Live data from Hacker News

Information on the revocation of WinRAR 5.91 digital certificate

rarlab.com

61–70 of 156 posts

Re: Information on the revocation of WinRAR 5.91 digital certificate

#61
post #30
post #18

Earlier quoted context omitted.

>this could eventually lead to developers being ransomed, “pay us big money or we will revoke your certificate” by whom? the platform makers (apple/microsoft) or malicious third parties?

Apple is effectively doing this to Epic and others, but it could be done by any agreement of enough CA's as well.

Epic violated the agreements they signed with Apple.

Whether or not we care for the contents of the agreements is a separate issue. Apple did not capriciously act against Epic - if they had then Epic wouldn’t have had an advertising campaign and lawsuit ready to go within hours.

The situation with WinRAR is completely different and it doesn’t help anything in trying to conflate the two; indeed it just muddies the waters :(

Re: Information on the revocation of WinRAR 5.91 digital certificate

#62
post #9

Earlier quoted context omitted.

7zip

I haven’t used WinRAR in ages, but what makes 7zip (which I use as well) better?

It can extract files to paths of more than 260 characters, without any extra tools or registry hacks, on any version of windows (even xp). Winrar cannot. As a bonus, 7zip can also delete folders with file paths that are over 260 characters from its file manager ui. It has been one of the only programs to be able to do so for many years.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#63
post #31
post #18

Earlier quoted context omitted.

>this could eventually lead to developers being ransomed, “pay us big money or we will revoke your certificate” by whom? the platform makers (apple/microsoft) or malicious third parties?

Both. We've seen third parties do this on Windows and Apple themselves use this to punish developers who dared criticize them.

Where and when did Microsoft or Apple yank someone's developer cert for the sole reason of criticism? An accusation that serious needs to be substantiated.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#64
post #14

Earlier quoted context omitted.

WinRAR does everything you ask of it; compress or decompress archives in one click. Why wouldn't people still use it?

Because every operating system has built in zip compression support.

zip is hardly the only compression algorithm, or the best one for all conceivable use cases, and tools like Winrar (and 7zip, for that matter) offer additional features that the OS tools do not.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#65
post #14

Earlier quoted context omitted.

WinRAR does everything you ask of it; compress or decompress archives in one click. Why wouldn't people still use it?

Because every operating system has built in zip compression support.

WinRAR is for RAR files, as the name suggests.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#66
Weird. Though there would be value in working with the vendors backing VT to get this fixed as this is just one of the issues with a false positive. Another is that users who use these products are probably alerted or otherwise prevented from using WinRAR too.

VT has it as malicious with the new hash too [1] .

Antiy-AVL calls it Win32.Shelma. Only good definition that seems to match that detection is from Kaspersky [2] stating that the 64 bit version is detected as using metasploit [3] components.

[1] https://www.virustotal.com/gui/file/21dd688a5371f5b0d297a307...

[2] https://threats.kaspersky.com/en/threat/Trojan.Win64.Shelma/

[3] https://www.metasploit.com/

edited: formatting

Re: Information on the revocation of WinRAR 5.91 digital certificate

#67

It is particularly ironic that so many people in this thread are recommending 7-zip in response to a cert problem with WinRAR when 7-zip has no code signing at all and presents the scary yellow "unknown software" screen when you try to install it.

People are not recommending 7-zip in response to the cert problem but rather to someone directly asking for a superior alternative in https://news.ycombinator.com/item?id=24284253

Regardless, 7zip does not have as much of a need for a certificate because it is foss so you do not need to trust the creators, in comparison to winrar which isn't and you need to trust them.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#68
post #4

Earlier quoted context omitted.

Yes. People who don't know any better alternatives continue to use it, and continue to recommend it to other people. So the cycle continues. Heck, WinZip still makes new releases so I'm sure people still use that too.

Or maybe their customers just like the product, as in the GUI and feature and don’t care that another compression algorithm can shave off a few extra megabytes. If I recall correctly WinRAR can make self extracting archives pretty easily. If you use that feature it might be easier/better to just continue using WinRAR. I love the fact that small software companies like RARLAB can still exist.

> Or maybe their customers just like the product, as in the GUI and feature and don’t care that another compression algorithm can shave off a few extra megabytes.

First of all, I very much doubt that the people who use winrar even notice the UI. They could switch to 7zip and feel right at home. People are used to UI changing drastically all the time, both from Windows itself, and from websites. Some of them complain about it, but even they adjust.

Second, I said nothing about "another compression algorithm". All the big compression software on Windows support each other's algorithms, but 7zip is free and winrar makes you pay for it. Also the people who use winrar don't care about compression algorithms in the first place, only that they get a file they can email and the other people can double-click to extract.

Third, the reality of the situation is that most people who use winrar are also the kind that use the trial version indefinitely. The more clued ones switch to pirated copies from piratebay et al. I'd rather people use 7zip than pirated copies, both for their safety and for RARLAB's benefit.

The reason these companies charge for things that are free is because they rely on users not knowing better, and the small fraction of users who do pay for it is sufficient to bankroll them. A 7zip user and a winrar user could be friends for life and the topic of "So what compression software do you use?" might never come up.

>If I recall correctly WinRAR can make self extracting archives pretty easily.

So can 7zip.

>I love the fact that small software companies like RARLAB can still exist.

You say this as if the alternatives are all big software companies. Last I checked, 7zip is still a one-person software.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#69

It is particularly ironic that so many people in this thread are recommending 7-zip in response to a cert problem with WinRAR when 7-zip has no code signing at all and presents the scary yellow "unknown software" screen when you try to install it.

People are not recommending 7-zip in response to the cert problem but rather to someone directly asking for a superior alternative in https://news.ycombinator.com/item?id=24284253 Regardless, 7zip does not have as much of a need for a certificate because it is foss so you do not need to trust the creators, in comparison to winrar which isn't and you need to trust them.

The fact that it is FOSS makes it _easier_ for someone to compile it with a backdoor or trojan. I would say the need for a certificate is _higher_ there. You don’t need to trust the developers, you need to be able to trust the people who have built the executable.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#70

> We think that revoking certificates based on questionable data discredits the certification system. It's hard to dispute this imo. There are many good reasons certificates should be revoked, but the reasoning should be 100% public information, for both the vendor and users who may have trusted the original certificate. I'm building a desktop app, and the process to even get a certificate is absurd. Each CA has thei…

The other consideration is that verifying identity is pointless, because malware authors don't actually use their own identities, they just pull a code signing certificate from the 1% of their already-infected users who have one. Then they go out and infect a million more users with it and get 10,000 more code signing certificates.

If all you're after is some kind of rate limiting then forget about identity verification and just require proof of a unique $500 donation to a 501(c)(3). Not only would it be easier to automate, it would do some good in the world, and people would be a lot happier to see their resources go there than to some box checking bureaucrats.

Post reply on HN