Not a lawyer but I suspect there's a viable tortious interference claim. Revocation is effectively telling your customers that your product is unsafe, if done without cause it could be actionable.
>Revocation is effectively telling your customers that your product is unsafe
> another explanation, i.e. that one reason for the revocation is some mysterious 570 MB executable file, which had been signed with our certificate but looked like a file used by hackers. Woah, talk about burying the lede? This sentence makes it sound like their private key was compromised, in which case it makes total sense to revoke the cert. Unless I'm misunderstanding what they're trying to say here.
You are misunderstanding. WinRAR's implication is that the CA is lying about the 570 MB file because they didn't mention it until WinRAR challenged them on the VirusTotal justification for revocation, and because they were unable to provide the file in question or any evidence that it exists.
> another explanation, i.e. that one reason for the revocation is some mysterious 570 MB executable file, which had been signed with our certificate but looked like a file used by hackers. Woah, talk about burying the lede? This sentence makes it sound like their private key was compromised, in which case it makes total sense to revoke the cert. Unless I'm misunderstanding what they're trying to say here.
You are misunderstanding. WinRAR's implication is that the CA is lying about the 570 MB file because they didn't mention it until WinRAR challenged them on the VirusTotal justification for revocation, and because they were unable to provide the file in question or any evidence that it exists.
You are misunderstanding. WinRAR's implication is that the CA is lying about the 570 MB file because they didn't mention it until WinRAR challenged them on the VirusTotal justification for revocation, and because they were unable to provide the file in question or any evidence that it exists.
[deleted]
The WinRAR post doesn't say that the file was submitted to VirusTotal, only that the CA said it "looked like a file used by hackers". Either there was no VirusTotal record for it or there was and WinRAR omitted that fact because it weakened their argument.
Yes. People who don't know any better alternatives continue to use it, and continue to recommend it to other people. So the cycle continues. Heck, WinZip still makes new releases so I'm sure people still use that too.
What is better alternative? 7-zip UI is not as good and missing some WinRAR features.
Not a lawyer but I suspect there's a viable tortious interference claim. Revocation is effectively telling your customers that your product is unsafe, if done without cause it could be actionable.
>Revocation is effectively telling your customers that your product is unsafe ...or that the certificate was no longer in compliance with their Certificate Practice Statement. It looks like their CPS gives them a great deal of leeway here. https://sectigo.com/uploads/files/Sectigo-CPS-v5.2.pdf#page=...
The main clauses either require a reasonable belief, which is a factual question that could easily go against the CA, or says they need to be "identified" as publishers of malicious software, without specifying how. An antivirus site that has many false positives likely wouldn't qualify.
It is particularly ironic that so many people in this thread are recommending 7-zip in response to a cert problem with WinRAR when 7-zip has no code signing at all and presents the scary yellow "unknown software" screen when you try to install it.
It's a bit like the way that plaintext HTTP is way easier to deal with than HTTPS, and the way browsers treat a self-signed cert as worse than no cert. Which... does lead to some odd outcomes, yes.
Yes. People who don't know any better alternatives continue to use it, and continue to recommend it to other people. So the cycle continues. Heck, WinZip still makes new releases so I'm sure people still use that too.
There are alternatives with built in recovery records? Which ones? I am being serious.
Yes. People who don't know any better alternatives continue to use it, and continue to recommend it to other people. So the cycle continues. Heck, WinZip still makes new releases so I'm sure people still use that too.
I have used both and prefer the WinRar GUI and the better multi part support.
Or maybe their customers just like the product, as in the GUI and feature and don’t care that another compression algorithm can shave off a few extra megabytes. If I recall correctly WinRAR can make self extracting archives pretty easily. If you use that feature it might be easier/better to just continue using WinRAR. I love the fact that small software companies like RARLAB can still exist.
It would be incredibly sad to see them go out of business, it's such an iconic piece of software.
> It would be incredibly sad to see them go out of business, it's such an iconic piece of software.
Granted, it's also famous for (supposedly) nobody ever paying for it, which doesn't exactly lend itself to staying in business.