6 ms·
WinRAR is (was?) developed in Russia, so it always seemed like a great way for the Russian FSB to hack foreign systems.
by iav 3y ago
WinRAR is (was?) developed in Russia, so it always seemed like a great way for the Russian FSB to hack foreign systems.
- fomine3 3y ago7-zip too. It seems that there are capable Russians about data compression.
- deleted 3y ago[deleted]
- xxpor 3y agoTIL, I was thrown off by the fact that it's a GmbH into thinking they were German.
- SillyUsername 3y agoWell this seems to suggest they're German https://www.win-rar.com/cookies.html?&L=0 https://www.win-rar.com/cookies.html?&L=0 The original author Eugene Roshal (iirc) isn't.
- nirui 3y agoHow is that conclusion came to mind? Did they wrote the entire code in Russian or the code just don't run on Russian computers? If you don't know, this is not even the first file compression related exploit. "Zip Slip"(0) for example, is just one year old, and there are many of them out there. [Zip Slip]: https://nvd.nist.gov/vuln/detail/CVE-2022-21675 https://nvd.nist.gov/vuln/detail/CVE-2022-21675
- jwilk 3y ago"Zip Slip" was a term made up in 2018 (see https://news.ycombinator.com/item?id=17237295 https://news.ycombinator.com/item?id=17237295) for a class of vulnerabilities that's been known since at least 2001.
- LinuxBender 3y agoThere is a tremendous amount of software created and maintained by Russian developers running on Windows, MacOS and Linux. One example would be NGinx which runs a good deal of websites on the internet. NGinx is now owned by F5 but still maintain the same developers. There is probably a better way to verify code, risk rank flaws and assign a level of trust. This should be an ongoing and ideally automated effort regardless of who is contributing code or hardware. I personally would like to see AI be able to review entire code bases and see the bigger picture because state sponsored lawful intercepts are rarely one piece of code but rather require multiple pieces of code and sometimes hardware to work in conjunction to form the back door.
- kgeist 3y agoYesterday I learned that a lot of crucial stuff in Postgres was developed by Russians (the list I saw was quite extensive). So if you run nginx+Postgres (like half the Internet?) then WinRAR is least of your concerns
- dewey 3y agoDifference being that PG / nginx are open source and audited unlike WinRAR.
- LinuxBender 3y agoThat's a fair point. Perhaps a solution could be that if someone were willing to pick up the par2cmdline code base and work with the 7-zip developers to merge it into their command line and GUI then there may not be many reasons left to utilize WinRAR.
- deleted 3y ago[deleted]
- mcast 3y agoI've met many incredibly talented eastern European engineers, who seem to overwhelmingly enjoy low-level programming (compilers, database internals, etc.). I don't see the concern.