5 ms·
That will probably turn out to have been a mistake. RAR should not be easy to use. TAR and CPIO would have been better formats to support out of the box.
by i2cmaster 3y ago
That will probably turn out to have been a mistake. RAR should not be easy to use. TAR and CPIO would have been better formats to support out of the box.
- rincebrain 3y agoSince it's "libarchive" support, good news, we get those too.
- i2cmaster 3y agoYeah, I saw that. My worry is that this will just make drive-by malware easier.
- rincebrain 3y agoAntimalware engines have already had to support unpacking somewhat arbitrary things, sometimes with serious comedic effects when people fuzzed those unpackers; I don't see this significantly increasing the burden of their examination, signed binaries are no more dangerous after this than before, and unsigned binaries could already bring their own arbitrary unpacker. (At least quickly thinking about it; I could easily have overlooked some complexity, but barring an unpatched libarchive exploit, I don't think this markedly increases attack surface...and at that point, you could probably make similar arguments about adding any new file format?)
- meinheld111 3y ago> RAR should not be easy to use Why is that?