Such data are cited in the results of a study of the websites of the highest authorities of 89 subjects of the Russian Federation, which is regularly conducted by the public movement "Information for All". As noted by the coordinator of the "Monitor of State Websites" project, Evgeny Altovsky, cyberattacks on Russian government websites have led to a noticeable improvement in the situation with their security at the federal level, and by 2023 the signal has reached the level of the subjects of the Federation: "We are seeing some improvement, but a fundamental change in the situation is still far away and there are no prerequisites for it."
In 2023, according to the belize whatsapp resource study, two websites of state bodies of the constituent entities of the Russian Federation scored 80 points in the rating of security of connection with visitors. Last year's record holder - the website of the Legislative Assembly of the Chelyabinsk Region - was joined by the website of the government of the Astrakhan Region. The average result of regional government websites is still lower - 26 against 27 points for federal government websites (the minimum acceptable result is 29 points).
of Government Agencies of the Russian Federation: the Culture of Cancelling Information Security of Federal Government Websites", which was conducted in July 2023, resources from 44 third-party hosts were also uncontrolledly loaded onto the websites of federal government agencies, only five of which were controlled by the state. Only 15% of government websites did not load code from third-party resources, while 26% of them were located in "unfriendly" countries. The authors of the study also found that even website administrators were not always aware of what third-party code the resources entrusted to them were loading.
To date, three government agencies of the subjects do not have official websites (according to the results of a similar study in 2022, there were five such), two do not have websites at all (their number has not changed). The authors of the study also found that 10% of the government websites studied do not support a secure connection, and more than 70% support it only formally, without providing reliable protection. However, in 2022, 15% of regional government websites did not support the HTTPS protocol.
According to the authors of the study, the situation with regional government websites getting rid of code loaded onto them from abroad is not the best. If federal websites completely got rid of loading Google Analytics in 2023, regional ones began to use it 40% more often, and the website of the Karelian parliament continues to load the code of the social network Facebook, declared extremist in Russia. 97% of the studied websites still load foreign code, thereby allowing third parties to control content and collect information about visitors. The authors of the study especially note that 53% of government websites load resources controlled by residents of unfriendly countries.
Deputy Chairman of the Government of the Tula Region - Minister for Informatization, Communications and Open Governance of the Tula Region Yaroslav Rakov, during his speech at the Infoforum Center conference, named one of the main reasons for the success of attacks, including on websites, the exploitation of vulnerabilities, primarily in the popular content management system 1C-Bitrix: Site Management. It was their exploitation, according to him, that led to the defacement of the websites of two municipal institutions of the Tula Region during a massive wave of similar incidents across the country on May 26, 2023.
As shown by the study "Information Security of Websites
-
- Posts: 581
- Joined: Thu Jan 02, 2025 7:16 am