Live data from Hacker News

Filezilla installer is suspicious again

forum.filezilla-project.org

71–80 of 258 posts

Re: Filezilla installer is suspicious again

#71

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

Getting off platforms is usually quite hard with most trying to be as sticky as possible. The common reason why people tend to stick to Windows is games, even if the situation has gotten better.

Personally I have come to the conclusion that the best solution is virtual machines with a linux base system. Put every game that is sticky to windows into its own little container and just have hardware passed through. That way every form of sticky platform only exist in a small pocket of virtual space. The tricky part is getting all this working as smoothly as if it was just one system that just happen to have really good sandboxing for untrustworthy platforms.

Re: Filezilla installer is suspicious again

#72
post #21

Any impact on the Linux versions of filezilla?

I don't see why, being on Linux, you would prefer to use FileZilla to transfer files to a remote machine over an insecure protocol when there are plenty of alternatives with better security. Rsync, for example, allows you to specify an SSH key. Or SCP, which also offers the same functionality.

Not sure why you are modded down for that comment.

It is also ridiculous that people on other platforms do not have a bullet proof file transfer tool baked into the operating system. Even VAX/VMS had better built in file transfer tools than what Windows has today.

Re: Filezilla installer is suspicious again

#73

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

> Its truly amazing to me that installing windows software is still like this

It doesn't have to be that way, since there is a Windows/Microsoft Store since plenty of years now.

But then you have gamers and game devs spreading FUD about UWP and the the MS Store, while they praise 3rd party platforms like Steam and GoG that actively refuse UWP apps in their store, while allowing Spyware like this.

https://www.reddit.com/r/Steam/comments/8pud8b/psa_red_shell...

Yet, nobody dares to hold those platforms responsible.

https://www.reddit.com/r/Games/comments/8sg294/16_studios_re...

> The long term solution is to get off the platform.

No, the long term solution is to embrace the MS Store, or at the very least modern platforms like WinRT/UWP that would prevent most types of malware attacks.

Why do we still accept the violation of the principle of least privilege in this day and age?

Re: Filezilla installer is suspicious again

#74
post #43

Earlier quoted context omitted.

This is a really toxic attitude in the open source community where when asked a question the answer is: "you're doing it wrong, just do it right". If I had a choice I would, but unless you have a few million dollars to give us to refactor 30 years of technical debt, please answer the question.

> you're doing it wrong, just do it right That's not how I wrote my comment above, I gave you alternatives. > If I had a choice I would You have choices, many. > unless you have a few million dollars to give us to refactor 30 years of technical debt How is using FileZilla a technical debt? What are you requiring from FileZilla that you need a few million of dollars to refactor code? What kind of code depends on an ex…

FileZilla is a program that supports multiple file transfer protocols (ftp and sftp), sftp, allows you to transfer files over the ssh protocol. https://en.wikipedia.org/wiki/SSH_File_Transfer_Protocol

Re: Filezilla installer is suspicious again

#75
post #71

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

Getting off platforms is usually quite hard with most trying to be as sticky as possible. The common reason why people tend to stick to Windows is games, even if the situation has gotten better. Personally I have come to the conclusion that the best solution is virtual machines with a linux base system. Put every game that is sticky to windows into its own little container and just have hardware passed through. That…

> The common reason why people tend to stick to Windows is games

For home users perhaps. Enterprise users are often locked into ERP clients, for instance, that are Windows only.

But the real killer reason enterprises use Windows is Active Directory. Simple GUI SSO and policy based management. For instance I could have a white-list that didn't have this adware on it and could apply it by group-policy...

Re: Filezilla installer is suspicious again

#76
post #58
post #40

Earlier quoted context omitted.

I got tricked into installing adware as part of a java install, and took me many hours to get it back off my system. I don’t get why microsoft isn’t pushing all these vendors really hard to distribute through the windows store. The windows store is a graveyard compared to the mac app store, despite having a head start and a bigger target audience, and it’s basically impossible to use windows without sideloading apps.…

Because nobody really wants to give the AppStore 30% of their revenue. Having it be a percentage of the revenue instead of just a flat fee means its just a money-grab IMHO. Ironically Apple is arguing in court that Qualcomm is doing the same thing to them (charging a percentage based on retail pricing) and that the price is unfair.

Very soon it won't be 30% anymore.

https://blogs.windows.com/buildingapps/2018/05/07/a-new-micr...

Re: Filezilla installer is suspicious again

#77
post #68

Earlier quoted context omitted.

The long term solution is to get off the platform. Never any malware on other platforms? Do you not remember Sourceforge? And let’s not forget that so much Linux software installs these days via curl|sh...

That's why I use my distro's package manager and review external scripts before running them.

Same here. PyPI and NPM are the Wild West too. Github makes no effort to combat typosquatting either.

People in glasshouses shouldn’t throw stones...

Re: Filezilla installer is suspicious again

#78

FYI the SourceForge version of FileZilla is clean, and has been since 2016. The official FileZilla installer has been doing this for some time now though. In case people don’t know, a lot has changed at SourceForge since my company acquired them in 2016. All projects are scanned for malware. We covered the improvements again here https://sourceforge.net/blog/brief-history-sourceforge-look-...

Yet this happened with your company at the helm: https://medium.com/@jonykatz/sourceforge-hiding-fact-that-th...

This blog post is not accurate at all.

Re: Filezilla installer is suspicious again

#79
I don't know whether it is really malware, or they just collect information from PC like browser history and cookies or just avoid being blocked by AV, anyway the real purpose is that developers don't want users to be able to control what is happening on their PC and to know what is really happening. I don't see any other explanation.

Re: Filezilla installer is suspicious again

#80
post #67
post #64

Earlier quoted context omitted.

What doesn't make sense? FileZilla is a bad actor who is trying to infect people's computers with malware. Download sites are bad actors who are trying to infect people's computers with malware. People should have all the information they need to avoid malware, so they can make good decisions, such as installing WinSCP from Ninite instead of installing FileZilla by any method. You keep denying that trustworthy free s…

>Such as installing WinSCP from Ninite instead of installing FileZilla by any method. https://en.wikipedia.org/wiki/WinSCP#Advertisements_in_insta... >You keep denying that trustworthy free software exists, and yet when anyone points out that it does, you change the topic. People who cheat on tests believe everyone is cheating on tests. You are unable to understand how "trustworthy free software" vendors make money.…

It would have been a bad idea to use WinSCP in 2014 also. Yet you'll notice they backed off and have had years to repair their reputation, instead of getting caught a second time and trying to cover it up like FileZilla is doing.

I understand how your kind of free software makes money perfectly well. It's not trustworthy in the slightest.

You don't need to make money to make a program that copies files. And if you bundle your free software with a scam, you're not making money as a software developer anyway, you're making money as a scammer.

Post reply on HN