Live data from Hacker News

Filezilla installer is suspicious again

forum.filezilla-project.org

241–250 of 258 posts

Re: Filezilla installer is suspicious again

#241
post #237

Earlier quoted context omitted.

This is a serious false accusation. Am I not allowed to prefer Windows? All I did was correct the rampant misinformation and bias against Windows that rarely gets challenged. And do you really think someone working for Microsoft would post something like this? https://www.reddit.com/r/Surface/comments/7of68m/surface_pro...

I didn't say you work for Microsoft. I have no way of knowing that, and it doesn't seem likely. But you can't use HN exclusively to promote one company over others. The reasons ought to be obvious.

But I'm not promoting any company. Most of my comments are just correcting misinformation and explaining why I use Windows. And as you can see on reddit, I heavily criticized MS and the media regarding the Surface Pen issues that they keep ignoring. That thread even got stickied on the Surface subreddit.

I also regularly criticize Windows 10 there, and praise iPads and ChromeOS. So please reconsider this ban.

Re: Filezilla installer is suspicious again

#242

Earlier quoted context omitted.

Honorable providers, for example the Tor and MPTCP projects, run their own repositories, with GnuPG-authenticated packages. You get up-to-date builds, with no crap.

So long as the provider remains honorable. If they decided to bundle malicious programs -- or someone who took control if their domain and private key did -- they easily could. They could publish updates to the program, publish new dependencies, or even publish updates to packages you normally get from your main distro repository. If you're doing apt-get update (or equivalent) how closely do you scrutinize the list o…

Yes. You gotta trust the provider.

Re: Filezilla installer is suspicious again

#243
post #228

Earlier quoted context omitted.

Honorable providers, for example the Tor and MPTCP projects, run their own repositories, with GnuPG-authenticated packages. You get up-to-date builds, with no crap.

But this negates the advantage of having a small number of trusted repos if you need to add third-party repos for every project.

Sure. And it's a tradeoff. The Tor and MPTCP projects came to mind, because I trust them. And there aren't many others that I trust.

My problem is that I prefer Debian stable, which is very conservative about package updates. But sometimes I end up using Ubuntu, because its repo includes newer packages.

Also, my core systems do not include anything except stable Debian. I only use third-party repos in project-specific VMs. I even use Oracle's MySQL Workbench in an Ubuntu VM. And even Windows 10 VMs, when I need Excel or other Windows-only apps. That is, compartmentalization.

Re: Filezilla installer is suspicious again

#244
post #238
post #182

Earlier quoted context omitted.

While its obvious that I have done no such thing, I find it rather interesting that people calling other people "scum" are not reminded of "civility".

The likeliest explanation for that is always the simplest one: we didn't see it. Obviously, though, breaking the rules isn't justified by other people breaking the rules. It always feels like the other person started it (and did worse), so one could use that to justify anything. Re your comments, personal swipes like "you seem very confused", "you are unable to understand", "rather than wild accusations and hysteria,…

I don't expect you to look at 100% of the comments, but its a bit like citing someone for jaywalking but letting the murder escape. Sure cite the jaywalker, but after you've found the murder.

>Re your comments, personal swipes like "you seem very confused", "you are unable to understand", "rather than wild accusations and hysteria, I'd recommend calm collected analytical thinking" are certainly uncivil and violate the site guidelines.

There are several flaws in your interpretation, but I don't wish to convince you otherwise.

Re: Filezilla installer is suspicious again

#245

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

Hashes never take the filename into account anyway. He knows this, and is trying to throw users off track.

Re: Filezilla installer is suspicious again

#246
post #184

Earlier quoted context omitted.

I guess I must have fallen into a time machine since I just purchased Photoshop last month.

That would be which logical fallacy? Something where you take something I said to a nonsensical extreme? I certainly never asserted that people did not pay for software. My point is that free software is very proven as a development, distribution, whatever method by now.

>My point is that free software is very proven as a development, distribution, whatever method by now.

Yes, it is indeed proven that when you pay people to develop software, it works great. (Linux, FF, Chrome, Photoshop, Windows, etc, etc). The license doesn't seem to make much of a difference.

When you don't - (your typical freeware on download.com) - they have to figure out a revenue stream after the fact, and the choices they end up making cause them to be on the front page of HN where people line up to call them "scum".

Obviously this is not about hobbyist/part-time developers with a github repo, who are already getting paid through an external job, etc.

Re: Filezilla installer is suspicious again

#247
post #244
post #238

Earlier quoted context omitted.

The likeliest explanation for that is always the simplest one: we didn't see it. Obviously, though, breaking the rules isn't justified by other people breaking the rules. It always feels like the other person started it (and did worse), so one could use that to justify anything. Re your comments, personal swipes like "you seem very confused", "you are unable to understand", "rather than wild accusations and hysteria,…

I don't expect you to look at 100% of the comments, but its a bit like citing someone for jaywalking but letting the murder escape. Sure cite the jaywalker, but after you've found the murder. >Re your comments, personal swipes like "you seem very confused", "you are unable to understand", "rather than wild accusations and hysteria, I'd recommend calm collected analytical thinking" are certainly uncivil and violate th…

Please just go out of your way to be civil. It's not that hard.

Re: Filezilla installer is suspicious again

#248
post #217
post #190

Earlier quoted context omitted.

Its the same reason that I don't think I can force you to answer any question I want. Its a point of principle.

It's a point of you dishonestly misrepresenting your own interest in FileZilla installing malware for any users still foolish enough to download it.

Yawn.

Re: Filezilla installer is suspicious again

#249
post #237

Earlier quoted context omitted.

This is a serious false accusation. Am I not allowed to prefer Windows? All I did was correct the rampant misinformation and bias against Windows that rarely gets challenged. And do you really think someone working for Microsoft would post something like this? https://www.reddit.com/r/Surface/comments/7of68m/surface_pro...

I didn't say you work for Microsoft. I have no way of knowing that, and it doesn't seem likely. But you can't use HN exclusively to promote one company over others. The reasons ought to be obvious.

Here is more proof that I'm not promoting for MS https://www.google.com/search?q=niveageforge+pen+issue+site:...

I'm the most vocal about this pen issue, that could potentially cost MS billions of dollars if they need to recall those devices. I once posted a pen issue thread that got banned from /r/Microsoft once. https://www.reddit.com/r/microsoft/comments/82ilso/the_worka...

Re: Filezilla installer is suspicious again

#250

Earlier quoted context omitted.

> The Linux one is from the same source too. Not in practise. The Linux version of Filezilla will usually be sourced from a package manager: $ apt show filezilla Package: filezilla Version: 3.28.0-1 … Description: Full-featured graphical FTP/FTPS/SFTP client Even Filezilla's own website says "It is highly recommended to use the package management system of your distribution". A huge portion of the software a typical…

Meh, they don't keep versions up to date. That version in the apt repo is several versions behind (not to mention how far behind they are on 16.04 repos), not something you usually want to do with network software like Filezilla. My comment listed just 4 pieces of software off the top of my head I installed on a fresh desktop recently, and I wouldn't get any of them from default apt install.

Just because the version is older doesn't mean it's insecure. Distros do backport patches, esp. if you run LTS versions.
Post reply on HN