Live data from Hacker News

Filezilla installer is suspicious again

forum.filezilla-project.org

11–20 of 258 posts

Re: Filezilla installer is suspicious again

#11
post #9

Suspicious? Let’s call this what it really is: The FileZilla owners are actively encouraging users to install malware as a way to monetize. That is very clear. Avoid FileZilla by all means.

Yep. This matches behavior I've seen many times before from other software companies.

In every circumstance I immediately ceased using anything made by them.

Re: Filezilla installer is suspicious again

#12

It's sad that FileZilla remains so popular long after the creator has chosen to monetize it with adware. I highly recommend any FileZilla user reading this should switch to WinSCP. It's free, open source, and not bundled with any crapware.

winscp has also previously bundled crapware (OpenCandy)

https://en.wikipedia.org/wiki/WinSCP#Advertisements_in_insta...

Re: Filezilla installer is suspicious again

#13

Well, damn. I didn't even know there were prior incidents. Ugh. I've used Filezilla within the last year. What are good alternatives?

WinSCP is a great open alternative.

https://winscp.net/eng/index.php

https://en.m.wikipedia.org/wiki/WinSCP

Re: Filezilla installer is suspicious again

#15
post #12

It's sad that FileZilla remains so popular long after the creator has chosen to monetize it with adware. I highly recommend any FileZilla user reading this should switch to WinSCP. It's free, open source, and not bundled with any crapware.

winscp has also previously bundled crapware (OpenCandy) https://en.wikipedia.org/wiki/WinSCP#Advertisements_in_insta...

Four years ago, with no incidents since.

Re: Filezilla installer is suspicious again

#16

Well, damn. I didn't even know there were prior incidents. Ugh. I've used Filezilla within the last year. What are good alternatives?

WinSCP is a great open alternative. https://winscp.net/eng/index.php https://en.m.wikipedia.org/wiki/WinSCP

They also have a history of doing this crap:

https://en.wikipedia.org/wiki/WinSCP#Advertisements_in_insta...

Re: Filezilla installer is suspicious again

#17
post #4
post #3

Earlier quoted context omitted.

Outside the filehash thing there isn't anything wrong with his responses. The project chose to get third party products from sources outside their control. There is nothing "technically" wrong with it. The thread is littered with poor security practices, but I see TightW's response as more painful. The admin is already clearly aware of the concern and is stating why it is setup that way. I would much rather see someb…

If your software installer bundles crapware for any reason then you've completely lost the plot and nobody should trust your software ever again.

There is pretty much no freeware download site that doesn't bundle crapware. I guess all freeware is untrustworthy by your logic.

https://www.howtogeek.com/207692/yes-every-freeware-download...

Re: Filezilla installer is suspicious again

#18
Botg site admin "The hash doesn't match because the filename doesn't match."

A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this.

" Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not."

Dangerously ignorant person here what they are actually saying is that they have no way on earth to be sure what's even IN the bundled packages nor what it will do to the users computer.

They have decided that tricking people into downloading malware is a reasonable alternative to charging money for their software or soliciting donations.

Its truly amazing to me that installing windows software is still like this.

The obvious and immediate solution is to abandon vendors who behave like this. This is challenging because you have to track the reputation of each individual vendor and users have proven unable to even consistently download the software from the right page let alone judge individuals vendors track record.

The long term solution is to get off the platform.

Re: Filezilla installer is suspicious again

#19

Well, damn. I didn't even know there were prior incidents. Ugh. I've used Filezilla within the last year. What are good alternatives?

WinSCP seems to be a popular recommendation. When I was a Windows user after the FileZilla/Sourceforge incident I switched to Cyberduck[1]. I really enjoyed it at the time and it seems it's gained many more features since.

[1]https://cyberduck.io/

Re: Filezilla installer is suspicious again

#20
post #4

Earlier quoted context omitted.

If your software installer bundles crapware for any reason then you've completely lost the plot and nobody should trust your software ever again.

Admin of FileZilla, Your reactions to this post deeply concern me. I do believe this is a serious problem you should at least entertain investigating whomever you have an agreement with in regards to bundling their stuff into your installer. Those domains its communicating with have several hits on known malware/RATs reports. For instance, https://www.maltiverse.com/sample/a98b1 ... 38233c50b7. Here is another that s…

I don't support crapware but I'm not going to tell someone how they should make their living. That post looks like rabble rousing to me. I have yet to see any factual information except a whole lot of "it seems" "it appears" "I believe". I'd rather reserve judgement till the facts emerge.
Post reply on HN