Are we still using FTP?
Trojan found in Filezilla downloaded from SourceForge
211–217 of 217 posts
Re: Trojan found in Filezilla downloaded from SourceForge
#212Earlier quoted context omitted.
I agree. Mailman is fantastic as it is. There's a technical brevity and image it gives off, and that's an important aspect of design. This isn't really a statement about usability or what's beautiful in design. I design user interfaces and creating a new UI for basically what mailman does would really just be an attempt at grabbing a different target audience. mailman has an image behind it. People associate with dif…
Have you considered contacting Guiness World Records regarding the size of that horse you stand atop of? If you genuinely do want to practice great design, start by considering user needs and the reason why "reskinning" as you call it might be wanted, instead of dismissing anything you don't immediately understand as "pah, must be junior designers, those with fancy gradients and far less experience than me". No, seri…
Re: Trojan found in Filezilla downloaded from SourceForge
#213Earlier quoted context omitted.
Have you considered contacting Guiness World Records regarding the size of that horse you stand atop of? If you genuinely do want to practice great design, start by considering user needs and the reason why "reskinning" as you call it might be wanted, instead of dismissing anything you don't immediately understand as "pah, must be junior designers, those with fancy gradients and far less experience than me". No, seri…
Arrogance is telling someone they don't understand something, when they tell you "no." > "User needs" Do you actually design anything?
Really dangerous.
Re: Trojan found in Filezilla downloaded from SourceForge
#214Earlier quoted context omitted.
Hmm. Yeah. I’ve thought about it for the last few hours, and decided that the best solution is to just use RSA in client.
How would that work? If you would use a private key to authenticate to the server you would still need to protect this key with a password. Otherwise stealing the private key will get an attacker access to the server just as simple.
And you could use a hardware key auth.
Like the German eID, where the key is signed by the government and on a special chipcard.
The software requests the card to sign, you need to type in your PIN on the reader itself, and the request will be signed with RSA.
The public key is world-readable on the card, so you can just send that to the server.
Re: Trojan found in Filezilla downloaded from SourceForge
#215Re: Trojan found in Filezilla downloaded from SourceForge
#216Earlier quoted context omitted.
Yeah I still can't believe how scummy sourceforge is. I wonder how new oss projects can protect themselves against this type of behavior. Anyone know if any oss licenses include a restriction against this kind of repackaging or any kind of malicious use clause?
That would be contradiction of terms. Anything with such restrictions is, by definition (look it up!), not Open Source.
In reality though there's a reason there are many different OSS licenses - many devs want options around attribution and yes, around use in limited ways. A please don't use this for abject evil clause may not meet the no true open source dictionary definition, but pragmatically speaking it's not necessarily a terrible idea.
Re: Trojan found in Filezilla downloaded from SourceForge
#217Unfortunately Filezilla has this trojan for some years now! The trojan send all your identities to a server. This is tested 100%. We had many passwords stolen this way and we are 100% sure that it's filezilla. Just take this test: Try to download the Filezilla and when the download page shows click on the Direct Link. Then compare the two executables, one that downloaded automatically and the one that it downloaded v…
That's a pretty serious claim. Do you actually have evidence to prove it was FZ? Just because the SF executable includes spyware doesn't mean it's disclosing passwords.