Live data from Hacker News

7zip.com Is Serving Malware

malwarebytes.com

11–20 of 104 posts

Re: 7zip.com Is Serving Malware

#11

Earlier quoted context omitted.

Do people even double check installers are digitally signed? There's so much open source stuff out there that is not digitally signed, most people might not even notice.

Windows has displayed a big scary orange prompt for at least the last decade when it isn't. More like 15-20 years IIRC. But I'm sure people blindly click through the "Unknown author" prompt just as they would ignore a certificate error.

Orange? It's a blue warning isn't it? Is this how one of us finds out he's colour blind?

Re: 7zip.com Is Serving Malware

#12

Earlier quoted context omitted.

Windows has displayed a big scary orange prompt for at least the last decade when it isn't. More like 15-20 years IIRC. But I'm sure people blindly click through the "Unknown author" prompt just as they would ignore a certificate error.

Like I said, theres a LOT of open source projects that show that prompt. Signing an MSI involves having a valid CA certificate, which AFAIK is not free, and goes beyond the budget of most projects.

It's not free but it's not expensive either. Most well known Windows open source projects have them; e.g. PuTTY, Wireguard, VLC, Rufus, etc.

Maybe it's high time for a free-as-in-beer CA for non-profit open source developers funded by donations?

Edit: I was wrong.

Prices on code signing certificates have skyrocketed to in excess of $500/year, due in part to continuing meddling by the CA/B forum which increased the requirements of standard certs to be the same as EV certs, and requiring the key to be stored in a hardware token—which must now be re-issued yearly.

This makes it near impossible to provide free or affordable certificates to developers. Thanks CA/B forum, lots of help as usual.

Re: 7zip.com Is Serving Malware

#13

Earlier quoted context omitted.

Windows has displayed a big scary orange prompt for at least the last decade when it isn't. More like 15-20 years IIRC. But I'm sure people blindly click through the "Unknown author" prompt just as they would ignore a certificate error.

Orange? It's a blue warning isn't it? Is this how one of us finds out he's colour blind?

Blue when it has a valid signature.

Orange when it's missing or invalid.

Re: 7zip.com Is Serving Malware

#14

Earlier quoted context omitted.

Windows has displayed a big scary orange prompt for at least the last decade when it isn't. More like 15-20 years IIRC. But I'm sure people blindly click through the "Unknown author" prompt just as they would ignore a certificate error.

Orange? It's a blue warning isn't it? Is this how one of us finds out he's colour blind?

The UAC dialog for unsigned software has an orange or yellow accent. You could be talking about the SmartScreen dialog. There's yet another dialog for executable files downloaded from the internet, which I think has a red shield for unsigned software.

Re: 7zip.com Is Serving Malware

#15
post #6

7zip.com has never been the official website of the project. It's been 7-zip.org

How can the average 7zip user know which one it is?

Search results can be gamed by SEO, there were also cases of malware developers buying ads so links to the malware download show up above legitimate ones. Wikipedia works only for projects prominent enough to have a Wikipedia page.

What are the other mechanisms for finding out the official website of a software?

Re: 7zip.com Is Serving Malware

#16

Does the 7-Zip author still refuse to digitally sign or even provide hashes of the official downloads? It's an extremely weird flex, he thinks it's a frivolous waste of time or something.

I migrated from 7-Zip to NanaZip, a fork with modern Windows features that the original developer refuses to implement.

https://github.com/M2Team/NanaZip

Post reply on HN