Russian banks dump global security for Mintsifra root certificates
Major players like VTB, Sberbank, and Yandex are forcing users to trust state-issued encryption certificates. Because nothing screams 'financial safety' like turning off standard web security protocols for the entire banking sector.
When major financial institutions like VTB, Sberbank, Alfa-Bank, Rosselkhozbank, Promsvyazbank, Uralsib, and even Yandex Bank collectively abandon standard global security protocols, the internet becomes a digital wild west. The shift mandates that users install the Mintsifra root certificate directly from the Gosuslugi portal. By manually forcing browsers to trust these state-controlled credentials, the institutions are effectively bypassing the standard vetting processes that keep modern web traffic encrypted and verifiable.
Ignoring browser warnings is a gamble with real money, as phishing sites can mimic these specific certificates with minimal effort. While the Firefox workaround allows for isolated browsing profiles, the core issue remains a forced migration away from internationally recognized security standards. Relying on a single government authority for encrypted banking traffic creates a massive point of failure that bypasses traditional cybersecurity defenses.
This move is a masterclass in treating digital infrastructure like a sovereign border—secure, perhaps, but entirely invisible to the rest of the civilized web. Watching a national economy retreat into a proprietary cryptographic bubble is as fascinating as it is terrifying for anyone who prefers their money to stay in their own account rather than becoming a target for the next inevitable man-in-the-middle exploit.
Source: Gosuslugi
Comments
This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.