Live data from Hacker News

Trojan found in Filezilla downloaded from SourceForge

forum.filezilla-project.org

211–217 of 217 posts

Re: Trojan found in Filezilla downloaded from SourceForge

#212

Earlier quoted context omitted.

I agree. Mailman is fantastic as it is. There's a technical brevity and image it gives off, and that's an important aspect of design. This isn't really a statement about usability or what's beautiful in design. I design user interfaces and creating a new UI for basically what mailman does would really just be an attempt at grabbing a different target audience. mailman has an image behind it. People associate with dif…

Have you considered contacting Guiness World Records regarding the size of that horse you stand atop of? If you genuinely do want to practice great design, start by considering user needs and the reason why "reskinning" as you call it might be wanted, instead of dismissing anything you don't immediately understand as "pah, must be junior designers, those with fancy gradients and far less experience than me". No, seri…

Personal attacks are not allowed on HN, even when someone seems arrogant. Please post civilly and substantively, or not at all.

Re: Trojan found in Filezilla downloaded from SourceForge

#213

Earlier quoted context omitted.

Have you considered contacting Guiness World Records regarding the size of that horse you stand atop of? If you genuinely do want to practice great design, start by considering user needs and the reason why "reskinning" as you call it might be wanted, instead of dismissing anything you don't immediately understand as "pah, must be junior designers, those with fancy gradients and far less experience than me". No, seri…

Arrogance is telling someone they don't understand something, when they tell you "no." > "User needs" Do you actually design anything?

You're not telling me no, most specifically because I'm not pitching this to you. You're telling yourself no. You say you don't need it, and extrapolate your view of the world to everybody else's.

Really dangerous.

Re: Trojan found in Filezilla downloaded from SourceForge

#214

Earlier quoted context omitted.

Hmm. Yeah. I’ve thought about it for the last few hours, and decided that the best solution is to just use RSA in client.

How would that work? If you would use a private key to authenticate to the server you would still need to protect this key with a password. Otherwise stealing the private key will get an attacker access to the server just as simple.

Well, you’d be 100% safe of MitM.

And you could use a hardware key auth.

Like the German eID, where the key is signed by the government and on a special chipcard.

The software requests the card to sign, you need to type in your PIN on the reader itself, and the request will be signed with RSA.

The public key is world-readable on the card, so you can just send that to the server.

Re: Trojan found in Filezilla downloaded from SourceForge

#216
post #208

Earlier quoted context omitted.

Yeah I still can't believe how scummy sourceforge is. I wonder how new oss projects can protect themselves against this type of behavior. Anyone know if any oss licenses include a restriction against this kind of repackaging or any kind of malicious use clause?

That would be contradiction of terms. Anything with such restrictions is, by definition (look it up!), not Open Source.

Sure if you want to be pedantic about it...

In reality though there's a reason there are many different OSS licenses - many devs want options around attribution and yes, around use in limited ways. A please don't use this for abject evil clause may not meet the no true open source dictionary definition, but pragmatically speaking it's not necessarily a terrible idea.

Re: Trojan found in Filezilla downloaded from SourceForge

#217

Unfortunately Filezilla has this trojan for some years now! The trojan send all your identities to a server. This is tested 100%. We had many passwords stolen this way and we are 100% sure that it's filezilla. Just take this test: Try to download the Filezilla and when the download page shows click on the Direct Link. Then compare the two executables, one that downloaded automatically and the one that it downloaded v…

That's a pretty serious claim. Do you actually have evidence to prove it was FZ? Just because the SF executable includes spyware doesn't mean it's disclosing passwords.

You are kidding right? And what do you think that spyware does? They steal passwords! Our DC warns us of stolen passwords every time a client is using this exactly "touched" version of FZ. The DC is informed by a security firm and 100% of the situations is the Filezilla that steals them!
Post reply on HN