Live data from Hacker News

Information on the revocation of WinRAR 5.91 digital certificate

rarlab.com

141–150 of 156 posts

Re: Information on the revocation of WinRAR 5.91 digital certificate

#141
post #29

The CA in question is CN = Sectigo RSA Code Signing CA

...previously known as Comodo. Did their reputation was so bad that they had to rebrand? https://sectigo.com/resource-library/comodo-ca-is-now-sectig...

Oh so it's another Comodo's bad reputation.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#142

Earlier quoted context omitted.

Or maybe their customers just like the product, as in the GUI and feature and don’t care that another compression algorithm can shave off a few extra megabytes. If I recall correctly WinRAR can make self extracting archives pretty easily. If you use that feature it might be easier/better to just continue using WinRAR. I love the fact that small software companies like RARLAB can still exist.

WinRAR seems to have added additional compression formats and algorithms, like 7zip and XZ: https://www.rarlab.com/otherfmt.htm WinZIP, too: https://www.winzip.com/win/en/lanall.html

> WinRAR seems to have added additional compression formats and algorithms, like 7zip and XZ: https://www.rarlab.com/otherfmt.htm

For decompression only. 7zip can work with these too. In fact 7zip (unlike winrar) can even create some of them.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#143

Earlier quoted context omitted.

You're saying that Apple is above reproach, criticism, oversight because it might make a dent in their $2T valuation?

No, I'm saying two things: 1) Apple's popularity at least partially comes from their highly restricted platform. If you don't agree with the terms of use for that platform, or want to develop on a less restrictive platform, you are not forced to use it. It's not a public utility, and forcing Apple to open it would remove one of the fundamental aspects that made it successful to begin with. 2) It's fair for Apple to p…

Ok. Thanks.

#1 I agree with the value proposition of Apple's App Store.

I disagree with your conclusion in two ways.

Treating these digital marketplaces, including App Store, the same as traditional physical marketplaces would remedy most of our current drama. I'm not saying we must nationalize these private platforms, thereby transmuting them to public open markets. I am saying that given their current economic importance, they must be normalized.

The job is as yet not done. As a long time enthusiastic Apple customer, I demand that App Store continues to improve. I want more curation, more safe guards, more fairness. Yes, for customers, App Store is currently best in class. And yet that's a pretty low bar.

re #2. The only opinion I have on the Apple vs Epic vs Fortnite slap fight is that any and all other content providers should also be able to fight it out with Apple on similar footing.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#144

Earlier quoted context omitted.

I’d argue that it’s more similar than it seems, but with one caveat: Apple (rightfully) became the market leader, but is essentially running what should be a public market. If one company took over all the physical land on the planet, and had everyone sign agreements to essentially pay taxes to them with every transaction, would we still argue that that’s not only legal, but morally justified?

>Apple (rightfully) became the market leader, but is essentially running what should be a public market. They became the market leader (and I say this as an Android person who dislikes Apple and would never own one) because it's not a public market - they offer a "premium" experience, and part of that is the heavily curated app store. Opening up the platform would undermine the whole reason why it's popular to begin…

> Do you not believe there is a significant ongoing cost relating to the Apple store? Bandwidth, storage, CDN, power and HVAC for equipment, other building / data centre costs, IT staff for maintaining the servers and services, developers to develop the store and maintain Apple's side of the arms race between malicious devs trying to fool Apple's automated checking and Apple trying to detect and prevent malicious apps being uploaded, other miscellaneous overheads (accounting, auditors, etc.)... why should they be prevented from collecting taxes to cover the costs?

Even Amazon’s S3, which is arguably one of the more expensive places to store data (and which covers all of Amazon’s overhead plus a healthy profit) is $0.023 per GB. Even the cheapest paid app/IAP is $.99, which gives Apple $.33, and is likely 100-200MB. In the 8GB case, that’s still $0.184 and there are a lot of potential IAPs to “make up costs” and use 0 bandwidth.

When you run the actual math, it’s very hard to argue for “massive ongoing costs” and “significant burden”, especially when Epic has said that they would host and distribute the files entirely themselves if given the ability.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#145
post #131

At my previous job we released updates to our Windows desktop application about 3-4 times per year. We had about 20'000 customers (but many of them not installing updates). We checked final build of our product on Virus Total before release and e-mail the various anti virus companies about the false positives. Thankfully, I wasn't the guy doing this work.

Unfortunately that doesn’t really help. We update an application about once a year but we get false positive alerts even months after AV programs have previously not complained about a binary. What’s worse is that not all AV vendors on Virus Total have an easy way to submit a false positive report and of those that do, the majority believes getting a false positive report to be an opt-in into their marketing mailing…

How is what these virus companies are doing not defamation? Are there any legal options you have when this happens to you?

And VirusTotal bears a large responsibility for this too - not only do they not make it easy to find contacts for the various anti virus engines as you have pointed out (while disavowing themselves of any responsibility), they will highlight a "Generic" AI bullshit detection from some random company in the same way as verified malware.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#146

Earlier quoted context omitted.

The other consideration is that verifying identity is pointless , because malware authors don't actually use their own identities, they just pull a code signing certificate from the 1% of their already-infected users who have one. Then they go out and infect a million more users with it and get 10,000 more code signing certificates. If all you're after is some kind of rate limiting then forget about identity verifica…

This is why code-signing certificates must be two-factor (e.g. embedded on a PIN secured smartcard where the private-key is protected from extraction by anybody ). My Tucows certificate is still a single *.pfx file - whereas my arguably less-consequential AATL (Adobe PDF signing) certificate is stuck on a crappy USB device that requires me to install marketing-laden software for. I miss my old commodity smartcard-bas…

Doesn't actually fix it:

https://www.schneier.com/essays/archives/2005/04/two-factor_...

Your computer is unknowingly infected with malware, you go to do an update to your app, you insert your smartcard and enter your PIN, the malware signs the malware author's thing with it.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#147
post #87
post #48

Earlier quoted context omitted.

There are alternatives with built in recovery records? Which ones? I am being serious.

That's the single remaining killer feature of RAR for me. I think the last time I actually used it was years ago when pulling a backup off of a degraded DVD-R, but it still provides a bit of peace of mind for long-term storage.

Any reason you can't use external PAR2 files? [0]

[0] https://en.wikipedia.org/wiki/Parchive

Re: Information on the revocation of WinRAR 5.91 digital certificate

#148
post #87

Earlier quoted context omitted.

That's the single remaining killer feature of RAR for me. I think the last time I actually used it was years ago when pulling a backup off of a degraded DVD-R, but it still provides a bit of peace of mind for long-term storage.

Any reason you can't use external PAR2 files? [0] [0] https://en.wikipedia.org/wiki/Parchive

It's the same thing as comparing Dropbox to an FTP server and Rsync. You can use it, it can be more powerful, but the unified experience is more convenient.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#149
post #124

Earlier quoted context omitted.

> Looking at application development I think a similar thing could be done, but what would we pin identity to? How about domain name? Whenever I install (Windows) software I rarely care about the mailing address or D.B.A. name; I look at the website address listed.

A domain name costs less than a dollar. A DBA or real-life identity cost significantly more. In addition, if I'm getting my software over the internet (99.99% of the cases), I'm already verifying the domain name via the browser (via tls), so it's not adding any additional security. If the server was hacked, the attacker can mint himself a new certificate and you won't be able to tell.

microsoft.com or debian.org would cost a lot more than $1 and I would trust signed or unsigned software downloaded from either a lot more than from a random domain name. Code-signing definitely adds the benefit of offline key management; there is less risk of signing keys being stolen than TLS keys. But the valuation of trust is rooted in the domain; if Debian has to revoke all their keys for some reason I'll trust debian.org over any other source for re-establishing a root of trust unless a significant fraction of the Internet and mailing lists are crying foul, and even then I would probably wait for control of debian.org to be settled before trusting any Debian repositories.

I still think that demonstrated control of a domain is sufficient for verifying a code-signing identity, even automatically like LetsEncrypt does for TLS.

Post reply on HN