Websites of seven Russian banks have switched to certificates from the National Certification Center of the Digital Development Ministry (Mintsifry), Mediazona reported. The banks are Sber, VTB, Rosselkhozbank, T-Bank, Uralsib, Promsvyazbank, and Bank Saint Petersburg. As of July 31, these sites were still using the Chinese TrustAsia certificate.
T-Bank has moved only its tinkoff.ru domain to the Russian certificate, while its main address tbank.ru continues to use a Let's Encrypt certificate. Bank Levoberezhny has connected the Mintsifry certificate only for its corporate internet banking. Last week, Alfa-Bank's website switched to the Mintsifry certificate.
Because of the switch to the new certificates, the banks' websites have stopped opening automatically in foreign browsers, RBK noted. When trying to access a site through a foreign browser, a warning appears saying "Connection is not secure"; users can proceed via the "Advanced settings" button, but bypassing the warning manually may be unsafe.
This summer, foreign certification centers began mass-revoking certificates from sanctioned Russian state-owned companies. In response, Mintsifry sent out recommendations to switch to its own certificates, saying this would ensure "uninterrupted and secure access" to domestic resources through foreign browsers and would not affect device operation. Independent experts say this is not the case: a Mintsifry certificate installed on a device allows authorities to decrypt traffic of any websites. Kazakhstan's authorities carried out a similar attack in 2019.
Mediazona recommends not installing the Mintsifry certificate. For access to websites that have switched to it, the outlet advises using a separate copy of the Firefox browser, which uses its own certificate store. Alternatively, users can use a Russian browser with pre-installed certificates, but it should be used safely only for visiting Russian websites.