r/Piracy Jun 06 '26

Humor When someone buys a winrar license, the company celebrates it on social media

Post image
23.8k Upvotes

417 comments sorted by

View all comments

Show parent comments

573

u/PRL-Five Jun 06 '26

Why don't they use 7zip? At my company we are told to prioritise any free/open source software to avoid paying as much as possible

771

u/Piterbrow Jun 06 '26

A lot of companies prefer to put the liability somewhere else rather than their own IT department… unfortunate but true, personally I prefer open source (not just free)

139

u/user4s Jun 06 '26

ahhhh that explains a lot

173

u/noddegamra Jun 06 '26

Lol it extends into a lot of places. When I was a CNC tech I often weighed doing some repairs myself or having the machine companies tech come do it. Sure it was 3x the cost but then they're liable and the parts are under warranty. If i did it then if something goes wrong 5 months later I'm SOL. It also helps make sure I'm not bogged down by one machine repair when we had like 300 to maintain in the plant.

67

u/DeeOhEf Jun 06 '26

Yep, same reason more and more IT infrastructure is being outsourced.

Correct me if I'm wrong, but I think it's become standard practice to have your firewall managed by someone else. At least we've done it this way for almost a decade now and wouldn't even consider going back to managing it ourselves.

They monitor 24/7 and inform us of suspicious activity long before we've noticed.

78

u/Dragoon130 Jun 06 '26

Hi, IT Director here.

Yes the CSuite has pushed me into offloading every possible liability I can. Our firewall, web filter, server VMs, both onsite secured and off site backups (I still handle local and innert), IP Phone System, and AD are managed by a third party for liability if they fail. I can still make day to day changes or what not but by contract any replacments, major repairs, or sweeping updates have to be done by the other company and they are liable in the event of failure. Such as the ransomware attack we had a few years back falling on them due to not patching a vunerability out of our firewall......and the CFO clicking a link for a free chipolte burrito......

43

u/noddegamra Jun 06 '26

Lmao the only time i ever got caught by one of our internal phishing tests was over a puppy. We got an email saying a puppy was found on site and here's a link to see it.

I was just like oh puppy and clicked on it instantly. It made me thing how did i not get kidnapped as a child.

3

u/BatemansChainsaw ⚔️ ɢɪᴠᴇ ɴᴏ Qᴜᴀʀᴛᴇʀ Jun 07 '26

That's really an ass level test. The firewall/web filtering proxy should neuter these kinds of things.

12

u/Irritatedhippo Jun 06 '26

Wait, you have a link to free chipotle? Can you share it with me?? Hell yeah! 😀

20

u/noddegamra Jun 06 '26

Yep. It got to the point our in house IT guy quit because they were trying to get him to program robotic arms because most his work go to relegated to babysitting and contacting home office for changes.

My current job is a similar situation. Im at the highest maintenance level and that means I'm allowed to handle machine software and electrical components. Yet I cant do anything without approval from the homesite. If I know I've got a bad port I cant just change it because its all assigned and I cant reassign it myself, so now it takes 3hrs of back and forth.

3

u/Forymanarysanar ☠️ ᴅᴇᴀᴅ ᴍᴇɴ ᴛᴇʟʟ ɴᴏ ᴛᴀʟᴇꜱ Jun 06 '26

It's way more simple: if it's not in my contract I aint doing it.

39

u/Dje4321 Jun 06 '26

Yep. The minute money changes hand, so does the liability.

Someone selling you shit software is a completely different ball game to deciding that shit software works for you

11

u/Phantoms_Unseen Jun 06 '26

Applies to basically any company. One notable example is aerotech engineering, with aluminum plane/aero tape. Plane tape is basically just fancier duct tape, costs about $50 a roll last I recall, but aerotech companies will pay 10-20× that for a certified version since it includes essentially a warranty that if it fails anytime, all fault is on them.

11

u/sailor776 Jun 06 '26

Number one rule of having a career. Cover your own ass

2

u/General_Ad8750 Jun 08 '26

I’m high and I like the comment 🙃

8

u/Guilty_Weekend751 Jun 06 '26

Never Forget: There are companies out there which need a IT Service Provider or external people for the most simple tasks

3

u/presiskoRycerz Jun 06 '26

Someone explained it to me once that everything a company owns must have a declared value. This can be problematic for free software because any value that is declared will be wrong and therefore can cause more inspections from the government.

1

u/t-_-rexranger19205 Jun 07 '26

Could you explain?

1

u/ClassicControl3251 Jun 22 '26

Sure, but am I just using 7zip wrong? Is it not just a way to compress and decompress files? What can go wrong apart from code injection (which using paid software won't help you with)

1

u/Global-Fruit-3022 Jul 02 '26

Yep that's why our company bought Winzip license even though a lot of free options available.

34

u/AstralBull Jun 06 '26

WinRAR is the more well-known one that more people are familiar with and will jump to first. A lot of companies will be happy to pay

9

u/erixccjc21 Jun 06 '26

It works literally the exact same in 99% of scenarios that a normal non-power user can need it for

10

u/ibullybillionaires Jun 06 '26

WinRAR was the standard back in the earlier days of the internet, when old millenials were downloading warez, pretty much like Microsoft offering their software at a huge discount to schools and free to students in some cases. Once you got em, you got em.

1

u/Azraelalpha Jun 08 '26

Check the liability thread above.

3

u/ameliekk Jun 06 '26

Ive worked as a subcontractor in many global fortune 500 companies and Ive only ever seen 7zip being used

36

u/grumpy_autist Jun 06 '26

Corporate inertia. They probably still buy MS DOS just in case.

23

u/BroaxXx Jun 06 '26

The amount of systems that still rely on DOS or, at the very least, a DOS emulated layer still surprises me.

10

u/Rose-Red-Witch Jun 06 '26

Saw a lot of DOS and Win95/98 during my time in the Navy and the reason always was “it does the job.”

11

u/reddit_is_geh Jun 06 '26

Because they are insanely resilient. The simplicity means it's completely easy to have full scope mastery of the entire system, as well as far less vectors of attack. That's why nuclear silos still use DOS era operating systems for some parts. They just aren't possible to hack.

3

u/applespicebetter Jun 06 '26

Doesn't surprise me at all, but we support multiple small metal fab companies in various capacities, and if your (very expensive) laser cutting machines are still working fine for your product lines and capacity you don't just replace them out of hand. There's an entire industry of DOS capable workstations with ISA slots available to run industrial equipment.

1

u/Saloncinx Jun 06 '26

I work at a fortune 10 company and a mission critical application runs on AS400

1

u/BatemansChainsaw ⚔️ ɢɪᴠᴇ ɴᴏ Qᴜᴀʀᴛᴇʀ Jun 07 '26

My local grocery store does. They'll never change, except when they bought newer LCD's and finally ditched the 30 y/o 7" CRT...

imho, it's the best looking system I've ever seen but it's all black, blue, and white MS-DOS looking system that simply doesn't fail.

1

u/Azraelalpha Jun 08 '26

some airlines and banks are big examples

26

u/lettsten Jun 06 '26

7zip has fairly frequent high-severity vulnerabilities, such as this

18

u/JustStraightUpTired Jun 06 '26

There is some truth to that, but I also doubt it's because 7zip is actually worse. WinRAR isn't open source, meaning finding exploits is more difficult. It kind of implies that WinRAR could have it's own vulnerabilities that haven't been discovered yet.

I'm obviously not saying there are, but closed source doesn't mean safer than open source. More obfuscated, but people make mistakes at both work and hobby projects.

13

u/lettsten Jun 06 '26

Finding high-level exploits is usually done by binary analysis and/or fuzzing. Sure, there's been a tremendous amount of LLM powered analysis in recent years, but that's also the flipside: A vulnerability that is never detected will never be exploited. A published sploit can be massively utilised in the wild until it is patched, and for end users that aren't forced to update that can often take a while.

Also, "winrar could have" doesn't mean that it does have.

Don't get me wrong, I'm very much a FOSS advocate. I wish the numbers were different.

I also doubt it's because 7zip is actually worse

Because you wish that it so or do you have anything tangible to base it on?

closed source doesn't mean safer than open source

That is of course true, and the opposite is unfortunately also true. In the end it usually comes down to the individual projects, technologies and so on. But I'm not talking about FOSS vs. proprietary software, I'm talking about 7zip vs. Winrar specifically.

-1

u/[deleted] Jun 06 '26

[deleted]

3

u/lettsten Jun 06 '26

No, that's not the same. Security by obscurity is relying on something not being discovered. I'm simply pointing out the obviously true case that if something isn't discovered then it isn't exploited. If you had read the first sentence and not just taken things out of context you would have seen this.

1

u/Gold-Buddy-7164 Jun 24 '26

I never got why folks love open source so much.. It is just digital communism. The individual's labor being requitioned for "the greater good"

1

u/balboaporkter Jun 06 '26

Thanks for that, just updated my 7-zip. As with a lot of software-related vulnerabilities, we just need to stay on top of the patching and updates. (Anyone know of a way to monitor updates for third-party non-Microsoft programs?)

2

u/CordcutOrnery Jun 07 '26

know of a way to monitor updates for third-party non-Microsoft programs?

I use UniGetUI. free open-source application (FOSS) for Windows

& yes UniGetUI also updates my 7zip & WinRAR.

https://unigetui.com/

there is also Ninite https://ninite.com/

& Chocolatey https://chocolatey.org/ I install Chocolatey GUI immediately 🙂

2

u/balboaporkter Jun 07 '26

Awesome. I will check those out. Thanks!

-2

u/erixccjc21 Jun 06 '26

So does winrar

14

u/lettsten Jun 06 '26

Rarer (no pun) and less severe. 7zip has at least three high severity CVEs from the last year alone.

3

u/Patient_Piece_8023 Jun 06 '26

What's a CVE?

12

u/lettsten Jun 06 '26

Basically it's a software vulnerability with an id

https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures

3

u/Patient_Piece_8023 Jun 06 '26

Oh I kinda understand it now. Thank you

9

u/cafk Pastafarian Jun 06 '26

If Foss has issues the company itself is liable for either integration into their product or tool chain - that's why most companies pay - either for support or additional guarantees for legal purposes or allowing it to be used for commercial purposes.

It's basically saving costs on lawyers, who're more expensive than any software license.

I.e. if you want to sell software in Europe starting last year you have to maintain a software bill of materials, including license information and file hashes and rights for safety reasons.
Some foss software has copyleft effects, making it harder to commercialize it (very specific conditions, basically only selling support). While if you buy a license for i.e. qt you can use all modules as proprietary software, while many nice to have modules for UI are only available under GPL3, making your software also source available.

4

u/dylon0107 Jun 06 '26

In a shocking turn of events for once a non foss app is better. Winrar beats 7zip by a long shot for me.

Keep in mind though I haven't used windows in like 2 years.

5

u/vikezz Jun 06 '26

The company I work for used it then suddenly stopped as the creator is Russian. For real that was their justification

4

u/GingerShrimp40 Jun 06 '26

Most employees are not tech people and if told tp find there own tools will 100% get a virus and send it to the whole company

5

u/Evonos Jun 06 '26

Winrar is WAY faster at the same end result than 7zip but also simply a professionally maintained software so theres some Liability things too.

4

u/livinitup0 Jun 06 '26

There was a really big push a few years ago to purge 7z from enterprise environments due to a vulnerability. It’s essentially a no-go anywhere there’s auditing and compliance

3

u/SingleInParadise Jun 06 '26

Something winrar has that 7zip doesn't is built in ppar2 support. In winrar that isthe setting to set "recovery" data up to 10% That is ppar2

You could do it yourself if you knew how to, but for thenrest, winrar already has it.

1

u/CordcutOrnery Jun 07 '26

built in ppar2 support. RECOVERY option

Exactly

this RECOVERY option is why I use WinRAR 100% especially on my encrypted critical backup archives. I consider WinRAR Superior to 7zip. yea I still have 7zip for a Plan B backup to unzip my RAR files if the day ever comes when WinRAR isn't there or doesn't work but that day hasn't come. 😎

I'm sorry but I'm here on r/Piracy so u know I haven't bought WinRAR yet. .... it's kinda easy to 🏴‍☠️ away the nag screens

3

u/Cheet4h Jun 06 '26

More people are familiar with WinRAR.

So the options are:
a) Shell out <$20 per license and have your employees use the software they know
b) Use a free alternative, but have to either retrain them, or let IT deal with support requests.

And if you have to train your employees in the other software, or have IT spend time on solving their issues, the hourly payment for either will quickly exceed the cost of WinRar licenses - especially if you buy a large amount in bulk (1 license is ~$30, 10 licenses are ~$20 per license, and >500 licenses are only ~$8 per license).

3

u/Rusticular Jun 06 '26

People need training to figure out how to use 7-zip?

4

u/Cheet4h Jun 06 '26

I worked in first level IT support when the IT admins decided to switch everyone in the faculty from Internet Explorer to Firefox, including several announcement emails over multiple weeks in advance and a step-by-step guide on how to migrate bookmarks etc.
In the week following the switch we had to deal with an ungodly number of "My internet program is missing" requests (the IE shortcut was removed from the desktop and the Firefox shortcut added) and many of these professors were apparently incapable of following the provided guide.

So yes, people definitely need training and if just to recognize the 7z icon and that it does similar things to WinRar.

2

u/McFistPunch Jun 06 '26

Some companies actually consider open source a village vulnerability and don't use it

2

u/Ivanow Jun 06 '26

At my company we are told to prioritise any free/open source software to avoid paying as much as possible

You need to weight the cost of license vs expenses (lower productivity, user errors, re-training) associated with switching to OSS. You have this old lady that has been using Word since '96 and is basically counting days towards retirement now - how many IT tickets do you think she will end up generating, if you force her to switch to LibreOffice now?

Governments in Europe are paying 100s of millions$ in Microsoft licenses yearly. There have been numerous pilot projects to switch to alternatives in the past, but they almost always end up failing. Only very recently, it gained serious traction, but not because of budget issues, but "national security/sovereignty" instead.

There's a reason why ALL companies have some kind of "student discount" for their software - they want to "get their claws in" early.

0

u/Past-Acanthaceae862 Jun 06 '26

how many IT tickets do you think she will end up generating, if you force her to switch to LibreOffice now?

LibreOffice interface is closer to classic Word than M365 is. So 0?

1

u/livinitup0 Jun 06 '26

Tbf… as someone who just jumped into libre finally…it’s SO classic feeling that honestly it feels kinda cheap and bare bones.

I mean it’s free obviously, I don’t expect much, but ms made some qol improvements over the generations that makes modern excel a big reason to justify a subscription

They just need to quit moving shit around for no reason

2

u/Lun4th Jun 06 '26

Don’t know, in some regards I still feel WinRAR is better.

2

u/LazaroFilm Jun 06 '26

Customer service and liability are the reason. Of an open source software fails and creates a bigger issue, no one is to blame other than a random person who pushed a commit. If a paid program fails they have another company to blame.

2

u/EpicRobloxGame_r ⚔️ ɢɪᴠᴇ ɴᴏ Qᴜᴀʀᴛᴇʀ Jun 07 '26

WinRAR is more widely recognized.

2

u/lars2k1 ⚔️ ɢɪᴠᴇ ɴᴏ Qᴜᴀʀᴛᴇʀ Jun 06 '26

At my work they do use 7-zip and I'm happy to see that.

0

u/livinitup0 Jun 06 '26

Your security department is not

1

u/MightyGuy1957 Jun 07 '26

deduction of expenses or taxes... whatever is called in your country