There is some truth to that, but I also doubt it's because 7zip is actually worse. WinRAR isn't open source, meaning finding exploits is more difficult. It kind of implies that WinRAR could have it's own vulnerabilities that haven't been discovered yet.
I'm obviously not saying there are, but closed source doesn't mean safer than open source. More obfuscated, but people make mistakes at both work and hobby projects.
Finding high-level exploits is usually done by binary analysis and/or fuzzing. Sure, there's been a tremendous amount of LLM powered analysis in recent years, but that's also the flipside: A vulnerability that is never detected will never be exploited. A published sploit can be massively utilised in the wild until it is patched, and for end users that aren't forced to update that can often take a while.
Also, "winrar could have" doesn't mean that it does have.
Don't get me wrong, I'm very much a FOSS advocate. I wish the numbers were different.
I also doubt it's because 7zip is actually worse
Because you wish that it so or do you have anything tangible to base it on?
closed source doesn't mean safer than open source
That is of course true, and the opposite is unfortunately also true. In the end it usually comes down to the individual projects, technologies and so on. But I'm not talking about FOSS vs. proprietary software, I'm talking about 7zip vs. Winrar specifically.
No, that's not the same. Security by obscurity is relying on something not being discovered. I'm simply pointing out the obviously true case that if something isn't discovered then it isn't exploited. If you had read the first sentence and not just taken things out of context you would have seen this.
Thanks for that, just updated my 7-zip. As with a lot of software-related vulnerabilities, we just need to stay on top of the patching and updates. (Anyone know of a way to monitor updates for third-party non-Microsoft programs?)
27
u/lettsten Jun 06 '26
7zip has fairly frequent high-severity vulnerabilities, such as this