Live data from Hacker News

Filezilla installer is suspicious again

forum.filezilla-project.org

211–220 of 258 posts

Re: Filezilla installer is suspicious again

#211
Just for information it seem that only the installer from their website first download page[0] is bundled (it has "bundled" in the name). When in the same page there is a link that says "Show additional download options"[1], in that page you have access to "clean" installers.

The way they did it is quite shady.

[0]: https://filezilla-project.org/download.php?type=client [1]: https://filezilla-project.org/download.php?show_all=1

Re: Filezilla installer is suspicious again

#212

It's sad that FileZilla remains so popular long after the creator has chosen to monetize it with adware. I highly recommend any FileZilla user reading this should switch to WinSCP. It's free, open source, and not bundled with any crapware.

This should go higher in the thread. I personally didn't know this behavior.

Re: Filezilla installer is suspicious again

#213
post #49

Earlier quoted context omitted.

Well, I do think there is some hypocrisy on the part of people (including myself) enjoying free software and services, when the revenue of those is generated by unaware people clicking on ads or accidentally installing crapware. >You CAN install binaries on other platforms but on for example linux distros their is a curated platform of packages where you can get most/all software. Sure, but things often work better w…

"things often work better when you pay people upfront rather than get something for free and let them fend for themselves"... Whoah, for a second I thought this was 1999.

Looking at the official numbers of desktop Linux installed systems looks like it.

Re: Filezilla installer is suspicious again

#214
post #194

Earlier quoted context omitted.

> Its truly amazing to me that installing windows software is still like this It doesn't have to be that way, since there is a Windows/Microsoft Store since plenty of years now. But then you have gamers and game devs spreading FUD about UWP and the the MS Store, while they praise 3rd party platforms like Steam and GoG that actively refuse UWP apps in their store, while allowing Spyware like this. https://www.reddit.c…

This account has been using HN exclusively to promote a pro-Microsoft agenda for a long time. That's a serious abuse of this site and I've banned it. All: Agenda-driven and single-purpose accounts aren't allowed on Hacker News because they're incompatible with the intellectual curiosity this site exists for. Double that when the agenda or single purpose is advancing corporate interests. It doesn't matter what corp it…

Also, double standards, since plenty of people post only about Linux, Android, ChromeOS, OSX or iOS and they never get flagged. And yes, genuine non-paid Windows enthusiasts like me do exist, and I shouldn't feel ashamed of it.

There is a perpetual hostility towards Windows users on this site, maybe you should address that first.

Re: Filezilla installer is suspicious again

#216
post #204
post #147

Earlier quoted context omitted.

This is allowed under GDPR? Doesn't this constitute breaking into computers?

Even if it did (but that’s rubish), it would have nothing to do with GDPR - which isn’t your personal magic bullet against anything you might not like.

Those two laws are, actually, my personal bullet against virtually everything I don't like happening to my own computer -as well as those owned by others (though that is not within my responsibility)-.

I feel like you missed the point though. There's no obvious question to the computer user that this is going to happen; ie. there is no consent. Which is important with regards to GDPR.

Next, what happens is the question. Either the security of the computer is breached (which I'll just call "malware" from hereon), or PII is being send (spyware).

Malware seems obvious to me. That's breaching computer security, been illegal for quite a while now. Not worth the discussion though recently the government of The Netherlands made it legal for the police to hack its civilians.

Spyware's legal status seems to have changed since GDPR though. Sure, a lot of spyware is shady, makers of it don't care. But the spyware being bundled with software was done by someone. And in this case, it appears to be within FileZilla's responsibility.

You may not be from EU; I saw FileZilla developers being obviously from the EU and I am from the EU as well. So the GDPR does apply for me, for sure.

Re: Filezilla installer is suspicious again

#217
post #190

Earlier quoted context omitted.

Even way down here where the core of the conversation isn't happening? How would a "no" derail it?

Its the same reason that I don't think I can force you to answer any question I want. Its a point of principle.

It's a point of you dishonestly misrepresenting your own interest in FileZilla installing malware for any users still foolish enough to download it.

Re: Filezilla installer is suspicious again

#218
Damn. Personally I'd hoped the FileZilla team had discontinued their bundling of malware since the SourceForge episode, which I wrote about here:

https://web.archive.org/web/20140816230250/http://blog.glust...

Instead, it looks like they've taken up with the malware creators directly.

Wonder what the most appropriate solution would be?

If Google were to "ban" FileZilla from its results (due to pushing malware), it sounds to me like that would work.

Re: Filezilla installer is suspicious again

#219
post #49

Earlier quoted context omitted.

I would rather they go out of business if they can't figure out another way to make money. You CAN install binaries on other platforms but on for example linux distros their is a curated platform of packages where you can get most/all software. The fact that this is the default way to install software and regular users don't need to look beyond the official repos is why installing software on linux isn't this kind of…

Well, I do think there is some hypocrisy on the part of people (including myself) enjoying free software and services, when the revenue of those is generated by unaware people clicking on ads or accidentally installing crapware. >You CAN install binaries on other platforms but on for example linux distros their is a curated platform of packages where you can get most/all software. Sure, but things often work better w…

> In the case of Linux packaging, there is no mechanism for monetization or advertising, so the point doesn't come up.

Just to point out, there are commercial versions of Linux (Red Hat, SUSE Linux, likely others). Both with workstation and server variants.

Re: Filezilla installer is suspicious again

#220
post #196
post #133

Earlier quoted context omitted.

I dispute "The hash doesn't match because the filename doesn't match." He did backpedal and say he really meant they don't match because the files are different. (Well, duh.) I also dispute "It's a tautological false-positive, by the very definition of the term, _everything_ is potentially unwanted." That's not the definition. Here is a definition in line with what just about everyone means by the term: "A potentiall…

Well, the central question in my mind anyway, is whether FileZilla distributes malware. I don't see any data on that yet.. maybe it will come. Meanwhile I'm not going to join other HN members in calling people I don't know "scum".

FileZilla doing this has been known for at least a few years:

https://web.archive.org/web/20140816230250/http://blog.glust...

Back then, they were doing it as part of the (previous incarnation of) SourceForge's "DevShare" offering. eg malware authors got SourceForge to bundle crapware with popular Win installers, and gave the developers a cut of the take.

It seems like the FileZilla people didn't like that revenue stream being cut off, and went to the source directly afterwards. :(

Post reply on HN