Live data from Hacker News

Filezilla installer is suspicious again

forum.filezilla-project.org

161–170 of 258 posts

Re: Filezilla installer is suspicious again

#161

Earlier quoted context omitted.

> The Linux one is from the same source too. Not in practise. The Linux version of Filezilla will usually be sourced from a package manager: $ apt show filezilla Package: filezilla Version: 3.28.0-1 … Description: Full-featured graphical FTP/FTPS/SFTP client Even Filezilla's own website says "It is highly recommended to use the package management system of your distribution". A huge portion of the software a typical…

Meh, they don't keep versions up to date. That version in the apt repo is several versions behind (not to mention how far behind they are on 16.04 repos), not something you usually want to do with network software like Filezilla. My comment listed just 4 pieces of software off the top of my head I installed on a fresh desktop recently, and I wouldn't get any of them from default apt install.

Repos of major distributions tend to keep security updates current. I can go to the source repo if I want the latest-and-greatest. And running a couple of releases behind is something I quite like to do, because bugs.

Re: Filezilla installer is suspicious again

#162
post #68

Earlier quoted context omitted.

The long term solution is to get off the platform. Never any malware on other platforms? Do you not remember Sourceforge? And let’s not forget that so much Linux software installs these days via curl|sh...

FYI the SourceForge version of FileZilla is clean, and has been since 2016. The official FileZilla installer has been doing this for some time now though. In case people don’t know, a lot has changed at SourceForge since my company acquired them in 2016. All projects are scanned for malware. We covered the improvements again here https://sourceforge.net/blog/brief-history-sourceforge-look-...

Thank you for the rescue of Sourceforge. It still has a lot of goodwill, and the rescue is restoring more.

Re: Filezilla installer is suspicious again

#163
post #157

Earlier quoted context omitted.

https://en.m.wikipedia.org/wiki/Microsoft_SmartScreen And this is considerably better than the “this app was downloaded from the internet do you want to open it” message that OSX provides which Windows provides by default also to all files downloaded from the internet.

The message you mention is not what was meant.

It’s exactly what was meant as you need to do shift+open to install unsigned apps which doesn’t add much if anything.

Re: Filezilla installer is suspicious again

#164

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

>This is challenging because you have to track the reputation of each individual vendor and users have proven unable to even consistently download the software from the right page let alone judge individuals vendors track record.

There was a pattern where articles about nasty android apps would always include some idiotic line about "Security experts say do not install apps you don't trust."

Who the hell knows anything about the apps they even trust, for all you know they sold out to malware companies yesterday.... there's no way to know.

Let alone that would also mean you never try any new software...

I HATE that line.

Re: Filezilla installer is suspicious again

#165
post #129

Earlier quoted context omitted.

> The common reason why people tend to stick to Windows is games For home users perhaps. Enterprise users are often locked into ERP clients, for instance, that are Windows only. But the real killer reason enterprises use Windows is Active Directory. Simple GUI SSO and policy based management. For instance I could have a white-list that didn't have this adware on it and could apply it by group-policy...

Active Directory is just a fancy name for LDAP, Kerberos, and DNS (often in combination with CIFS). There's no reason why you cannot use an equiv in a partly or pure Linux/UNIX environment. And indeed, there are many partly Linux/UNIX environments where the servers are running on Linux/UNIX yet the clients are running on Windows. The killer feature of Windows is that people are used to running it as desktop, meaning…

I've found that FreeIPA tends to be a fantastic replacement: https://www.freeipa.org/

If you're using Red Hat/Fedora GNOME desktops, you can pair that with Fleet Commander to set up desktop policy: https://fleet-commander.org/

At some point soon, I expect it to work for SUSE and Mageia systems, too.

I currently run this on a Fedora Server setup to pair with some Fedora Workstations I manage.

Re: Filezilla installer is suspicious again

#166
post #103

Earlier quoted context omitted.

Similar experience here; Windows Update has been completely broken since shortly after I upgraded from Win7 to Win10. It tries to update -- it downloads several GB of patches, reboots and spends about 20 minutes installing -- then it tells me something along the lines of my system being "incompatible" with Windows (I forget the details, it's been a while) and rolls everything back. Every six months or so I let it try…

Hey, mine too! I actually had that, reformatted, it was fixed for a while, and it's back to doing it again. The worst part is when windows will start ignoring my request to delay updates to the weekend, and will begin restarting my computer during the week whenever I walk away from it for too long.

One of the most frustrating parts of Win10 is the update scheduling. You can request that an update be delayed, but the OS does not always honor the request as specified (settings - update & security - windows update - active hours).

In Win10 Pro, you can postpone an update for max 35 days (windows update - advanced options - pause updates), but never indefinitely. If a pending update will break your machine (and you know because you already had to uninstall it), there's nothing you can do; it will install in five weeks no matter what. It's a timebomb.

Adding insult to injury is that these are primarily "feature" updates, and the features are for Microsoft's benefit. The April 2018 update enabled "Timeline" in the Task View (Win + Tab). All session activity is now shared with Microsoft by default. It must be disabled in Settings - Security & Privacy - Activity Sharing... so I disable all the new less-privacy things I don't want, and there are a lot of them... a week later, they are all switched on again, without notification or consent, after a subsequent Tuesday update.

And this is the reboot I can't postpone, on the OS I purchased. It's part Heller, part Kafka.

Re: Filezilla installer is suspicious again

#167
post #118

This has always been the case. Filezilla offers two versions for Windows and macOS on their website: Bundled and non-bunbled. You get the bundled version when you click "Download FileZilla Client" and then the big green "Download FileZilla Client" button (assuming you're visiting the website from a Windows or macOS client): "This installer may include bundled offers." makes this also very clear. In order to get the c…

>You get the bundled version when you click "Download FileZilla Client" and then the big green "Download FileZilla Client" button (assuming you're visiting the website from a Windows or macOS client)... In order to get the clean version, you have to click "Show additional download options" and then pick the version you want.

Right, nothing shady about this UI pattern at all.

>"This installer may include bundled offers." makes this also very clear.

It makes nothing clear. It's purposely vague language used to disguise the fact that these "bundled offers" consist of software no person would actually chose to install on their machine.

>For anyone saying that Filezilla can't be trusted anymore due to doing this, it's still open source and you can check out and build the code yourself: https://filezilla-project.org/sourcecode.php

What would that accomplish? The issue is that the dev doesn't even know what the hell comes across the wire when you chose to install this crap. How is reading the FileZilla source helpful?

Re: Filezilla installer is suspicious again

#168
post #120

Earlier quoted context omitted.

Let's be honest a lot of people wont suspect the main recommended download to be sketchy until it's too late in some cases.

I guess "This installer may include bundled offers." as a warning is not clear enough because it's not written in 72px red-colored bold text? Don't get me wrong, but, in my honest opinion, they make it clear on their own website that it includes bundled offers. I know many other open source projects that offer builds of their software for free, including "bundled offers", without any hint.

And what are these "offers" exactly? Are they applications someone will update actually want to install on their machine if they knew what they were? You can't actually be this obtuse.

Re: Filezilla installer is suspicious again

#169

FYI the SourceForge version of FileZilla is clean, and has been since 2016. The official FileZilla installer has been doing this for some time now though. In case people don’t know, a lot has changed at SourceForge since my company acquired them in 2016. All projects are scanned for malware. We covered the improvements again here https://sourceforge.net/blog/brief-history-sourceforge-look-...

The fact that a clean installer exists is not really the point, nor should you take it as an opportunity to plug your company.

Re: Filezilla installer is suspicious again

#170

Earlier quoted context omitted.

Microsoft itself is collecting a lot of telemetry even in Basic configuration [1], for example, if you use UAC (privileges elevation popup) they collect "the full command line arguments being used to elevate.". Also they collect a lot of hardware identifiers (including IMEI - unique phone identifier that allows to track it) so later they can reliably prove that some user was using this computer at this time. What a n…

Do you rather trust arbitrary 3rd party Win32 apps, that have free reign to crawl your whole user profile and mess with the integrity of your system? If you're already on Windows 10, at the very least embrace UWP to get some control over your privacy.

> If you're already on Windows 10, at the very least embrace UWP to get some control over your privacy.

This is reasonable. And, at this point it's important to note that the first comment in the chain advocated for moving off the platform.

Post reply on HN