alt.hn

8/3/2026 at 9:33:34 PM

Seven Russian banks have moved to a certificate authority run by the state

https://en.zona.media/article/2026/08/03/cert

by mtty

8/3/2026 at 11:30:00 PM

Based on the timing, I assume this is a direct response to the US state directed revocation of certificates of Iran's Fars News Agency.

by jackb4040

8/3/2026 at 11:23:38 PM

Of course. Who else would be their CA? Some USA state-run CA? That's far too much political risk.

I hope we see a different CA for each ccTLD in the future.

by inigyou

8/3/2026 at 10:51:21 PM

This is probably the future. Who is better able to verify an identity than a state? State run registrars regulate companies. States issue individuals ID documents. If you have trusted central parries issue encryption certificates it will gravitate to fewer and more centralised issuers.

Decentralised systems such as ssh are different, but I find it hard to imagine trusted central authorities ending up as anything other than states, or so heavily regulated as to be effectively state be controlled. This wax always the big flaw in SSL/TLS. In DNS too.

by graemep

8/3/2026 at 10:18:59 PM

Might as well merge them all and call FSBank, for they will be sure as hell MITMing all the communication between clients and backends.

by wartywhoa23

8/3/2026 at 11:24:00 PM

They don't need to. These are politically connected entities.

by inigyou

8/3/2026 at 10:26:26 PM

Nope, MitMing will be done by the SORM system [0] using certificates signed by the Ministry of Digital "Development" which will be trusted the Yandex Browser, which will be widely installed out of necessity by ordinary Russians to access banks and subsequently other Web resources.

Surely this will improve user security and trust in the existing Web PKI system in non-Western countries. /s

[0]: https://en.wikipedia.org/wiki/SORM

by fuoqi

8/3/2026 at 11:26:27 PM

> Surely this will improve user security and trust in the existing Web PKI system in non-Western countries. /s

I recognize that Russia is making this change for MitM spying, but this particular sarcasm seems incorrect. Given Verisign's willingness to bend the knee to Texas courts, one could reasonably lose faith in US PKI issuers such as Digicert. I certainly hope the EU is studying the problem US-controlled EU-trusted issuers — the EU age verification systems hinge critically on them, much less the entire web. So I empathize with the sarcasm, but best not to offer MitM proponents (whether in Russia or the U.S. or elsewhere!) an argument that could be used against your viewpoint.

by altairprime

8/3/2026 at 11:45:13 PM

>I recognize that Russia is making this change for MitM spying

Not really, FSB would love to spy on everyone, but this is caused by certificate revokation and directly helped the FSB. From the article:

>The banks first moved to GlobalSign in 2022. This June, GlobalSign began revoking certificates held by sanctioned Russian companies, and they moved on to HARICA, the Greek academic authority.

>A month ago, HARICA refused to revoke: its issuance is self-service and domain-validated, so its certificates identify a domain and nothing else; it was not, it argued, “the competent authority to make these legal attributions.” However, on July 27, Greece’s eIDAS supervisory body appeared to confirm the disputed certificates had been revoked and referred the case to the national financial sanctions unit.

by orbital-decay