Live data from Hacker News

Filezilla installer is suspicious again

forum.filezilla-project.org

21–30 of 258 posts

Re: Filezilla installer is suspicious again

#22
It is still possible to get non bundled versions of filezilla by clicking "Show additional download options" rather than clicking the big download button. Whether or not to continue to use filezilla or to trust that that software is really clean is another matter.

Re: Filezilla installer is suspicious again

#25
post #20

Earlier quoted context omitted.

Admin of FileZilla, Your reactions to this post deeply concern me. I do believe this is a serious problem you should at least entertain investigating whomever you have an agreement with in regards to bundling their stuff into your installer. Those domains its communicating with have several hits on known malware/RATs reports. For instance, https://www.maltiverse.com/sample/a98b1 ... 38233c50b7. Here is another that s…

I don't support crapware but I'm not going to tell someone how they should make their living. That post looks like rabble rousing to me. I have yet to see any factual information except a whole lot of "it seems" "it appears" "I believe". I'd rather reserve judgement till the facts emerge.

If it were the first instance of this with Filezilla, and the admin response wasn't dismissive, I'd agree with you.

They earned their reputation as untrustworthy.

Re: Filezilla installer is suspicious again

#26

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

Vendors who have partaken in the "bundled crapware" model of distribution - Google, Amazon, Yahoo, Microsoft, Adobe, Oracle, etc, etc.

>They have decided that tricking people into downloading malware is a reasonable alternative to charging money for their software or soliciting donations.

If you would be so kind enough as to show them how to make money perhaps they'll stop doing it.

>Its truly amazing to me that installing windows software is still like this.

Eh? Which OS platform are you using that does not allow a user to execute binaries?

Re: Filezilla installer is suspicious again

#27
post #17
post #4

Earlier quoted context omitted.

If your software installer bundles crapware for any reason then you've completely lost the plot and nobody should trust your software ever again.

There is pretty much no freeware download site that doesn't bundle crapware. I guess all freeware is untrustworthy by your logic. https://www.howtogeek.com/207692/yes-every-freeware-download...

Oh my god. You're talking to competent computer users on Hacker News, not people who use crapware download sites and need to be warned away from them by "HowToGeek".

Of course there is trustworthy freeware. You can get it using Apt, Yum, Ninite, Chocolatey, Homebrew, or just by going to the actual site of a trustworthy software product.

The fact that the people who run most download sites are scum isn't a problem with the software. It's a problem with those sites.

Re: Filezilla installer is suspicious again

#28
post #17
post #4

Earlier quoted context omitted.

If your software installer bundles crapware for any reason then you've completely lost the plot and nobody should trust your software ever again.

There is pretty much no freeware download site that doesn't bundle crapware. I guess all freeware is untrustworthy by your logic. https://www.howtogeek.com/207692/yes-every-freeware-download...

Yes, that would logically follow.

Re: Filezilla installer is suspicious again

#29
FYI the SourceForge version of FileZilla is clean, and has been since 2016. The official FileZilla installer has been doing this for some time now though. In case people don’t know, a lot has changed at SourceForge since my company acquired them in 2016. All projects are scanned for malware. We covered the improvements again here https://sourceforge.net/blog/brief-history-sourceforge-look-...

Re: Filezilla installer is suspicious again

#30
post #27
post #17

Earlier quoted context omitted.

There is pretty much no freeware download site that doesn't bundle crapware. I guess all freeware is untrustworthy by your logic. https://www.howtogeek.com/207692/yes-every-freeware-download...

Oh my god. You're talking to competent computer users on Hacker News, not people who use crapware download sites and need to be warned away from them by "HowToGeek". Of course there is trustworthy freeware. You can get it using Apt, Yum, Ninite, Chocolatey, Homebrew, or just by going to the actual site of a trustworthy software product. The fact that the people who run most download sites are scum isn't a problem wit…

Um, the download section on the vendors website contains the text "This installer may include bundled offers. Check below for more options."

https://imgur.com/a/Xrc1jMy

You can download FileZilla without the bundled "offers". If the average hacker news reader is capable of doing that, then whats left is just a criticism of ALL bundled installers, in which case, pick a number and join the queue.

Post reply on HN