Live data from Hacker News

7zip.com Is Serving Malware

malwarebytes.com

1–10 of 104 posts

Re: 7zip.com Is Serving Malware

#7

Does the 7-Zip author still refuse to digitally sign or even provide hashes of the official downloads? It's an extremely weird flex, he thinks it's a frivolous waste of time or something.

Do people even double check installers are digitally signed? There's so much open source stuff out there that is not digitally signed, most people might not even notice.

Re: 7zip.com Is Serving Malware

#8

Does the 7-Zip author still refuse to digitally sign or even provide hashes of the official downloads? It's an extremely weird flex, he thinks it's a frivolous waste of time or something.

Do people even double check installers are digitally signed? There's so much open source stuff out there that is not digitally signed, most people might not even notice.

Windows has displayed a big scary orange prompt for at least the last decade when it isn't. More like 15-20 years IIRC.

But I'm sure people blindly click through the "Unknown author" prompt just as they would ignore a certificate error.

Re: 7zip.com Is Serving Malware

#9

Earlier quoted context omitted.

Do people even double check installers are digitally signed? There's so much open source stuff out there that is not digitally signed, most people might not even notice.

Windows has displayed a big scary orange prompt for at least the last decade when it isn't. More like 15-20 years IIRC. But I'm sure people blindly click through the "Unknown author" prompt just as they would ignore a certificate error.

Like I said, theres a LOT of open source projects that show that prompt. Signing an MSI involves having a valid CA certificate, which AFAIK is not free, and goes beyond the budget of most projects.

Re: 7zip.com Is Serving Malware

#10

Does the 7-Zip author still refuse to digitally sign or even provide hashes of the official downloads? It's an extremely weird flex, he thinks it's a frivolous waste of time or something.

He's always been an odd one, for a long time he refused to enable even basic hardening features like ASLR and DEP because they made the executables slightly larger. He eventually relented on some of those, but last I heard the more advanced mitigations like HE-ASLR, CFG and GS were still disabled.
Post reply on HN