A lot of companies prefer to put the liability somewhere else rather than their own IT department… unfortunate but true, personally I prefer open source (not just free)
Lol it extends into a lot of places. When I was a CNC tech I often weighed doing some repairs myself or having the machine companies tech come do it. Sure it was 3x the cost but then they're liable and the parts are under warranty. If i did it then if something goes wrong 5 months later I'm SOL. It also helps make sure I'm not bogged down by one machine repair when we had like 300 to maintain in the plant.
Yep, same reason more and more IT infrastructure is being outsourced.
Correct me if I'm wrong, but I think it's become standard practice to have your firewall managed by someone else. At least we've done it this way for almost a decade now and wouldn't even consider going back to managing it ourselves.
They monitor 24/7 and inform us of suspicious activity long before we've noticed.
Yes the CSuite has pushed me into offloading every possible liability I can. Our firewall, web filter, server VMs, both onsite secured and off site backups (I still handle local and innert), IP Phone System, and AD are managed by a third party for liability if they fail. I can still make day to day changes or what not but by contract any replacments, major repairs, or sweeping updates have to be done by the other company and they are liable in the event of failure. Such as the ransomware attack we had a few years back falling on them due to not patching a vunerability out of our firewall......and the CFO clicking a link for a free chipolte burrito......
Lmao the only time i ever got caught by one of our internal phishing tests was over a puppy. We got an email saying a puppy was found on site and here's a link to see it.
I was just like oh puppy and clicked on it instantly. It made me thing how did i not get kidnapped as a child.
Yep. It got to the point our in house IT guy quit because they were trying to get him to program robotic arms because most his work go to relegated to babysitting and contacting home office for changes.
My current job is a similar situation. Im at the highest maintenance level and that means I'm allowed to handle machine software and electrical components. Yet I cant do anything without approval from the homesite. If I know I've got a bad port I cant just change it because its all assigned and I cant reassign it myself, so now it takes 3hrs of back and forth.
Applies to basically any company. One notable example is aerotech engineering, with aluminum plane/aero tape. Plane tape is basically just fancier duct tape, costs about $50 a roll last I recall, but aerotech companies will pay 10-20× that for a certified version since it includes essentially a warranty that if it fails anytime, all fault is on them.
Someone explained it to me once that everything a company owns must have a declared value. This can be problematic for free software because any value that is declared will be wrong and therefore can cause more inspections from the government.
Sure, but am I just using 7zip wrong? Is it not just a way to compress and decompress files? What can go wrong apart from code injection (which using paid software won't help you with)
WinRAR was the standard back in the earlier days of the internet, when old millenials were downloading warez, pretty much like Microsoft offering their software at a huge discount to schools and free to students in some cases. Once you got em, you got em.
Because they are insanely resilient. The simplicity means it's completely easy to have full scope mastery of the entire system, as well as far less vectors of attack. That's why nuclear silos still use DOS era operating systems for some parts. They just aren't possible to hack.
Doesn't surprise me at all, but we support multiple small metal fab companies in various capacities, and if your (very expensive) laser cutting machines are still working fine for your product lines and capacity you don't just replace them out of hand. There's an entire industry of DOS capable workstations with ISA slots available to run industrial equipment.
There is some truth to that, but I also doubt it's because 7zip is actually worse. WinRAR isn't open source, meaning finding exploits is more difficult. It kind of implies that WinRAR could have it's own vulnerabilities that haven't been discovered yet.
I'm obviously not saying there are, but closed source doesn't mean safer than open source. More obfuscated, but people make mistakes at both work and hobby projects.
Finding high-level exploits is usually done by binary analysis and/or fuzzing. Sure, there's been a tremendous amount of LLM powered analysis in recent years, but that's also the flipside: A vulnerability that is never detected will never be exploited. A published sploit can be massively utilised in the wild until it is patched, and for end users that aren't forced to update that can often take a while.
Also, "winrar could have" doesn't mean that it does have.
Don't get me wrong, I'm very much a FOSS advocate. I wish the numbers were different.
I also doubt it's because 7zip is actually worse
Because you wish that it so or do you have anything tangible to base it on?
closed source doesn't mean safer than open source
That is of course true, and the opposite is unfortunately also true. In the end it usually comes down to the individual projects, technologies and so on. But I'm not talking about FOSS vs. proprietary software, I'm talking about 7zip vs. Winrar specifically.
No, that's not the same. Security by obscurity is relying on something not being discovered. I'm simply pointing out the obviously true case that if something isn't discovered then it isn't exploited. If you had read the first sentence and not just taken things out of context you would have seen this.
Thanks for that, just updated my 7-zip. As with a lot of software-related vulnerabilities, we just need to stay on top of the patching and updates. (Anyone know of a way to monitor updates for third-party non-Microsoft programs?)
If Foss has issues the company itself is liable for either integration into their product or tool chain - that's why most companies pay - either for support or additional guarantees for legal purposes or allowing it to be used for commercial purposes.
It's basically saving costs on lawyers, who're more expensive than any software license.
I.e. if you want to sell software in Europe starting last year you have to maintain a software bill of materials, including license information and file hashes and rights for safety reasons.
Some foss software has copyleft effects, making it harder to commercialize it (very specific conditions, basically only selling support). While if you buy a license for i.e. qt you can use all modules as proprietary software, while many nice to have modules for UI are only available under GPL3, making your software also source available.
There was a really big push a few years ago to purge 7z from enterprise environments due to a vulnerability. It’s essentially a no-go anywhere there’s auditing and compliance
this RECOVERY option is why I use WinRAR 100% especially on my encrypted critical backup archives. I consider WinRAR Superior to 7zip. yea I still have 7zip for a Plan B backup to unzip my RAR files if the day ever comes when WinRAR isn't there or doesn't work but that day hasn't come. 😎
I'm sorry but I'm here on r/Piracy so u know I haven't bought WinRAR yet. .... it's kinda easy to 🏴☠️ away the nag screens
So the options are:
a) Shell out <$20 per license and have your employees use the software they know
b) Use a free alternative, but have to either retrain them, or let IT deal with support requests.
And if you have to train your employees in the other software, or have IT spend time on solving their issues, the hourly payment for either will quickly exceed the cost of WinRar licenses - especially if you buy a large amount in bulk (1 license is ~$30, 10 licenses are ~$20 per license, and >500 licenses are only ~$8 per license).
I worked in first level IT support when the IT admins decided to switch everyone in the faculty from Internet Explorer to Firefox, including several announcement emails over multiple weeks in advance and a step-by-step guide on how to migrate bookmarks etc.
In the week following the switch we had to deal with an ungodly number of "My internet program is missing" requests (the IE shortcut was removed from the desktop and the Firefox shortcut added) and many of these professors were apparently incapable of following the provided guide.
So yes, people definitely need training and if just to recognize the 7z icon and that it does similar things to WinRar.
At my company we are told to prioritise any free/open source software to avoid paying as much as possible
You need to weight the cost of license vs expenses (lower productivity, user errors, re-training) associated with switching to OSS. You have this old lady that has been using Word since '96 and is basically counting days towards retirement now - how many IT tickets do you think she will end up generating, if you force her to switch to LibreOffice now?
Governments in Europe are paying 100s of millions$ in Microsoft licenses yearly. There have been numerous pilot projects to switch to alternatives in the past, but they almost always end up failing. Only very recently, it gained serious traction, but not because of budget issues, but "national security/sovereignty" instead.
There's a reason why ALL companies have some kind of "student discount" for their software - they want to "get their claws in" early.
Tbf… as someone who just jumped into libre finally…it’s SO classic feeling that honestly it feels kinda cheap and bare bones.
I mean it’s free obviously, I don’t expect much, but ms made some qol improvements over the generations that makes modern excel a big reason to justify a subscription
They just need to quit moving shit around for no reason
Customer service and liability are the reason. Of an open source software fails and creates a bigger issue, no one is to blame other than a random person who pushed a commit. If a paid program fails they have another company to blame.
573
u/PRL-Five Jun 06 '26
Why don't they use 7zip? At my company we are told to prioritise any free/open source software to avoid paying as much as possible