Live data from Hacker News

Information on the revocation of WinRAR 5.91 digital certificate

rarlab.com

131–140 of 156 posts

Re: Information on the revocation of WinRAR 5.91 digital certificate

#131

At my previous job we released updates to our Windows desktop application about 3-4 times per year. We had about 20'000 customers (but many of them not installing updates). We checked final build of our product on Virus Total before release and e-mail the various anti virus companies about the false positives. Thankfully, I wasn't the guy doing this work.

Unfortunately that doesn’t really help. We update an application about once a year but we get false positive alerts even months after AV programs have previously not complained about a binary.

What’s worse is that not all AV vendors on Virus Total have an easy way to submit a false positive report and of those that do, the majority believes getting a false positive report to be an opt-in into their marketing mailing lists.

I absolutely hate my about quarterly task of going from a name of an AV engine on Virus Total who suddenly decided that our binary which hasn’t changed on months must be infected to finding the actual submit-a-false-positive page to then writing the report and then unsubscribing from their mailing list I inevitably end up on

Re: Information on the revocation of WinRAR 5.91 digital certificate

#132
post #61

Earlier quoted context omitted.

Epic violated the agreements they signed with Apple. Whether or not we care for the contents of the agreements is a separate issue. Apple did not capriciously act against Epic - if they had then Epic wouldn’t have had an advertising campaign and lawsuit ready to go within hours. The situation with WinRAR is completely different and it doesn’t help anything in trying to conflate the two; indeed it just muddies the wat…

I’d argue that it’s more similar than it seems, but with one caveat: Apple (rightfully) became the market leader, but is essentially running what should be a public market. If one company took over all the physical land on the planet, and had everyone sign agreements to essentially pay taxes to them with every transaction, would we still argue that that’s not only legal, but morally justified?

> If one company took over all the physical land [in a prohibitively large area], and had everyone sign agreements to essentially pay taxes to them [...] that [that is] legal

Well, that's basically the definition of a country, so...

Edit: countries tend to define what is legal.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#133

Earlier quoted context omitted.

I’d argue that it’s more similar than it seems, but with one caveat: Apple (rightfully) became the market leader, but is essentially running what should be a public market. If one company took over all the physical land on the planet, and had everyone sign agreements to essentially pay taxes to them with every transaction, would we still argue that that’s not only legal, but morally justified?

> If one company took over all the physical land [in a prohibitively large area], and had everyone sign agreements to essentially pay taxes to them [...] that [that is] legal Well, that's basically the definition of a country, so... Edit: countries tend to define what is legal.

so... ...?

Re: Information on the revocation of WinRAR 5.91 digital certificate

#134

Earlier quoted context omitted.

I’d argue that it’s more similar than it seems, but with one caveat: Apple (rightfully) became the market leader, but is essentially running what should be a public market. If one company took over all the physical land on the planet, and had everyone sign agreements to essentially pay taxes to them with every transaction, would we still argue that that’s not only legal, but morally justified?

>Apple (rightfully) became the market leader, but is essentially running what should be a public market. They became the market leader (and I say this as an Android person who dislikes Apple and would never own one) because it's not a public market - they offer a "premium" experience, and part of that is the heavily curated app store. Opening up the platform would undermine the whole reason why it's popular to begin…

You're saying that Apple is above reproach, criticism, oversight because it might make a dent in their $2T valuation?

Re: Information on the revocation of WinRAR 5.91 digital certificate

#135

> We think that revoking certificates based on questionable data discredits the certification system. It's hard to dispute this imo. There are many good reasons certificates should be revoked, but the reasoning should be 100% public information, for both the vendor and users who may have trusted the original certificate. I'm building a desktop app, and the process to even get a certificate is absurd. Each CA has thei…

> I'm building a desktop app, and the process to even get a certificate is absurd...

When switching providers, I don't suppose you tried K Software? Mitchell Vincent has fantastic personal customer service. Been a while since I last used his services, but he's always been patient & helpful when I ran into issues getting verified:

https://www.ksoftware.net/code-signing-certificates/

That said, I've noticed a lot of big companies in the music industry stopped signing their software altogether and distribute it unsigned now. Doesn't seem to have hurt their sales - or maybe even improved it, there's less lag on Windows launching an unsigned app.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#136
post #62

Earlier quoted context omitted.

It can extract files to paths of more than 260 characters, without any extra tools or registry hacks, on any version of windows (even xp). Winrar cannot. As a bonus, 7zip can also delete folders with file paths that are over 260 characters from its file manager ui. It has been one of the only programs to be able to do so for many years.

Amount of times this has been an issue with using Winrar for 15+ years : zero. I'm amazed at all the comments calling for 7zip as the one and only. winrar works just fine so does windows zip function. If you have an edge case, yeah then you need something that can handle it.

FWIW I agree with you, personally I also prefer Winrar, and have used it for many years with zero issues. I like its ui better than 7zip's. But the 260 chars is the one edge case that happened to be important to me and so I decided to switch.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#137

Earlier quoted context omitted.

There's another aspect of this situation that also discredits the system: that they can just go out and get a different cert from another vendor. How many such vendors are there? How long would it take for an actual bad actor to have all their certs discovered and revoked? If that time is long, then the certification process is of even more dubious value, since the bad guys would not be materially hindered by the cer…

The job of a certificate authority is to verify an identity, not to vet that the holder is using the certificate only for good. As long as the CAs do that job (which is a separate issue), it's fine if John Doe can get 50 different CAs to certify that he is, indeed, John Doe.

Take a look at the "Baseline Requirements for the Issuance and Management of Code Signing Certificates"[0] - specifically section 13.1.

Here's the most relevant excerpt:

> A CA MUST revoke a Code Signing Certificate in any of the four circumstances: (1) the Application Software Supplier requests revocation, (2) the subscriber requests revocation, , (3) a third party provides information that leads the CA to believe that the certificate is compromised or is being used for Suspect Code, or (4) the CA otherwise decides that the certificate should be revoked.

[0] https://cabforum.org/baseline-requirements-code-signing/

Re: Information on the revocation of WinRAR 5.91 digital certificate

#138

I know the authorities need to err on the side of caution, but it's quite astonishing to me that someone at the authority didn't just say 'It's WinRAR...' and let it slide. It's got to be one of the most well known tools in the entire windows ecosystem.

Build servers being compromised and used to inject malware into trusted, signed binaries is a thing that happens. Being one of the most well known tools in the entire Windows ecosystem makes WinRAR a particularly juicy target for trying to pull that off.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#139

It is particularly ironic that so many people in this thread are recommending 7-zip in response to a cert problem with WinRAR when 7-zip has no code signing at all and presents the scary yellow "unknown software" screen when you try to install it.

It's a bit like the way that plaintext HTTP is way easier to deal with than HTTPS, and the way browsers treat a self-signed cert as worse than no cert. Which... does lead to some odd outcomes, yes.

This (the "positive indication" problem in HTTPS) is gradually being fixed.

Shiny new features require Secure Context so (other than on localhost) you can't do them with HTTP at all. That means things like Geolocation, WebAuthn, Service Workers, and essentially anything that's actually novel (couldn't just be polyfilled with Javascript). There are even old features getting deprecated in non-Secure Contexts because in hindsight we should have required Secure Context but it was hard to pull the trigger. For example EME (the DRM for some video content online) will probably require Secure Context.

Browsers are also adding back scary warnings for some more basic features like form submission when used without Secure Context.

And some domains (including entire TLDs) are locked down to forbid HTTP anyway. If you type in an HTTP URL in those domains it's rewritten as HTTPS and you can't undo that†

† Some browsers can override this as a corporate policy, so if your company really wants to be less secure it can disable the upgrades for some or all domains. But out of the box this is how the browser behaves.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#140

Earlier quoted context omitted.

>Apple (rightfully) became the market leader, but is essentially running what should be a public market. They became the market leader (and I say this as an Android person who dislikes Apple and would never own one) because it's not a public market - they offer a "premium" experience, and part of that is the heavily curated app store. Opening up the platform would undermine the whole reason why it's popular to begin…

You're saying that Apple is above reproach, criticism, oversight because it might make a dent in their $2T valuation?

No, I'm saying two things:

1) Apple's popularity at least partially comes from their highly restricted platform. If you don't agree with the terms of use for that platform, or want to develop on a less restrictive platform, you are not forced to use it. It's not a public utility, and forcing Apple to open it would remove one of the fundamental aspects that made it successful to begin with.

2) It's fair for Apple to pass costs on to the third party developers who consume their resources, and unfair for Epic to try and subvert this - especially when their obligations were made clear in the terms of use for the platform.

Epic "only" have a 17 odd billion dollar valuation, so while they're not in the same ballpark as Apple they are by no means some helpless small business getting crushed by a giant corporate bully. As I see it, Epic are throwing a tantrum because they want all of the benefits of using Apple's platform and none of the drawbacks. Cutting off services for customers who refuse to pay is the norm in pretty much any other instance - why should this be different?

Post reply on HN