Live data from Hacker News

Filezilla installer is suspicious again

forum.filezilla-project.org

101–110 of 258 posts

Re: Filezilla installer is suspicious again

#101

Earlier quoted context omitted.

> Giving the party running the store 30% of all revenue is a hard sale to start with. Very soon it won't be 30% anymore. https://blogs.windows.com/buildingapps/2018/05/07/a-new-micr... > Linux package management works like an app store with an official source and the ability to add whichever sources you choose. A search of available packages shows results giving sources the priority set by the user. Updating the syst…

"There exist 3rd party package repositories on Windows too." The MS store does NOT have user configurable repos for consumer versions of windows.

You don't need the MS Store for 3rd party repositories.

Re: Filezilla installer is suspicious again

#102

Can't we just fork and fix?

I'd honestly like to just see new alternatives altogether, crazy there's like no other GUI alternatives that are open source and comparable.

Cyberduck? https://cyberduck.io/

Seems like a good alternative with a modern UI.

Re: Filezilla installer is suspicious again

#103

Earlier quoted context omitted.

Its truly amazing to me that installing windows software is still like this. You think this is bad, you should try the Windows 10 auto updater. Disclaimer: It's broken on my brand new PC and no helpful on-line fix has worked so far. So I might hold hate in my heart.

Similar experience here; Windows Update has been completely broken since shortly after I upgraded from Win7 to Win10. It tries to update -- it downloads several GB of patches, reboots and spends about 20 minutes installing -- then it tells me something along the lines of my system being "incompatible" with Windows (I forget the details, it's been a while) and rolls everything back. Every six months or so I let it try…

Hey, mine too! I actually had that, reformatted, it was fixed for a while, and it's back to doing it again.

The worst part is when windows will start ignoring my request to delay updates to the weekend, and will begin restarting my computer during the week whenever I walk away from it for too long.

Re: Filezilla installer is suspicious again

#104
post #90
post #84

Earlier quoted context omitted.

The post which you've replied to raised a question which you've chosen not to answer. Are you at all connected to the FileZilla project?

I choose to ignore irrelevant questions to avoid derailing the conversation.

Even way down here where the core of the conversation isn't happening? How would a "no" derail it?

Re: Filezilla installer is suspicious again

#105

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

>they don't have a checksum for the bundled package but botg doesn't want to say this

Well, it shouldn't really be called "bundled". It's more a "drive-by download". What is bundled is only a downloader (so the checksum remains the same). And it offers and downloads what the other party sees more profitable today.

In this sense they really don't know what they bundle.

Re: Filezilla installer is suspicious again

#106

Earlier quoted context omitted.

Yet this happened with your company at the helm: https://medium.com/@jonykatz/sourceforge-hiding-fact-that-th...

This blog post is not accurate at all.

So what's your side of the story, then?

Re: Filezilla installer is suspicious again

#107
post #103

Earlier quoted context omitted.

Similar experience here; Windows Update has been completely broken since shortly after I upgraded from Win7 to Win10. It tries to update -- it downloads several GB of patches, reboots and spends about 20 minutes installing -- then it tells me something along the lines of my system being "incompatible" with Windows (I forget the details, it's been a while) and rolls everything back. Every six months or so I let it try…

Hey, mine too! I actually had that, reformatted, it was fixed for a while, and it's back to doing it again. The worst part is when windows will start ignoring my request to delay updates to the weekend, and will begin restarting my computer during the week whenever I walk away from it for too long.

Flash backs to the Win XP restart dialog that popped up every 20 minutes until you couldn't take it anymore.

Re: Filezilla installer is suspicious again

#108

Earlier quoted context omitted.

"There exist 3rd party package repositories on Windows too." The MS store does NOT have user configurable repos for consumer versions of windows.

You don't need the MS Store for 3rd party repositories.

You: "No, the long term solution is to embrace the MS Store"

Me: No solution which gives a single party absolute control over what software a user is allowed to run is a long term solution.

Re: Filezilla installer is suspicious again

#109
Since I haven't seen it mentioned here, note that the first post in this thread was on 13 December 2017, with most of the back and forth between botg and TigheW taking place in early January 2018.

Post #14 revived the thread 11 days ago and the last seven or eight posts are from the last 24 hours or so.

Looks like the thread has since been "locked" to prevent further discussion.

Re: Filezilla installer is suspicious again

#110

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

> The long term solution is to get off the platform.

Ug. Running untrusted executables on any platform can be trouble. The problem is that by blaming the platform, people keep putting the onus on these OS's, distros, etc to build walls around carefully curated gardens. Gotta take the good with the bad. Either you accept that people can run untrusted executables or you give up the flexibility to build/use/distribute untrusted executables yourself. Sadly it seems as devs grow into larger companies and prefer the latter, they forget their indie beginnings enabled by the former. "What's $100?" they say. "Getting a cert is easy" they say. "If you aren't building anything dangerous, why do you have a problem with curation?" they say. The same anti-freedom arguments are always there in the name of safety.

If you downloaded untrusted Filezilla and executed it raw on any platform it could be an issue. If users required Filezilla to be distributed in the Windows app store, it could be less of an issue. One could argue the fact that installing Windows software is sometimes still like this is because of the lack of restrictions against it. But as users keep complaining and devs stay silent, all platforms including Windows will continue to reduce liberty in the name of safety and you'll feel better.

Post reply on HN