Information on the revocation of WinRAR 5.91 digital certificate
121–130 of 156 posts
Re: Information on the revocation of WinRAR 5.91 digital certificate
#122Earlier quoted context omitted.
The customers have a VM for this that will be likely delivered indefinitely for this purpose: Webkit + friends.
There’s a lot of parts and peripherals of a computer you can’t touch from inside of that VM. The vast majority, really.
Re: Information on the revocation of WinRAR 5.91 digital certificate
#123Earlier quoted context omitted.
That doesn't rate limit wealthy attackers, it just locks regular individuals out of the system. Peter Thiel could still buy 10,000 malicious certificates at $500/ea, while I wouldn't even be able to buy one for a simple project.
To be fair, the former isn't really a problem; most malware authors are profit-motivated; they're trying to scam/phish/ransomware/etc people. If you increase their operating costs sufficiently, they'll go away. The ones who can afford to eat certificate costs mostly have nation-state connections they can use to get around identity verification anyway. That said, the latter part does make this a non-starter, although…
I get the reasoning of "voter id laws are bad because they disproportionately disenfranchise poor people", but "code signing certificates are bad because they disproportionately disenfranchise poor programmers" doesn't really make any sense. If you know how to program, and you can pony up $300 for the code signing certificate, chances are you probably already have the requisite identity paperwork. On the off chance that you don't, it's no big deal because lots of prominent software aren't signed (eg. 7zip, notepad++), so it's not like you're sticking out by not doing so.
Re: Information on the revocation of WinRAR 5.91 digital certificate
#124Earlier quoted context omitted.
Let's Encrypt's argument for why all the fancy features that CA's offered boiled down to "These are more complicated ways of proving that you own a domain". So by automating the verification of ownership of a domain you could essentially run a CA for pennies per certificate, and give them out for free. Looking at application development I think a similar thing could be done, but what would we pin identity to? I don't…
> Looking at application development I think a similar thing could be done, but what would we pin identity to? How about domain name? Whenever I install (Windows) software I rarely care about the mailing address or D.B.A. name; I look at the website address listed.
Re: Information on the revocation of WinRAR 5.91 digital certificate
#125Earlier quoted context omitted.
Epic violated the agreements they signed with Apple. Whether or not we care for the contents of the agreements is a separate issue. Apple did not capriciously act against Epic - if they had then Epic wouldn’t have had an advertising campaign and lawsuit ready to go within hours. The situation with WinRAR is completely different and it doesn’t help anything in trying to conflate the two; indeed it just muddies the wat…
I’d argue that it’s more similar than it seems, but with one caveat: Apple (rightfully) became the market leader, but is essentially running what should be a public market. If one company took over all the physical land on the planet, and had everyone sign agreements to essentially pay taxes to them with every transaction, would we still argue that that’s not only legal, but morally justified?
Re: Information on the revocation of WinRAR 5.91 digital certificate
#126Earlier quoted context omitted.
>this could eventually lead to developers being ransomed, “pay us big money or we will revoke your certificate” by whom? the platform makers (apple/microsoft) or malicious third parties?
Both. We've seen third parties do this on Windows and Apple themselves use this to punish developers who dared criticize them.
Re: Information on the revocation of WinRAR 5.91 digital certificate
#127Anyone know which CA did this? I'd like to add it to my list of 'entities to avoid doing business with'.
Re: Information on the revocation of WinRAR 5.91 digital certificate
#128Earlier quoted context omitted.
To be fair, the former isn't really a problem; most malware authors are profit-motivated; they're trying to scam/phish/ransomware/etc people. If you increase their operating costs sufficiently, they'll go away. The ones who can afford to eat certificate costs mostly have nation-state connections they can use to get around identity verification anyway. That said, the latter part does make this a non-starter, although…
>That said, the latter part does make this a non-starter, although the same is true of most means of identity verification, which lock out anyone with inadequate identity paperwork. I get the reasoning of "voter id laws are bad because they disproportionately disenfranchise poor people", but "code signing certificates are bad because they disproportionately disenfranchise poor programmers" doesn't really make any sen…
At a sample size of one (me), this is false in 100% of cases. (To be fair, you did say "chances are" rather than "it is certainly the case that".)
> it's no big deal because lots of prominent software aren't signed (eg. 7zip, notepad++)
Sure, but that's a argument against code signing in general, not fees versus paperwork.
Re: Information on the revocation of WinRAR 5.91 digital certificate
#129Earlier quoted context omitted.
Epic violated the agreements they signed with Apple. Whether or not we care for the contents of the agreements is a separate issue. Apple did not capriciously act against Epic - if they had then Epic wouldn’t have had an advertising campaign and lawsuit ready to go within hours. The situation with WinRAR is completely different and it doesn’t help anything in trying to conflate the two; indeed it just muddies the wat…
I’d argue that it’s more similar than it seems, but with one caveat: Apple (rightfully) became the market leader, but is essentially running what should be a public market. If one company took over all the physical land on the planet, and had everyone sign agreements to essentially pay taxes to them with every transaction, would we still argue that that’s not only legal, but morally justified?
They became the market leader (and I say this as an Android person who dislikes Apple and would never own one) because it's not a public market - they offer a "premium" experience, and part of that is the heavily curated app store. Opening up the platform would undermine the whole reason why it's popular to begin with. As long as you aren't using a jailbroken device (and there aren't any current 0-day attacks, which are rare) you don't have to worry about downloading random malware or side-loading something nasty.
Not to mention that it would prevent Apple from enforcing things like sign-in with apple ID, which again reduces user convenience and undermines the reason apple products are popular in the first place. People buy Apple devices because they "Just Work" and are willing to trade away control of the device to get that convenience - there's no real difference between an iPhone and a flagship Samsung phone (for example) in terms of hardware quality, it's all about slickness and ease of use.
>If one company took over all the physical land on the planet, and had everyone sign agreements to essentially pay taxes to them with every transaction, would we still argue that that’s not only legal, but morally justified?
Do you not believe there is a significant ongoing cost relating to the Apple store? Bandwidth, storage, CDN, power and HVAC for equipment, other building / data centre costs, IT staff for maintaining the servers and services, developers to develop the store and maintain Apple's side of the arms race between malicious devs trying to fool Apple's automated checking and Apple trying to detect and prevent malicious apps being uploaded, other miscellaneous overheads (accounting, auditors, etc.)... why should they be prevented from collecting taxes to cover the costs?
I'm sure it would be profitable for Apple to some degree, but not nearly as much as people seem to believe - IIRC something like two billion iPhones (not sure if that includes other iOS devices or just the phones) of various makes have been produced, and almost all of those will have checked in regularly to the store for updates and installing new stuff over the course of the devices lifetime - how much bandwidth do you think that would use? Apparently the (ballpark) storage on a device consumed by an install of fortnite on iOS is around 8GB, multiplied by 100 million downloads... That would not all be concurrent and earlier install would have been lighter, and how much of that comes through Apple vs. Epic's own CDN I do not know (e.g. if they can distribute game content themselves), but in any case I'm sure it is still a massive load on the store IX.
I hate to rant like this but the whole "ApPlE gReEdY" argument with no consideration of the costs involved is really irritating, and I've been seeing it everywhere since the dispute over Fortnite kicked off - I don't know the actual figures but I'm sure there are massive ongoing costs involved in running the Apple store. Putting a significant burden on that infrastructure and then complaining when you get kicked off for not contributing to it is an incredible display of gall on Epic's part.