You know that little padlock icon in your browser? The one that tells you your connection is “secure”? It’s becoming a lie — and seven Russian banks just proved it.
This week, seven major Russian banks quietly migrated to a certificate authority operated by the Russian state. In plain English: the government is now the entity that says “yes, this bank’s website is really the bank’s website.” Not Verisign. Not Let’s Encrypt. Not some independent, internationally trusted authority. The state.
When the entity that verifies trust is also the entity that can systematically break it, you don’t have security. You have a surveillance apparatus wearing a padlock as a costume.
Here’s what’s actually happening under the hood. Every time you connect to your bank online, your browser checks a cryptographic certificate to confirm the server is legitimate. This is the backbone of HTTPS — the entire trust model of the modern internet. These certificates are issued by Certificate Authorities, or CAs, which are supposed to be neutral third parties. The whole system works because no single actor controls the issuance and verification process.
Russia just threw that model out the window.
By moving seven banks to a state-run CA, the Russian government has positioned itself as the ultimate guarantor of digital identity for financial communications. That means the same entity that issues the certificate can also perform a man-in-the-middle attack — intercepting, decrypting, and reading every single transaction between you and your bank. And you’d never know. Your browser would show the padlock. The connection would look “secure.” But the state would be reading everything.
One commenter on the original story put it bluntly: “Might as well merge them all and call it FSBank.”
They’re not wrong. The FSB — Russia’s successor to the KGB — doesn’t need to hack your bank. They don’t need zero-day exploits or sophisticated malware campaigns. They just became the certificate authority. The encryption still works perfectly. It just works for them, not for you.
The most effective surveillance state isn’t one that breaks encryption. It’s one that holds the keys and convinces you the lock still works.
Now, you might be thinking: “This is Russia. It doesn’t affect me.” Think again.
Another commenter made an observation that should keep every security engineer awake at night: “Who is better able to verify an identity than a state? State-run registrars regulate companies. States issue individuals ID documents. If you have trusted central parties issue encryption certificates, it will gravitate to fewer and more centralized issuers.”
This is the twist nobody wants to talk about. The logic is seductive. States DO issue passports. States DO register corporations. Why shouldn’t states issue the certificates that verify digital identity? It sounds reasonable — until you realize it’s the exact argument that dismantles the decentralized trust model the internet was built on.
The internet’s security architecture was designed around a radical idea: trust should be distributed, verifiable, and independent of any single authority. That’s what made it different from, say, a national ID system. You didn’t have to trust the government. You had to trust math.
Russia is betting that you’ll trade math for authority. And here’s the uncomfortable truth: they might be right.
China has already built its own parallel internet infrastructure. Iran has experimented with a national intranet. Now Russia is nationalizing the trust layer itself. This isn’t a trend — it’s a template. Every authoritarian government on earth is watching this experiment. If it works — if citizens accept the padlock without asking who’s holding the key — you’ll see this model exported to every country where the state wants total visibility into digital life.
The endgame isn’t an internet that’s broken. It’s an internet that works perfectly — for everyone except the user.
So what do we do? First, stop treating the padlock as proof of anything. The padlock means the connection is encrypted. It does NOT mean the entity on the other end is who they claim to be — not when the certificate authority is also the adversary. Second, if you do business with any Russian bank or any entity using these certificates, assume your communications are intercepted. Not might be. Are. Third, support decentralized identity and cryptographic verification systems that don’t rely on state-controlled authorities.
The internet was built on the assumption that trust could be decentralized. That assumption is being tested right now, in real time, with real money, by a state that has every incentive to prove it wrong.
The question isn’t whether Russia can pull this off. The question is whether the rest of us will even notice before the same playbook arrives in our own browsers.
Privacy wasn’t taken from you by a hack. It’s being dismantled by a certificate.
FAQ
Q: Doesn't HTTPS still encrypt the connection? What's the actual problem?
A: Yes, the connection is still encrypted. But when the state controls the certificate authority, it can issue its own certificates and perform man-in-the-middle attacks without your browser ever showing a warning. The encryption works — it just works for the interceptor, not for you.
Q: If I don't use Russian banks, why should I care?
A: Because this is a proof of concept. If the model succeeds in Russia, every authoritarian government has a ready-made template for nationalizing the trust layer of the internet. The threat is to the global end-to-end trust model, not just to Russian banking customers.
Q: Isn't it actually logical for states to issue certificates since they already issue passports and IDs?
A: It's the most dangerous reasonable-sounding argument in cybersecurity. States issue IDs within a legal framework with checks and balances. A certificate authority with MITM capability has no such constraint — it can silently intercept everything. The whole point of decentralized trust was to prevent exactly this concentration of power.