Live data from Hacker News

Information on the revocation of WinRAR 5.91 digital certificate

rarlab.com

91–100 of 156 posts

Re: Information on the revocation of WinRAR 5.91 digital certificate

#91
post #11

With both Windows and MacOS both putting scary warnings and hard to bypass blocking methods on improperly signed software this could eventually lead to developers being ransomed, “pay us big money or we will revoke your certificate”. This is not the only incident like this.

A non-problem. Linux will run on x86 hardware till the end of time.

Professional developers have to write code that runs on their customers' systems.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#92

> We think that revoking certificates based on questionable data discredits the certification system. It's hard to dispute this imo. There are many good reasons certificates should be revoked, but the reasoning should be 100% public information, for both the vendor and users who may have trusted the original certificate. I'm building a desktop app, and the process to even get a certificate is absurd. Each CA has thei…

Let's Encrypt's argument for why all the fancy features that CA's offered boiled down to "These are more complicated ways of proving that you own a domain". So by automating the verification of ownership of a domain you could essentially run a CA for pennies per certificate, and give them out for free.

Looking at application development I think a similar thing could be done, but what would we pin identity to? I don't know if there is one thing that every app has like a website.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#93
post #29

The CA in question is CN = Sectigo RSA Code Signing CA

...previously known as Comodo. Did their reputation was so bad that they had to rebrand? https://sectigo.com/resource-library/comodo-ca-is-now-sectig...

Yes they've been pretty much terrible. https://www.techdirt.com/articles/20160623/17483934805/super...

Re: Information on the revocation of WinRAR 5.91 digital certificate

#96

> We think that revoking certificates based on questionable data discredits the certification system. It's hard to dispute this imo. There are many good reasons certificates should be revoked, but the reasoning should be 100% public information, for both the vendor and users who may have trusted the original certificate. I'm building a desktop app, and the process to even get a certificate is absurd. Each CA has thei…

The other consideration is that verifying identity is pointless , because malware authors don't actually use their own identities, they just pull a code signing certificate from the 1% of their already-infected users who have one. Then they go out and infect a million more users with it and get 10,000 more code signing certificates. If all you're after is some kind of rate limiting then forget about identity verifica…

This is why code-signing certificates must be two-factor (e.g. embedded on a PIN secured smartcard where the private-key is protected from extraction by anybody).

My Tucows certificate is still a single *.pfx file - whereas my arguably less-consequential AATL (Adobe PDF signing) certificate is stuck on a crappy USB device that requires me to install marketing-laden software for. I miss my old commodity smartcard-based certificates.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#97

> We think that revoking certificates based on questionable data discredits the certification system. It's hard to dispute this imo. There are many good reasons certificates should be revoked, but the reasoning should be 100% public information, for both the vendor and users who may have trusted the original certificate. I'm building a desktop app, and the process to even get a certificate is absurd. Each CA has thei…

Let's Encrypt's argument for why all the fancy features that CA's offered boiled down to "These are more complicated ways of proving that you own a domain". So by automating the verification of ownership of a domain you could essentially run a CA for pennies per certificate, and give them out for free. Looking at application development I think a similar thing could be done, but what would we pin identity to? I don't…

Registered company information and/or notarised identity cards.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#98
post #62

Earlier quoted context omitted.

I haven’t used WinRAR in ages, but what makes 7zip (which I use as well) better?

It can extract files to paths of more than 260 characters, without any extra tools or registry hacks, on any version of windows (even xp). Winrar cannot. As a bonus, 7zip can also delete folders with file paths that are over 260 characters from its file manager ui. It has been one of the only programs to be able to do so for many years.

Amount of times this has been an issue with using Winrar for 15+ years : zero.

I'm amazed at all the comments calling for 7zip as the one and only. winrar works just fine so does windows zip function. If you have an edge case, yeah then you need something that can handle it.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#99
post #3

Do people still use WinRar? :O

Ebooks available on IRC are often compressed as RAR files. More often lately Epub books are not being compressed since Epub files are already compressed, and compressing them again as RAR files doesn't really gain you anything.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#100
post #4

Earlier quoted context omitted.

Yes. People who don't know any better alternatives continue to use it, and continue to recommend it to other people. So the cycle continues. Heck, WinZip still makes new releases so I'm sure people still use that too.

Or maybe their customers just like the product, as in the GUI and feature and don’t care that another compression algorithm can shave off a few extra megabytes. If I recall correctly WinRAR can make self extracting archives pretty easily. If you use that feature it might be easier/better to just continue using WinRAR. I love the fact that small software companies like RARLAB can still exist.

We paid for an enterprise license for like 5000 computers. Why the fuck we did that, nobody seems to know.
Post reply on HN