Live data from Hacker News

Information on the revocation of WinRAR 5.91 digital certificate

rarlab.com

21–30 of 156 posts

Re: Information on the revocation of WinRAR 5.91 digital certificate

#21
post #4

Earlier quoted context omitted.

Yes. People who don't know any better alternatives continue to use it, and continue to recommend it to other people. So the cycle continues. Heck, WinZip still makes new releases so I'm sure people still use that too.

> People who don't know any better alternatives continue to use it Genuine question: what are the better alternatives?

Peazip: https://peazip.github.io/

I used to use 7zip, but switched when I discovered that Peazip doesn't extract to a temporary directory when extracting (thus, saving extra I/O work). It directly extracts into the target directory.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#22

Earlier quoted context omitted.

> People who don't know any better alternatives continue to use it Genuine question: what are the better alternatives?

Peazip: https://peazip.github.io/ I used to use 7zip, but switched when I discovered that Peazip doesn't extract to a temporary directory when extracting (thus, saving extra I/O work). It directly extracts into the target directory.

Is a file move that big of an IO operation?

Re: Information on the revocation of WinRAR 5.91 digital certificate

#23
post #4
post #3

Do people still use WinRar? :O

Yes. People who don't know any better alternatives continue to use it, and continue to recommend it to other people. So the cycle continues. Heck, WinZip still makes new releases so I'm sure people still use that too.

Hang on, should I be moving off of pkzip?

Re: Information on the revocation of WinRAR 5.91 digital certificate

#24
> We think that revoking certificates based on questionable data discredits the certification system.

It's hard to dispute this imo. There are many good reasons certificates should be revoked, but the reasoning should be 100% public information, for both the vendor and users who may have trusted the original certificate.

I'm building a desktop app, and the process to even get a certificate is absurd. Each CA has their own wildly different processes, and seemingly answers to nobody. I changed cert providers recently after Digicert suddenly raised their prices 400% on a whim, and it took a huge number of changing requirements, phone calls, 3rd parties, and over a month to receive the new one, despite already having an existing verified & still-valid signing certificate with all those details from an equally legitimate provider.

I'd kill to see a modern service a la Let's Encrypt but for code signing. Something transparent, reliable, fast & trusted cross-platform (I can dream). Verifying identity is a hard problem, but it's really not _that_ hard a problem - there's plenty of fintech services that can reliably do sufficient KYC for banking in 5 minutes with a few id details and video call.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#25
post #4

Earlier quoted context omitted.

Yes. People who don't know any better alternatives continue to use it, and continue to recommend it to other people. So the cycle continues. Heck, WinZip still makes new releases so I'm sure people still use that too.

Or maybe their customers just like the product, as in the GUI and feature and don’t care that another compression algorithm can shave off a few extra megabytes. If I recall correctly WinRAR can make self extracting archives pretty easily. If you use that feature it might be easier/better to just continue using WinRAR. I love the fact that small software companies like RARLAB can still exist.

WinRAR seems to have added additional compression formats and algorithms, like 7zip and XZ: https://www.rarlab.com/otherfmt.htm

WinZIP, too: https://www.winzip.com/win/en/lanall.html

Re: Information on the revocation of WinRAR 5.91 digital certificate

#26
post #4
post #3

Do people still use WinRar? :O

Yes. People who don't know any better alternatives continue to use it, and continue to recommend it to other people. So the cycle continues. Heck, WinZip still makes new releases so I'm sure people still use that too.

Somehow archival tools have become political. 7zip seems to be the new one people use even though that means their users now have to download and understand two packages instead of one. It’s off-putting, especially when downloading your tool was already an act of yak shaving. As awesome as we want to think our tools are, the people who use them may be preoccupied with other problems instead. Friction will not convert them.

I think I shamed someone out of using 7z recently by pointing out that if they claim to be trying to attract a broad audience of hobbyist developers, using a compression library that doesn’t exist on OS X (with out without Xcode) is not a smart plan. In this particular case you had to download two tools to use their code, and that just tore it for me.

When I went back recently they had switched to .xz, which does exist.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#27
> another explanation, i.e. that one reason for the revocation is some mysterious 570 MB executable file, which had been signed with our certificate but looked like a file used by hackers.

Woah, talk about burying the lede? This sentence makes it sound like their private key was compromised, in which case it makes total sense to revoke the cert. Unless I'm misunderstanding what they're trying to say here.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#30
post #18
post #11

With both Windows and MacOS both putting scary warnings and hard to bypass blocking methods on improperly signed software this could eventually lead to developers being ransomed, “pay us big money or we will revoke your certificate”. This is not the only incident like this.

>this could eventually lead to developers being ransomed, “pay us big money or we will revoke your certificate” by whom? the platform makers (apple/microsoft) or malicious third parties?

Apple is effectively doing this to Epic and others, but it could be done by any agreement of enough CA's as well.
Post reply on HN