WARNING ⚠️
The Central Bank has presented installing an “internal root certificate” on customers’ devices as one way to continue banking services.
The Central Bank has presented installing an “internal root certificate” on customers’ devices as one way to continue banking services.
But the issue is not merely eliminating warnings in internet banking. If this trust is established at the level of the entire device, it could affect more than just the bank’s website and, under specific circumstances, create the conditions for monitoring encrypted communications.
A browser considers a website’s certificate valid when its chain of trust leads back to a trusted root authority. If a user adds an internal root certificate to the operating system, the device may also recognize certificates issued by that same authority for other websites as valid.
The danger arises when that authority issues a fake certificate for a website and an attacker is able to position themselves in the traffic path. In such circumstances, the browser may trust the intermediary without displaying the usual warning, while a man-in-the-middle attack could enable the communication to be decrypted.
Installing a root certificate by itself does not mean that eavesdropping will occur; the main issue is the broad discretion granted to that authority.
There is, of course, a lower-risk approach: the banking app could trust an internal authority only for its own services and domains, without changing the trust store for the entire device.
That raises the central question about the Central Bank’s proposal: to resolve disruptions to banking services, why should trust in a new authority potentially be extended to communications outside the banking system as well?
❤1
moreweb.
WARNING ⚠️ The Central Bank has presented installing an “internal root certificate” on customers’ devices as one way to continue banking services. But the issue is not merely eliminating warnings in internet banking. If this trust is established at the level…
We have been saying this at moreweb for months now
This is an immediate security risk for the end-user with surveillance as the real result
I repeat, This is Mitm
THIS IS MITM
THIS IS MITM
DO NOT INSTALL THE ROOT CERTIFICATE
This is an immediate security risk for the end-user with surveillance as the real result
I repeat, This is Mitm
THIS IS MITM
THIS IS MITM
DO NOT INSTALL THE ROOT CERTIFICATE
❤2
نصب گواهی ریشه بانک مرکزی در دستگاه شما این امکان را فراهم میکند تا تمام ترافیک شبکه شما بدون استثنا توسط سیستم فیلترینگ بررسی شود
این به این معناست که آیکون قفل سبز در مرورگر به یک دروغ به تمام معنا تبدیل شده و تمام ترافیک قابل مشاهده خواهد بود ⚠️
این به این معناست که آیکون قفل سبز در مرورگر به یک دروغ به تمام معنا تبدیل شده و تمام ترافیک قابل مشاهده خواهد بود ⚠️
👍5
moreweb.
نصب گواهی ریشه بانک مرکزی در دستگاه شما این امکان را فراهم میکند تا تمام ترافیک شبکه شما بدون استثنا توسط سیستم فیلترینگ بررسی شود این به این معناست که آیکون قفل سبز در مرورگر به یک دروغ به تمام معنا تبدیل شده و تمام ترافیک قابل مشاهده خواهد بود ⚠️
بانک مرکزی نصب «گواهی ریشه داخلی» روی دستگاه مشتریان را یکی از راههای ادامه خدمات بانکی مطرح کرده است!
اما مسئله فقط رفع هشدار اینترنتبانک نیست؛ اگر این اعتماد در سطح کل دستگاه ایجاد شود، میتواند فراتر از سایت بانک اثر بگذارد و در شرایط مشخص، زمینه رهگیری ارتباطات رمزگذاریشده را فراهم کند.
© raaznet
اما مسئله فقط رفع هشدار اینترنتبانک نیست؛ اگر این اعتماد در سطح کل دستگاه ایجاد شود، میتواند فراتر از سایت بانک اثر بگذارد و در شرایط مشخص، زمینه رهگیری ارتباطات رمزگذاریشده را فراهم کند.
مرورگر زمانی گواهی یک سایت را معتبر میداند که زنجیره آن به یک مرجع ریشه مورد اعتماد برسد. اگر کاربر یک ریشه داخلی را به سیستمعامل اضافه کند، دستگاه ممکن است گواهیهای دیگری را هم که همان مرجع صادر کرده معتبر بشناسد.
خطر زمانی ایجاد میشود که آن مرجع برای یک سایت گواهی جعلی صادر کند و مهاجم نیز بتواند در مسیر ترافیک قرار بگیرد. در چنین شرایطی، مرورگر میتواند بدون هشدار معمول به واسطه اعتماد کند و حمله «مرد میانی» امکان رمزگشایی ارتباط را فراهم کند.
نصب گواهی ریشه بهتنهایی به معنای شنود نیست؛ مسئله اصلی دامنه اختیاری است که به آن مرجع داده میشود.
البته راه کمخطرتر وجود دارد؛ اپ بانک میتواند فقط برای سرویسها و دامنههای خودش به یک مرجع داخلی اعتماد کند، بدون تغییر فهرست اعتماد کل دستگاه.
پرسش اصلی طرح بانک مرکزی همین است: برای حل اختلال خدمات بانکی، چرا باید اعتماد یک مرجع تازه احتمالا به ارتباطات خارج از بانک هم گسترش پیدا کند؟
© raaznet
❤1
Free access to Anthropic’s medical AI for doctors in around 100 countries
In partnership with the medical platform OpenEvidence, Anthropic is making a specialized, free version of the service available to doctors and healthcare providers in around 100 countries, primarily low- and middle-income countries.
OpenEvidence has already been free for doctors in the United States and Europe, answering their medical questions based on peer-reviewed research and clinical guidelines. The new development is the expansion of this free version to countries that previously did not have access to the technology. Anthropic is providing the underlying back-end technology.
The initiative also includes countries such as Uganda, Angola, Sudan, Haiti, and Mongolia.
According to OpenEvidence founder Daniel Nadler, access to medical knowledge should not depend on geography. The financial details of the partnership have not been disclosed.
The service is designed for doctors and healthcare professionals. It does not mean that Claude is becoming free or that a general medical chatbot is being offered to all users.
Reuters
In partnership with the medical platform OpenEvidence, Anthropic is making a specialized, free version of the service available to doctors and healthcare providers in around 100 countries, primarily low- and middle-income countries.
OpenEvidence has already been free for doctors in the United States and Europe, answering their medical questions based on peer-reviewed research and clinical guidelines. The new development is the expansion of this free version to countries that previously did not have access to the technology. Anthropic is providing the underlying back-end technology.
The initiative also includes countries such as Uganda, Angola, Sudan, Haiti, and Mongolia.
According to OpenEvidence founder Daniel Nadler, access to medical knowledge should not depend on geography. The financial details of the partnership have not been disclosed.
The service is designed for doctors and healthcare professionals. It does not mean that Claude is becoming free or that a general medical chatbot is being offered to all users.
Reuters
Telegram Update Concept
Many users have asked Telegram to add a feature showing how long each person usually takes to reply to private messages.
For example, when you open a contact’s profile, it might display something like:
“Usually replies within 2 minutes and 30 seconds”
“Usually replies after 3 days!”
It could even rank users by response time, showing what percentage of users they respond faster than.
Many users have asked Telegram to add a feature showing how long each person usually takes to reply to private messages.
For example, when you open a contact’s profile, it might display something like:
“Usually replies within 2 minutes and 30 seconds”
“Usually replies after 3 days!”
It could even rank users by response time, showing what percentage of users they respond faster than.