With both Windows and MacOS both putting scary warnings and hard to bypass blocking methods on improperly signed software this could eventually lead to developers being ransomed, “pay us big money or we will revoke your certificate”. This is not the only incident like this.
A non-problem. Linux will run on x86 hardware till the end of time.
Information on the revocation of WinRAR 5.91 digital certificate
91–100 of 156 posts
Re: Information on the revocation of WinRAR 5.91 digital certificate
#92> We think that revoking certificates based on questionable data discredits the certification system. It's hard to dispute this imo. There are many good reasons certificates should be revoked, but the reasoning should be 100% public information, for both the vendor and users who may have trusted the original certificate. I'm building a desktop app, and the process to even get a certificate is absurd. Each CA has thei…
Looking at application development I think a similar thing could be done, but what would we pin identity to? I don't know if there is one thing that every app has like a website.
Re: Information on the revocation of WinRAR 5.91 digital certificate
#93The CA in question is CN = Sectigo RSA Code Signing CA
...previously known as Comodo. Did their reputation was so bad that they had to rebrand? https://sectigo.com/resource-library/comodo-ca-is-now-sectig...
Re: Information on the revocation of WinRAR 5.91 digital certificate
#94They should really name the CA. It's quite common for 1 of the 60 tests on virustotal.com to turn up a false positive.
Re: Information on the revocation of WinRAR 5.91 digital certificate
#95Who was the CA with whom they had this difference of opinion?
Re: Information on the revocation of WinRAR 5.91 digital certificate
#96> We think that revoking certificates based on questionable data discredits the certification system. It's hard to dispute this imo. There are many good reasons certificates should be revoked, but the reasoning should be 100% public information, for both the vendor and users who may have trusted the original certificate. I'm building a desktop app, and the process to even get a certificate is absurd. Each CA has thei…
The other consideration is that verifying identity is pointless , because malware authors don't actually use their own identities, they just pull a code signing certificate from the 1% of their already-infected users who have one. Then they go out and infect a million more users with it and get 10,000 more code signing certificates. If all you're after is some kind of rate limiting then forget about identity verifica…
My Tucows certificate is still a single *.pfx file - whereas my arguably less-consequential AATL (Adobe PDF signing) certificate is stuck on a crappy USB device that requires me to install marketing-laden software for. I miss my old commodity smartcard-based certificates.
Re: Information on the revocation of WinRAR 5.91 digital certificate
#97> We think that revoking certificates based on questionable data discredits the certification system. It's hard to dispute this imo. There are many good reasons certificates should be revoked, but the reasoning should be 100% public information, for both the vendor and users who may have trusted the original certificate. I'm building a desktop app, and the process to even get a certificate is absurd. Each CA has thei…
Let's Encrypt's argument for why all the fancy features that CA's offered boiled down to "These are more complicated ways of proving that you own a domain". So by automating the verification of ownership of a domain you could essentially run a CA for pennies per certificate, and give them out for free. Looking at application development I think a similar thing could be done, but what would we pin identity to? I don't…
Re: Information on the revocation of WinRAR 5.91 digital certificate
#98Earlier quoted context omitted.
I haven’t used WinRAR in ages, but what makes 7zip (which I use as well) better?
It can extract files to paths of more than 260 characters, without any extra tools or registry hacks, on any version of windows (even xp). Winrar cannot. As a bonus, 7zip can also delete folders with file paths that are over 260 characters from its file manager ui. It has been one of the only programs to be able to do so for many years.
I'm amazed at all the comments calling for 7zip as the one and only. winrar works just fine so does windows zip function. If you have an edge case, yeah then you need something that can handle it.
Re: Information on the revocation of WinRAR 5.91 digital certificate
#99Do people still use WinRar? :O
Re: Information on the revocation of WinRAR 5.91 digital certificate
#100Earlier quoted context omitted.
Yes. People who don't know any better alternatives continue to use it, and continue to recommend it to other people. So the cycle continues. Heck, WinZip still makes new releases so I'm sure people still use that too.
Or maybe their customers just like the product, as in the GUI and feature and don’t care that another compression algorithm can shave off a few extra megabytes. If I recall correctly WinRAR can make self extracting archives pretty easily. If you use that feature it might be easier/better to just continue using WinRAR. I love the fact that small software companies like RARLAB can still exist.