Russian banks dump global security for Mintsifra root certificates
Major players like VTB, Sberbank, and Yandex are forcing users to trust state-issued encryption certificates. Because nothing screams 'financial safety' like turning off standard web security protocols for the entire banking sector.
When major financial institutions like VTB, Sberbank, Alfa-Bank, Rosselkhozbank, Promsvyazbank, Uralsib, and even Yandex Bank collectively abandon standard global security protocols, the internet becomes a digital wild west. The shift mandates that users install the Mintsifra root certificate directly from the Gosuslugi portal. By manually forcing browsers to trust these state-controlled credentials, the institutions are effectively bypassing the standard vetting processes that keep modern web traffic encrypted and verifiable.
Ignoring browser warnings is a gamble with real money, as phishing sites can mimic these specific certificates with minimal effort. While the Firefox workaround allows for isolated browsing profiles, the core issue remains a forced migration away from internationally recognized security standards. Relying on a single government authority for encrypted banking traffic creates a massive point of failure that bypasses traditional cybersecurity defenses.
This move is a masterclass in treating digital infrastructure like a sovereign border—secure, perhaps, but entirely invisible to the rest of the civilized web. Watching a national economy retreat into a proprietary cryptographic bubble is as fascinating as it is terrifying for anyone who prefers their money to stay in their own account rather than becoming a target for the next inevitable man-in-the-middle exploit.
Source: Gosuslugi
Comments
Help shape the next version: Add context or suggest a correction. AI review can add points toward a rewrite. Reviews and updates may take time; a full meter does not guarantee a new version.