Live data from Hacker News

Filezilla installer is suspicious again

forum.filezilla-project.org

151–160 of 258 posts

Re: Filezilla installer is suspicious again

#151

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

Well, botg does come pretty close to admitting that:

    #9 Post by botg » 2018-01-05 09:11
    The connections are for fetching offers and, if the user
    accepts the offer, the offered file. What the file is
    for is written in the offer text. The network requests
    to fetch offers are done only after the user has agreed
    to it by accepting the privacy policy.
Right, the user has agreed to install some random thing.

    #10 Post by TigheW » 2018-01-05 16:55
    Sorry man, this isn't "bundled software that people
    want" and no amount of repeating it will make it true.
    This is a malware downloader bundled with your software
    and hosted on your page and you're intentionally
    misleading the users who are here directly asking you
    if it's safe to run this bundle on their machines. ...
Damn.

Re: Filezilla installer is suspicious again

#153

Earlier quoted context omitted.

> The Linux one is from the same source too. Not in practise. The Linux version of Filezilla will usually be sourced from a package manager: $ apt show filezilla Package: filezilla Version: 3.28.0-1 … Description: Full-featured graphical FTP/FTPS/SFTP client Even Filezilla's own website says "It is highly recommended to use the package management system of your distribution". A huge portion of the software a typical…

Meh, they don't keep versions up to date. That version in the apt repo is several versions behind (not to mention how far behind they are on 16.04 repos), not something you usually want to do with network software like Filezilla. My comment listed just 4 pieces of software off the top of my head I installed on a fresh desktop recently, and I wouldn't get any of them from default apt install.

Honorable providers, for example the Tor and MPTCP projects, run their own repositories, with GnuPG-authenticated packages. You get up-to-date builds, with no crap.

Re: Filezilla installer is suspicious again

#154

Earlier quoted context omitted.

> The long term solution is to get off the platform. Ug. Running untrusted executables on any platform can be trouble. The problem is that by blaming the platform, people keep putting the onus on these OS's, distros, etc to build walls around carefully curated gardens. Gotta take the good with the bad. Either you accept that people can run untrusted executables or you give up the flexibility to build/use/distribute u…

macOS has a good solution to this, where attempting to open an unsigned binary will fail and warn the user, but can be overridden in the file's context menu.

https://en.m.wikipedia.org/wiki/Microsoft_SmartScreen

And this is considerably better than the “this app was downloaded from the internet do you want to open it” message that OSX provides which Windows provides by default also to all files downloaded from the internet.

Re: Filezilla installer is suspicious again

#155
post #39

Sophisticated users will know to download the unbundled installer, and maybe even go so far as to verify the hash. But that sideskirts the question of whether to continue using software where the authors are willing to put their users at risk by monetizing with what is apparently malware bundles. FileZilla is by all accounts a fantastic piece of software. I’ve used it for years, both the client and the server, and it…

I don't really see the problem. If the developers want to get paid for they work they can just sell their software. The problem is when someone tries to monetize their product by deceiving users. This is the case: they prevent user from knowing what is happening on their computer, download and run suspicious binaries and use EULA as an excuse. And I suspect, they themselves don't even know for sure what is bundled in…

Imagine if Google charged $5 per month for a subscription to their search engine. We're kind of seeing this with Youtube Red.......

Re: Filezilla installer is suspicious again

#156
post #93
post #80

Earlier quoted context omitted.

It would have been a bad idea to use WinSCP in 2014 also. Yet you'll notice they backed off and have had years to repair their reputation, instead of getting caught a second time and trying to cover it up like FileZilla is doing. I understand how your kind of free software makes money perfectly well. It's not trustworthy in the slightest. You don't need to make money to make a program that copies files. And if you bu…

You seem very confused. FileZilla wasn't "caught". They openly say that they bundle crapware. Sorry, this is not a productive conversation. Goodbye.

You've crossed into incivility in this thread. That's not allowed on HN, regardless of how wrong someone else (or everyone else) may be. If you could please (re-)read https://news.ycombinator.com/newsguidelines.html and not do it again, we'd appreciate that.

Re: Filezilla installer is suspicious again

#157

Earlier quoted context omitted.

macOS has a good solution to this, where attempting to open an unsigned binary will fail and warn the user, but can be overridden in the file's context menu.

https://en.m.wikipedia.org/wiki/Microsoft_SmartScreen And this is considerably better than the “this app was downloaded from the internet do you want to open it” message that OSX provides which Windows provides by default also to all files downloaded from the internet.

The message you mention is not what was meant.

Re: Filezilla installer is suspicious again

#158

Earlier quoted context omitted.

Four years ago, with no incidents since.

It’s funny to see defense of a program that intentionally included adware in a previous version.

I’m defending the four years of good behavior, not the bad behavior back then. People and companies make mistakes and bad decisions, and I don’t mind supporting them if they prove over time that they’ve changed. Four years of good behavior is long enough for me. If your response to a company doing something you don’t like is an eternal blacklist, even years after they respond to their customers and change their behavior, think about what you’re really encouraging. For one thing, never admitting anything, for another, coverups.

Re: Filezilla installer is suspicious again

#159
When I read "You get AV flags for business reasons on the AV vendor's behalf, not because of malware." I pretty much became convinced they have gone to the dark side. I've seen enough shady business that this pattern really jumps out - as soon as people start claiming everybody is conspiring against them for monetary reasons, or out of envy, etc. with no proof - it is a very strong sign that the person is not to be trusted. There are false positives but the sign is very strong.

Re: Filezilla installer is suspicious again

#160
post #9

Suspicious? Let’s call this what it really is: The FileZilla owners are actively encouraging users to install malware as a way to monetize. That is very clear. Avoid FileZilla by all means.

If what you say is true a more productive approach is to make a derivative of the last known non-malware release of FileZilla with a new name. FileZilla's code respects your software freedom (FileZilla is licensed under the GNU GPL v2, last I knew), so there's no reason not to use that freedom to make a derivative which doesn't come with a tricky installer. Rejecting free software when improvements can be had is an o…

the statement you're replying to was probably intended for users (ie the people who use ftp in some capacity all the time). they should absolutely stop using filezilla. sure, in the general sense there's no reason the project couldn't be productively forked, but the immediate concern is the fact that FZ presents itself as a modern open source client when in fact its stuck in 1998 and bundles f*ing popups
Post reply on HN