Live data from Hacker News

Information on the revocation of WinRAR 5.91 digital certificate

rarlab.com

81–90 of 156 posts

Re: Information on the revocation of WinRAR 5.91 digital certificate

#81
post #42

Earlier quoted context omitted.

You are misunderstanding. WinRAR's implication is that the CA is lying about the 570 MB file because they didn't mention it until WinRAR challenged them on the VirusTotal justification for revocation, and because they were unable to provide the file in question or any evidence that it exists.

Why not at least link to the virustotal listing for said file? Perhaps someone else has it from the hash? I doubt the CA would lie about the existence of such a file, although perhaps they are mistaken about the signature (it could be a case of a 570 MB file concatenated with a legitimately signed winrar executable - signatures don't always cover all parts of the file)

> Why not at least link to the virustotal listing for said file?

I don't think virustotal accepts files larger than 500 MB.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#82
post #42

Earlier quoted context omitted.

You are misunderstanding. WinRAR's implication is that the CA is lying about the 570 MB file because they didn't mention it until WinRAR challenged them on the VirusTotal justification for revocation, and because they were unable to provide the file in question or any evidence that it exists.

Why not at least link to the virustotal listing for said file? Perhaps someone else has it from the hash? I doubt the CA would lie about the existence of such a file, although perhaps they are mistaken about the signature (it could be a case of a 570 MB file concatenated with a legitimately signed winrar executable - signatures don't always cover all parts of the file)

It seems unlikely it's on VT:

1. VT has an upload limit of 128 MB. (Maybe the private API allows more, not sure.)

2. VT allows sample download if you have a VT Intelligence account - so if this was a file shared with VT, the CA should be able to provide the file.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#83
post #4

Earlier quoted context omitted.

Yes. People who don't know any better alternatives continue to use it, and continue to recommend it to other people. So the cycle continues. Heck, WinZip still makes new releases so I'm sure people still use that too.

Or maybe their customers just like the product, as in the GUI and feature and don’t care that another compression algorithm can shave off a few extra megabytes. If I recall correctly WinRAR can make self extracting archives pretty easily. If you use that feature it might be easier/better to just continue using WinRAR. I love the fact that small software companies like RARLAB can still exist.

I wonder how profitable they are. In Poland WinRAR was big at the time (still sort of is, but 7-zip taken over a lot of users), but buying license was actually point of jokes and memes. Everybody just used shareware trial and closed that nag window every time.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#84
post #51

Earlier quoted context omitted.

"Security-in-depth": https://news.ycombinator.com/item?id=24193087

On some level I get it but aren't cash cards a thing? What actual level of identity and KYC do these cert companies do? How easy is it for someone without scruples to get another cert without revealing their identity? (Genuine questions: I do not personally know.)

Cash cards can be distinguished against at the merchant level by most payment providers (and often are to prevent delayed charge fraud).

Re: Information on the revocation of WinRAR 5.91 digital certificate

#87
post #48
post #4

Earlier quoted context omitted.

Yes. People who don't know any better alternatives continue to use it, and continue to recommend it to other people. So the cycle continues. Heck, WinZip still makes new releases so I'm sure people still use that too.

There are alternatives with built in recovery records? Which ones? I am being serious.

That's the single remaining killer feature of RAR for me. I think the last time I actually used it was years ago when pulling a backup off of a degraded DVD-R, but it still provides a bit of peace of mind for long-term storage.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#88

Earlier quoted context omitted.

There's another aspect of this situation that also discredits the system: that they can just go out and get a different cert from another vendor. How many such vendors are there? How long would it take for an actual bad actor to have all their certs discovered and revoked? If that time is long, then the certification process is of even more dubious value, since the bad guys would not be materially hindered by the cer…

The job of a certificate authority is to verify an identity, not to vet that the holder is using the certificate only for good. As long as the CAs do that job (which is a separate issue), it's fine if John Doe can get 50 different CAs to certify that he is, indeed, John Doe.

Plainly whoever is issuing the cert we're discussing sees their role as much broader. Presumably the OS manufacturer also sees it that way.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#89
post #4

Earlier quoted context omitted.

Yes. People who don't know any better alternatives continue to use it, and continue to recommend it to other people. So the cycle continues. Heck, WinZip still makes new releases so I'm sure people still use that too.

> People who don't know any better alternatives continue to use it Genuine question: what are the better alternatives?

For zip files in particular, you can just right click and 'Extract all' in modern versions of Windows. I believe you can also double-click to open them like folders in Explorer.

7-Zip covers the majority of other formats you're likely to encounter.

Re: Information on the revocation of WinRAR 5.91 digital certificate

#90
post #11

With both Windows and MacOS both putting scary warnings and hard to bypass blocking methods on improperly signed software this could eventually lead to developers being ransomed, “pay us big money or we will revoke your certificate”. This is not the only incident like this.

A non-problem. Linux will run on x86 hardware till the end of time.
Post reply on HN