Live data from Hacker News

Filezilla installer is suspicious again

forum.filezilla-project.org

171–180 of 258 posts

Re: Filezilla installer is suspicious again

#171

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

> Its truly amazing to me that installing windows software is still like this It doesn't have to be that way, since there is a Windows/Microsoft Store since plenty of years now. But then you have gamers and game devs spreading FUD about UWP and the the MS Store, while they praise 3rd party platforms like Steam and GoG that actively refuse UWP apps in their store, while allowing Spyware like this. https://www.reddit.c…

There is also e.g. Chocolatey[0], which IIRC is the closest thing to a GNU/Linux package manager for Windows.

I install and update from Chocolatey whenever possible.

[0] https://chocolatey.org/

Re: Filezilla installer is suspicious again

#172
post #120

Earlier quoted context omitted.

I guess "This installer may include bundled offers." as a warning is not clear enough because it's not written in 72px red-colored bold text? Don't get me wrong, but, in my honest opinion, they make it clear on their own website that it includes bundled offers. I know many other open source projects that offer builds of their software for free, including "bundled offers", without any hint.

Let's try to imagine what his thought processes were. And to do that I would try to put myself in his shoes and imagine what my thought processes would be: "I have this popular software, but I'm not getting rich out of it. What if I put crap adware with it. But that'd be dishonest and I would be helping the scammy/scummy side of the internet (1). Well, if I put a disclaimer on the download page, then it'd be the user…

The worst part is if he put that it's not to be used for commercial use (Windows version or something) and just sell commercial licenses he'd be rich and not have to deal with the crummy income he's getting from malvertisement. Let's be real, corporations will pay good money for convenience. Lots of companies still pay for Visual Studio and MSDN accounts even though they can get .NET Core and Visual Studio Code for free.

Re: Filezilla installer is suspicious again

#173
post #120

Earlier quoted context omitted.

I guess "This installer may include bundled offers." as a warning is not clear enough because it's not written in 72px red-colored bold text? Don't get me wrong, but, in my honest opinion, they make it clear on their own website that it includes bundled offers. I know many other open source projects that offer builds of their software for free, including "bundled offers", without any hint.

And what are these "offers" exactly? Are they applications someone will update actually want to install on their machine if they knew what they were? You can't actually be this obtuse.

I agree with you, and honestly if you were used to FileZilla just working and not having malware on it like I was you wouldnt even think about reading before downloading cause you've downloaded it a million times prior... Now I just don't bother with FileZilla, rather use SCP on a terminal.

Re: Filezilla installer is suspicious again

#174
post #124

Earlier quoted context omitted.

It’s funny to see defense of a program that intentionally included adware in a previous version.

why? do you believe in no second chances?

When it comes to software security, second chances are for accidents.

Re: Filezilla installer is suspicious again

#175
Stop using Windows 10, its a malware not OS. Use real OS like Linux/BSD. Windows 10 is a true horror show, it has way too many backdoors and sends every single keystroke to Microsoft no matter what you disable.

Here is one article; https://www.gnu.org/proprietary/malware-microsoft.en.html

Windows 10 has also been banned by some contries because of this security issues.

[1] https://windowsreport.com/russia-ban-windows/

[2] https://arstechnica.com/tech-policy/2015/08/ban-windows-10-i...

Re: Filezilla installer is suspicious again

#176
post #12

Earlier quoted context omitted.

winscp has also previously bundled crapware (OpenCandy) https://en.wikipedia.org/wiki/WinSCP#Advertisements_in_insta...

Four years ago, with no incidents since.

And the author pinky swears he won't reach into the cookie jar again.

Re: Filezilla installer is suspicious again

#177
post #14
post #2

I can't believe those are real admin responses. TigheW was far more patient than they needed to be, that was painful.

What factual information do you dispute from their responses?

A) The hash/filename comments, that's ridiculous and obviously meant to mislead (yes, the BOTG person tries to walk it back, but it was still bullshit) 2) The lack of actual rebuttal — a tonne of valid points were made about the bundled binary, the dats, the phoning home, the unsigned executables, etc. None of them were addressed. 3) the nonsense about digital signatures

Do you really truly think they did an adequate job responding to the complaints/criticisms/questions? Seriously?

Re: Filezilla installer is suspicious again

#178
post #71

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

Getting off platforms is usually quite hard with most trying to be as sticky as possible. The common reason why people tend to stick to Windows is games, even if the situation has gotten better. Personally I have come to the conclusion that the best solution is virtual machines with a linux base system. Put every game that is sticky to windows into its own little container and just have hardware passed through. That…

The opposite is true for my purposes... I run linux and then use virtualbox to run windows 10 for the only app i'm using windows for, which is QuickBooks. I gave up on closed source software decades ago. With Windows, every six months you have to reinstall your machine because of malware and of course the hour(s) of lost productivity per day compared to linux. Good luck with that.

Re: Filezilla installer is suspicious again

#179
post #20

Earlier quoted context omitted.

I don't support crapware but I'm not going to tell someone how they should make their living. That post looks like rabble rousing to me. I have yet to see any factual information except a whole lot of "it seems" "it appears" "I believe". I'd rather reserve judgement till the facts emerge.

Dude you are all over these comments defending indefensible behavior. What they are doing is wrong. Full Stop. You seriously sound like the admins in the forums.

I'm wagering he has some kind of connection or relationship with the software or developers. There's just no way someone would espouse the views KSK holds without some kind of external factor / ulterior motive.

Re: Filezilla installer is suspicious again

#180
post #58
post #40

Earlier quoted context omitted.

I got tricked into installing adware as part of a java install, and took me many hours to get it back off my system. I don’t get why microsoft isn’t pushing all these vendors really hard to distribute through the windows store. The windows store is a graveyard compared to the mac app store, despite having a head start and a bigger target audience, and it’s basically impossible to use windows without sideloading apps.…

Because nobody really wants to give the AppStore 30% of their revenue. Having it be a percentage of the revenue instead of just a flat fee means its just a money-grab IMHO. Ironically Apple is arguing in court that Qualcomm is doing the same thing to them (charging a percentage based on retail pricing) and that the price is unfair.

lol you're out here arguing that the people who are (without FULLY disclosing it) bundling malware that downloads and compiles DATs/unsigned binaries from anon domains are in the right, but you have a problem with Apple's revenue model for the App Store?
Post reply on HN