate. Levoberezhny bank switched only its business banking. Alfa-Bank made the jump last week.

(T-bank, widely known as Tinkoff, dropped its founder’s name in 2024, two years after Oleg Tinkov denounced the invasion of Ukraine. Tinkov says he was pressured into selling his stake at 3% of its value. He renounced his Russian citizenship later that year, left the country and was subsequently designated a “foreign agent”.)

No major browser trusts the Ministry’s root—so the Ministry is asking users to install it manually, describing the step as “safe” and as having no effect on how devices function.

Once a root certificate is installed, it can vouch for any domain—not just the bank a person installed it to reach, but Gmail, iCloud, a messaging service, a news site. The browser accepts the result silently, because the user told it to. And the agency making the request already operates the network the traffic crosses: TSPU deep-packet-inspection equipment sits inline at Russian ISPs while state DNS resolvers can redirect a hostname to a server of their choosing.

Archived

  • Sims@lemmy.ml
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    2
    ·
    2 hours ago

    More ignorant Epstein propaganda from the well-known US state-sponsored propaganda site ‘mediazona’. I wonder how all the Russia haters reconcile with the fact that the Epstein psycho class earn their money and get their power by convincing every Merican that ‘Russia baad’, ‘Iran baad’, ‘Venezuela baad’, ‘China baad’, ‘Palestine/gaza baad’ and so on and on.

    I mean at some point even the dumbest hardcore Epstein believer/supporter will have to wonder if this is all true, or if some of it could be manipulation ? …and if some are manipulation… where does it stop ??

    Well, if the propagandized Russophobes could at least TRY to review the claims from the US state propaganda apparatus before attacking other nations, or at least TRY to learn the counter arguments to the simplistic ‘Russia baad’ narrative: https://www.youtube.com/playlist?list=PL6-hcqTF_eSc6PIdk3QIwtoxtTK1wr30y

    But we all know that won’t happen. …I guess hate/anger insulates people from the truth, and keeps them going despite lack of reasonable evidence/facts. Pure ‘lynch mob’ mentality.

    Well played by the Western Oligarchy swines, well played…

  • dondelelcaro@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    15 hours ago

    Controlling the certs doesn’t control the keys. Access to the keys is necessary to inspect the traffic. Even without government control of the root certificates, if they can access the keys, they can decrypt the traffic.

    Now, controlling the certs can open you up to MITM, but that’s a risk no matter who controls the root.

  • coolasbreeze@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    19 hours ago

    This is just how root certificates work no? The assumption that the Russians will abuse this is just as valid for any US company, given what we know form the Snowden leaks.

  • kungen@feddit.nu
    link
    fedilink
    English
    arrow-up
    1
    ·
    15 hours ago

    In 2021, Tinkov had complications after surgery and his chances of survival were estimated at only 40%

    he publicly criticized the Russian invasion of Ukraine in April 2022

    July 2022: his cancer went into remission

    Wow, I didn’t realize oligarchs could pay off their karma that easily. I wonder why more don’t do it.