Seven.zip
7-zip.org
7-zip.org
I hope apps will not make links out of .zip TLD.
Not trying to accuse anybody, just wondering.
You know that 7-zip.org is the official site. You see that's where you end up after the redirect. Just bookmark and use that. No reason to add more steps.
How would I know that, tho? What if 7-zip.com is the official, and 7-zip.com is a similar site with a malware?
It only takes some SEO to make it look plausible for many users who trust Google and see "seven.zip" as the first search result.
either way, what's the solution to prevention? disallow the entire TLD and every possible TLD that could lead to phishing? there are already plenty of issues with .com being used for phishing. have a regulatory body do ID verification of every registrant and if it sounds like a domain that could possibly be misused then ... what?
At least 7-zip.org could have a list of domains that they own and control if they wish people to use these alternate domains.
I would have assumed the main reason to register alternate domains like this would not be so people can use them, but rather to prevent others registering them and abusing them.
Anyway, I would never choose to fight this battle, feels rather futile. It doesn't help that they have a dash in the name, so they have to hunt down names with 7-zip and 7zip as well.
$ whois 7-zip.org
…
Registrar: GoDaddy.com, LLC
…
$ whois seven.zip
…
Registrar: Google LLC.
…
Name servers don’t match: $ dig +short 7-zip.org NS
ns01.domaincontrol.com.
ns02.domaincontrol.com.
$ dig +short seven.zip NS
ns-cloud-c1.googledomains.com.
ns-cloud-c2.googledomains.com.
ns-cloud-c3.googledomains.com.
ns-cloud-c4.googledomains.com.
(Aside: I believe these queries are strictly the wrong thing, asking seven.zip what its nameservers are, but you actually need to ask the zip. nameservers what seven.zip’s nameservers are. The two will normally match, but don’t actually have to, and in my crazy hacker dreams (you know, the ones where five dollar wrenches don’t exist) I can imagine the difference being used sneakily. But I’m not sure if there’s any good way of asking for the actual nameservers with dig, which is basically “`dig +short zip. NS`, then `dig +short @one-of-those-zip-nameserver-addresses seven.zip. NS`”, and yes, you’d need to follow more steps if you were dealing with a deeper domain name. Whois records are actually more convenient in general!)And servers don’t match:
$ dig +short 7-zip.org
49.12.202.237
$ dig +short -x 49.12.202.237
static.237.202.12.49.clients.your-server.de.
$ dig +short seven.zip
216.239.36.21
216.239.34.21
216.239.32.21
216.239.38.21
$ dig +short -x 216.239.36.21
any-in-2415.1e100.net.
These checks give no reason to suspect it’s legitimate.Step 2. Redirect to X
Step 3. Gain popularity quickly and appear as a legitimate alias of X
Step 4. Take control of X
Step 5. ...
Step 6. Profit
This is both much-needed and incredibly inconvenient in the world of windows binary distribution.
A public key does not exist in a vacuum. Ideally, it is part of a larger "web of trust", having been signed by others in that web. Unfortunately, websites like 7-zip.org do: they are socially isolated, which is where this situation of mistrust originated. Package managers (like Debian's apt or Archlinux' pacman) are at the advantage here, because the social coordination of a software repository sets the perfect circumstances for a web of trust; and the package manager itself automatically checks gpg signatures after downloading each package.
For power users on any modern Windows 10/Windows 11 there is at least WinGet now. Its manifests repo is becoming a very interesting (open) source of truth for common Windows applications. Admittedly, it in most cases doesn't seem to be checking specific code signatures in most cases either, but at least includes SHA checksums.
For instance, 7zip's manifests: https://github.com/microsoft/winget-pkgs/tree/master/manifes...
It's too bad there's still not a great option for "average user that doesn't know/trust how to use a CLI", given how sadly polluted the Microsoft Store can be for many common, especially Open Source, applications. For direct instance, because winget kindly includes Microsoft Store results when searching, there is a "7zip 22" in the Microsoft Store that costs some amount of money (winget details say "PaidUnknownPrice" for the pricing information; I'm on a corporate machine right now with the actual Store access locked so can't search in the actual Store right now) and the Publisher is listed as RepackagerExpress.com. (That website currently doesn't go anywhere, giving it a spot check.)
Having seen this, I may boot up my personal machine and try to report this specific Store listing for violating the Store's Open Source policies, though I'm unsure if such whackamole is all that useful. (Seems like it might be a useful winget feature request for it to provide Store Report URLs.)
The Cathedral cannot emulate a Bazaar.
Finding a legitimate download one time is better than having to find it every time.
Bootstrapping keys is a difficult thing for sure, but TOFU is still better than nothing at all and seems to work pretty well in practice.
For example, http://byurejects.com/ redirects to https://admissions.utah.edu/apply/
IDK exactly who owns "byurejects.com" but I'm guessing it's not "utah.edu."
(Background: Brigham Young University and University of Utah are rivals.)
In this particular case though, it's a 301/Permanent redirect[0], meaning it should be remembered forever. This includes the domain not being listed by search engines[1] (the target URL is used) and once you've visited it on your system it will remember the redirect indefinitely.
The point being, you don't need to trust who set it up, it's very hard to undo. If someone wanted to do this nefariously or reserve the right to use the domain in a different way in the future, they would want to use a temporary redirect.
[0]: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/301 [1]: https://developers.google.com/search/docs/crawling-indexing/...
Without a statement on the official 7-zip site, I'd assume it's unofficial and untrustworthy.
Sadly it seems the address was 'corrected' and instead was posted as 7-zip.org
If you go to https://seven.zip it does indeed redirect to 7-zip.org :)
I was wondering why this submission with this name, when the page title is 7-zip and the download is a .exe and not called seven.zip or so, but then remembered the recently (stupidly) approved TLD that is .zip
Edit: well https://i.snipboard.io/uAo7BG.jpg
I was actually hoping for 7.zip :)
Speaking of domain names, what is the best option for the cheapest possible domain tld (including renewal), maybe something you can even get for 10 years and save a ton? Also would be nice if it had free whois? Extension doesn't matter as this would be for personal use. Is it still xyz or ovh?
I've also heard .in is a good place for 10-year registrations (at another registrar I don't remember). However, .in domains do not have WHOIS privacy.
It's still a rough MVP but it's online and working: https://www.getlocalcert.net/
Other than that, yeah, it's a cesspool.
I was just thinking for personal projects & game servers, would be nice to have a bunch of cheap domains one could use.
Formatting prob sucks, on mobilr, sorry:
cheapestdomainame.xyz$1.99
MULTI-YEAR SALE
cheapestdomainame.lol$1.99
MULTI-YEAR SALE
cheapestdomainame.org$8.99
cheapestdomainame.me
The connection to the central registry is busy. Please try again later
cheapestdomainame.pro$3.85
cheapestdomainame.co$3.49
cheapestdomainame.gay$2.99
cheapestdomainame.one$14.99
cheapestdomainame.sucks$249.99Do prices change a lot?
imo better integration with Win 10/11 context menus and more compression codecs
.sh also exists and the world didn't burn.
If I send an email to my (less technically minded) family I may attach photos.zip. If I mention photos.zip in the body then the mail client may now convert it to a link. If http[://]photos.zip is a malware site, my family may download malware. I may inadvertently link to a malware site by talking about a zip file.
I could also send an email with "install.sh" as an attachment, and mention it in the body. http[://]install.sh could be a malware site too.
The differences. Non-technical people send, receive, and talk about zip files much more often.
.sh was also registered with a clear reason, it's a ccTLD, it's for a country. .zip is just a vanity gTLD. If Zipland was a country, I'd support .zip or ideally .zp. Without a clear purpose and with clear malicious uses, people are just going to block the TLD. Lots of IT folks talking about implementing it on Reddit.
Even if not, you have the regular browser protections against downloading malware which are always active (deny-lists, reputation, scanning, ...).
> Without a clear purpose
The clear purpose is freedom of expression. Why should TLDs be limited to country codes? Allowing generic TLDs also relieves pressure on .com and brings down domain costs, since now you can have an interesting.space or cool.site
Google also registered .dad, .prof, .phd, .esq, .foo, .mov, and, .nexus. I've seen similar complaints about .mov, but there's no opposition to the others or gTLDs in general.
https://www.blog.google/products/registry/8-new-top-level-do...
I support freedom of expression through TLDs but there's a meaningful pre-existing use of .zip. It's not clear to me that the value of the TLD outweighs the phishing risk, the malware risk, the cost of software developers preventing x.zip from rendering as a link, etc. It's possible the TLD ends up on a block lists and eventually gets discontinued.
.app is an extension used on MacOS for app installers. Yet the .app TLD didn't seem to materialize phishing/malware risk since it's 2018 introduction.
The exact same arguments were made back then:
But .zip already has malicious use, so the comparison is moot. What's different is that normal users of all platforms talk about .zip files, only slightly-technical MacOS users talk about .app. That attack base and opportunity is much smaller.
https://news.netcraft.com/archives/2023/05/17/phishing-attac...
Google has made some interesting choices in the sorts of gTLDs it has registered since it has had the capability to do so.
7z -something < file.7z | whatever > out.file
Personally, I would use 'xz -9' if I wanted high compression, it works better with UNIX type systems Systems.
-so Write data to StdOut
and...
-si Read data from StdIn
Sizes:
* uncompress: 36,495,045,244
* gz: 18,729,830,001
* xz: 16,739,567,484
* 7z: 16,257,755,606
7z ended up being about 480 meg smaller, in a way that was a bit unexpected. I was expecting xz to be slightly smaller.
Also, this process took about 15 hours.
You can try something like CoreDNS or maybe Acrylic DNS Proxy which is a small local proxy that adds wildcard and even regexp support: https://mayakron.altervista.org/support/acrylic/Home.htm
https://github.com/aonez/Keka/wiki/Rar-compression
Sounds like it is a licensing issue more than anything? People still compress to RAR?
From the home page (https://www.keka.io/en/):
Keka can create files in these formats:
7Z ZIP TAR GZIP BZIP2 XZ LZIP DMG ISO BROTLI ZSTD LRZIP AAR WIM
And extract all of these formats:
7Z ZIP ZIPX RAR TAR GZIP BZIP2 XZ LZIP DMG ISO BROTLI ZSTD LRZIP LZMA EXE CAB WIM MSI PAX JAR WAR IPA XIP APK APPX XPI WPRESS IS3 CPGZ CPIO CPT SPK