Earlier quoted context omitted.
High-profile projects actually can't stop. If you attempt to stop using Sourceforge, they will consider your account "abandoned" and continue mirroring the new site and serving downloads with their malware dropper included. So if you want to keep the malware out of your releases, you need to maintain control of your project by keeping SourceForge up to date. The GIMP project learned this the hard way: http://www.gimp…
"Since the content they host is open-source, this is technically legal, but it's scummy as all hell." If the project is licensed under GPLv3 (or any other strong copyleft license), wouldn't they be illegally hosting it because they are bundling their malware dropper with software that isn't compatible with the license?
Trojan found in Filezilla downloaded from SourceForge
171–180 of 217 posts
Re: Trojan found in Filezilla downloaded from SourceForge
#172Earlier quoted context omitted.
The cool thing about D's forums/feed is how amazingly fast they are. I wish more web apps were designed like this, with a fast backend framework. Instead, it's all either slow, slow backend frameworks like Ruby, or even worse, these SPA applications that require extensive client-side JS processing before they show you the goods. Node is a step in the right direction for both problems: for the first, Node-based backen…
most slowness you are talking about is usually database and/or caching related
Re: Trojan found in Filezilla downloaded from SourceForge
#173Something came up last time Sourceforge was discussed here, namely "why are projects still using it?"... I'm the project lead for LXQt ( http://lxqt.org ). We inherited some infrastructure legacy from LXDE, which was hosted on sourceforge. Today, we have moved most of the legacy to Github but we're still using Sourceforge's mailing list system. We're moving to a self-hosted mailman3 instance but it's been excruciatin…
"So I'm pitching this to bored devs and entrepreneurs: Help us, and many other projects, by creating a "Github for mailing lists" with a web client featuring a clean high quality UI, easily browsable/linkable archives, etc. Make it open source, make it self-hostable, stuff in enterprise support. Make it quick and easy to create new lists." Uggh ... really ? So the simple, clean, extremely fast loading HTML indexes of…
I'm not suggesting the existing software to change, I'm suggesting something new. Pitching something that doesn't exist today (the D-Lang forums linked here come quite close though). Our goal is to merge our current forums with our mailing list and not have to maintain both separately.
So I'll thank you to get off my damn lawn, you and the seven crates of entitlement you carry around.
Re: Trojan found in Filezilla downloaded from SourceForge
#174Re: Trojan found in Filezilla downloaded from SourceForge
#175Earlier quoted context omitted.
If you're managing 5+ projects at once, your inbox must be a train-wreck of garbage from these mailing lists. GitHub has email notifications for issues, but you can opt out of any particular discussion if it gets too pedantic or doesn't relate to you. This helps massively reduce inbox clutter. The thing that bugs me about mailing lists the most is you get all the email, all the time, forever.
>If you're managing 5+ projects at once, your inbox must be a train-wreck of garbage from these mailing lists. This is a total non-issue. Mailing lists support daily digests if you want that, and email clients support folders and filters if you want that instead. Nobody managing 5+ mailing list-based projects at once is dumping all of that into an unsorted inbox.
Because who doesn't like mucking around with their client's filtering?
Re: Trojan found in Filezilla downloaded from SourceForge
#176SourceForge and Filezilla are both on their way out, hence their owners desire to monetize their remaining users while they still can. WinSCP is a decent alternative. As is Swish: http://www.swish-sftp.org/ https://github.com/alamaison/swish
Re: Trojan found in Filezilla downloaded from SourceForge
#177Re: Trojan found in Filezilla downloaded from SourceForge
#178Earlier quoted context omitted.
If you opt-in, they do. Filezilla was one of the first to opt-in. If you say "no, I don’t want you to bundle your installer with my project", they will do so anyway (look at GIMP), and you get nothing.
so yeah, it seems like there's kind of a conflict of interest here. if there's no way for a user to know whether the project opted in to revenue sharing, then how can they trust the project? in other words, in my view, a project that opts in to revenue sharing with crapware bundlers who are known to sometimes distrubute malware, is behaving unethically. so now i don't trust filezilla dev's in general, even if i get a…
If it bundles crapware, and the maintainer listed on sourceforge.net is sourceforge itself, they didn’t opt in.
Otherwise they did.
Re: Trojan found in Filezilla downloaded from SourceForge
#179Tim Kosse has really tarnished the reputation of FileZilla by ignoring the SourceForge malware problem. Chrome and Firefox should add SourceForge to their malicious site list.
a) Certainly if a site is distributing malware/virus/trojans it needs to be flagged as such -- whether it is intentional or not.
b) Sourceforge's policies indicate it they are no longer a trusted source for official files and is probably being ranked far too highly on Google and other search engines.
c) If Dice fails to promptly and adequately address the distribution of malicious files for profit the appropriate government agencies should become involved.