Live data from Hacker News

Filezilla installer is suspicious again

forum.filezilla-project.org

1–10 of 258 posts

Re: Filezilla installer is suspicious again

#3
post #2

I can't believe those are real admin responses. TigheW was far more patient than they needed to be, that was painful.

Outside the filehash thing there isn't anything wrong with his responses. The project chose to get third party products from sources outside their control. There is nothing "technically" wrong with it. The thread is littered with poor security practices, but I see TightW's response as more painful. The admin is already clearly aware of the concern and is stating why it is setup that way. I would much rather see somebody state the practices are wrong rather than just calling this guy out since it is really counter-productive.

Re: Filezilla installer is suspicious again

#4
post #3
post #2

I can't believe those are real admin responses. TigheW was far more patient than they needed to be, that was painful.

Outside the filehash thing there isn't anything wrong with his responses. The project chose to get third party products from sources outside their control. There is nothing "technically" wrong with it. The thread is littered with poor security practices, but I see TightW's response as more painful. The admin is already clearly aware of the concern and is stating why it is setup that way. I would much rather see someb…

If your software installer bundles crapware for any reason then you've completely lost the plot and nobody should trust your software ever again.

Re: Filezilla installer is suspicious again

#5
post #4
post #3

Earlier quoted context omitted.

Outside the filehash thing there isn't anything wrong with his responses. The project chose to get third party products from sources outside their control. There is nothing "technically" wrong with it. The thread is littered with poor security practices, but I see TightW's response as more painful. The admin is already clearly aware of the concern and is stating why it is setup that way. I would much rather see someb…

If your software installer bundles crapware for any reason then you've completely lost the plot and nobody should trust your software ever again.

Personally, I abandoned FileZilla after the prior incidents and would never consider installing it again.

Re: Filezilla installer is suspicious again

#6
post #4
post #3

Earlier quoted context omitted.

Outside the filehash thing there isn't anything wrong with his responses. The project chose to get third party products from sources outside their control. There is nothing "technically" wrong with it. The thread is littered with poor security practices, but I see TightW's response as more painful. The admin is already clearly aware of the concern and is stating why it is setup that way. I would much rather see someb…

If your software installer bundles crapware for any reason then you've completely lost the plot and nobody should trust your software ever again.

Admin of FileZilla,

Your reactions to this post deeply concern me. I do believe this is a serious problem you should at least entertain investigating whomever you have an agreement with in regards to bundling their stuff into your installer.

Those domains its communicating with have several hits on known malware/RATs reports. For instance, https://www.maltiverse.com/sample/a98b1 ... 38233c50b7.

Here is another that spawns the same type of .exe which turns out to be NJRAT malware -> https://www.hybrid-analysis.com/sample/ ... mentId=120

Your defensive attitude is what alarms me the most. Almost as if you might care more about your bundle agreement profits than your users security/safety.

Hole in one. I wouldn’t trust those admins to make me a cup of tea, and I agree that their attitude reeks of deception for selfish reasons. Nobody should ever trust their software again, full stop.

Post reply on HN