Live data from Hacker News

Filezilla installer is suspicious again

forum.filezilla-project.org

111–120 of 258 posts

Re: Filezilla installer is suspicious again

#111
post #17
post #4

Earlier quoted context omitted.

If your software installer bundles crapware for any reason then you've completely lost the plot and nobody should trust your software ever again.

There is pretty much no freeware download site that doesn't bundle crapware. I guess all freeware is untrustworthy by your logic. https://www.howtogeek.com/207692/yes-every-freeware-download...

this guys is trolling, seriously, just stop responding to them.

ksk - many hn readers build using free software for places like google, amazon etc, that are trusted all the way up to places like the CIA. Seriously, please troll somewhere else. Basically no one working in almost any open source project wants to be working with an author that bundles in crapware, ESPECIALLY if the author doesn't actually even control the crapware. If you don't get why this is a bad idea you'll have to trust folks who use open source software regularly that this is a bad thing.

Re: Filezilla installer is suspicious again

#112
post #99

Earlier quoted context omitted.

If what you say is true a more productive approach is to make a derivative of the last known non-malware release of FileZilla with a new name. FileZilla's code respects your software freedom (FileZilla is licensed under the GNU GPL v2, last I knew), so there's no reason not to use that freedom to make a derivative which doesn't come with a tricky installer. Rejecting free software when improvements can be had is an o…

The hard part is search engine ranking.

And that little issue with trademarks: https://filezilla-project.org/trademark_policy.php

Re: Filezilla installer is suspicious again

#113

Earlier quoted context omitted.

> Its truly amazing to me that installing windows software is still like this It doesn't have to be that way, since there is a Windows/Microsoft Store since plenty of years now. But then you have gamers and game devs spreading FUD about UWP and the the MS Store, while they praise 3rd party platforms like Steam and GoG that actively refuse UWP apps in their store, while allowing Spyware like this. https://www.reddit.c…

The long term solution CAN'T be the MS store. It requires asking Microsoft for permission to compete with them. It gives MS permission to bar entire categories of software globally or in your particular market. Giving the party running the store 30% of all revenue is a hard sale to start with. More importantly it gives MS the position to impose whatever dictates it or even more likely every government in existence th…

What is your ideal solution? Which platform should we move to? On Linux I can download Filezilla and it run it untrusted too. So obviously there is no Linux distro that satisfies your requirements because this exact same issue can happen there. Same on Mac. Heck, even Windows is willing to warn you. iOS and the like give Apple similar permissions that you are against, so "the long term solution CAN'T be" the Apple app store.

Re: Filezilla installer is suspicious again

#114
post #3
post #2

I can't believe those are real admin responses. TigheW was far more patient than they needed to be, that was painful.

Outside the filehash thing there isn't anything wrong with his responses. The project chose to get third party products from sources outside their control. There is nothing "technically" wrong with it. The thread is littered with poor security practices, but I see TightW's response as more painful. The admin is already clearly aware of the concern and is stating why it is setup that way. I would much rather see someb…

It's threads like these that remind me, quite clearly, that not everyone shares the same ethics that I do.

Re: Filezilla installer is suspicious again

#115

It's sad that FileZilla remains so popular long after the creator has chosen to monetize it with adware. I highly recommend any FileZilla user reading this should switch to WinSCP. It's free, open source, and not bundled with any crapware.

I posted this further down the thread but may as well say it here too.

Cyberduck[1] was what I moved to after the FileZilla installer on Sourceforge forced me to wipe & reinstall Windows a few years back. It's available for MacOS and Windows, GPL3 licensed[2] and worked great for me at the time. I've since moved to Linux so I haven't been able to play around with any of the newer features/versions but it would be the first thing I tried if I switched back today. Definitely recommend taking a look.

[1]: https://cyberduck.io/

[2]: https://github.com/iterate-ch/cyberduck

Re: Filezilla installer is suspicious again

#116
post #68

Earlier quoted context omitted.

The long term solution is to get off the platform. Never any malware on other platforms? Do you not remember Sourceforge? And let’s not forget that so much Linux software installs these days via curl|sh...

FYI the SourceForge version of FileZilla is clean, and has been since 2016. The official FileZilla installer has been doing this for some time now though. In case people don’t know, a lot has changed at SourceForge since my company acquired them in 2016. All projects are scanned for malware. We covered the improvements again here https://sourceforge.net/blog/brief-history-sourceforge-look-...

That is awesome and I'm glad you are working to clean up the Sourceforge reputation. However, the issue (at least for me) is one of shattered trust. Even though you can affirm the Filezilla downloads you host don't have malicious payloads in the installer, I no longer trust the creator of Filezilla. If he's scummy enough to fill up his "bundled" installer with known malware and viruses, and then lie to his users about it on his forum, he's scummy enough to put something potentially harmful in the program itself.

It would be trivial to integrate a hidden Monero or other coin miner in the source of the main Filezilla program that only runs when the program itself is running. I know I often leave my FTP going overnight for uploading big files (I have really fast downstream but painfully slow upstream) and that's a lot of time for my machine to be surreptitiously mining for someone else. Multiply that by the hundred of thousands if not millions of Filezilla users across all platforms, and you have the potential for a ton of illicitly gained virtual money at your users' expense.

Re: Filezilla installer is suspicious again

#118
This has always been the case. Filezilla offers two versions for Windows and macOS on their website: Bundled and non-bunbled. You get the bundled version when you click "Download FileZilla Client" and then the big green "Download FileZilla Client" button (assuming you're visiting the website from a Windows or macOS client): "This installer may include bundled offers." makes this also very clear. In order to get the clean version, you have to click "Show additional download options" and then pick the version you want. For anyone saying that Filezilla can't be trusted anymore due to doing this, it's still open source and you can check out and build the code yourself: https://filezilla-project.org/sourcecode.php

Re: Filezilla installer is suspicious again

#119
post #20

Earlier quoted context omitted.

Admin of FileZilla, Your reactions to this post deeply concern me. I do believe this is a serious problem you should at least entertain investigating whomever you have an agreement with in regards to bundling their stuff into your installer. Those domains its communicating with have several hits on known malware/RATs reports. For instance, https://www.maltiverse.com/sample/a98b1 ... 38233c50b7. Here is another that s…

I don't support crapware but I'm not going to tell someone how they should make their living. That post looks like rabble rousing to me. I have yet to see any factual information except a whole lot of "it seems" "it appears" "I believe". I'd rather reserve judgement till the facts emerge.

Dude you are all over these comments defending indefensible behavior. What they are doing is wrong. Full Stop. You seriously sound like the admins in the forums.

Re: Filezilla installer is suspicious again

#120
post #22

It is still possible to get non bundled versions of filezilla by clicking "Show additional download options" rather than clicking the big download button. Whether or not to continue to use filezilla or to trust that that software is really clean is another matter.

Let's be honest a lot of people wont suspect the main recommended download to be sketchy until it's too late in some cases.

I guess "This installer may include bundled offers." as a warning is not clear enough because it's not written in 72px red-colored bold text? Don't get me wrong, but, in my honest opinion, they make it clear on their own website that it includes bundled offers. I know many other open source projects that offer builds of their software for free, including "bundled offers", without any hint.
Post reply on HN