Live data from Hacker News

Filezilla installer is suspicious again

forum.filezilla-project.org

31–40 of 258 posts

Re: Filezilla installer is suspicious again

#31
post #14
post #2

I can't believe those are real admin responses. TigheW was far more patient than they needed to be, that was painful.

What factual information do you dispute from their responses?

I'd dispute the whole "we are shipping this extra software, we don't really know what it does, but they are paying us so I don't see what the problem is ¯\_(ツ)_/¯" (paraphrasing)

Re: Filezilla installer is suspicious again

#32
post #11
post #9

Suspicious? Let’s call this what it really is: The FileZilla owners are actively encouraging users to install malware as a way to monetize. That is very clear. Avoid FileZilla by all means.

Yep. This matches behavior I've seen many times before from other software companies. In every circumstance I immediately ceased using anything made by them.

They did this before. Used to have Binkiland included in the installer from Soureceforge. They stopped, but obviously they're right back at it again.

Re: Filezilla installer is suspicious again

#33
post #25
post #20

Earlier quoted context omitted.

I don't support crapware but I'm not going to tell someone how they should make their living. That post looks like rabble rousing to me. I have yet to see any factual information except a whole lot of "it seems" "it appears" "I believe". I'd rather reserve judgement till the facts emerge.

If it were the first instance of this with Filezilla, and the admin response wasn't dismissive, I'd agree with you. They earned their reputation as untrustworthy.

Which facts did they dismiss? I just saw a lot of rabble rousing..

Re: Filezilla installer is suspicious again

#34
post #20

Earlier quoted context omitted.

Admin of FileZilla, Your reactions to this post deeply concern me. I do believe this is a serious problem you should at least entertain investigating whomever you have an agreement with in regards to bundling their stuff into your installer. Those domains its communicating with have several hits on known malware/RATs reports. For instance, https://www.maltiverse.com/sample/a98b1 ... 38233c50b7. Here is another that s…

I don't support crapware but I'm not going to tell someone how they should make their living. That post looks like rabble rousing to me. I have yet to see any factual information except a whole lot of "it seems" "it appears" "I believe". I'd rather reserve judgement till the facts emerge.

If I see someone being immoral I'm going to tell them "how to make their living" not because I hope they are going to be so inspired as to change for the better because you and I both know that's not going to work.

I do so because I hope other people will listen and stop doing business with them leading to a decrease in profit and THEN changed behaviour from the culprit.

There is lots of factual information. They are factually doing a lot of malware like behaviour in their installer and bundling software from questionable sources they have no control over. At best they are putting their customers at risk.

The only facts that can possible emerge is that its actually worse and customers are getting their identities stolen or some such.

Rabble rousing is literally the only way anything gets fixed.

Re: Filezilla installer is suspicious again

#36
post #26

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

Vendors who have partaken in the "bundled crapware" model of distribution - Google, Amazon, Yahoo, Microsoft, Adobe, Oracle, etc, etc. >They have decided that tricking people into downloading malware is a reasonable alternative to charging money for their software or soliciting donations. If you would be so kind enough as to show them how to make money perhaps they'll stop doing it. >Its truly amazing to me that inst…

I would rather they go out of business if they can't figure out another way to make money.

You CAN install binaries on other platforms but on for example linux distros their is a curated platform of packages where you can get most/all software.

The fact that this is the default way to install software and regular users don't need to look beyond the official repos is why installing software on linux isn't this kind of shit show.

Re: Filezilla installer is suspicious again

#38
post #30
post #27

Earlier quoted context omitted.

Oh my god. You're talking to competent computer users on Hacker News, not people who use crapware download sites and need to be warned away from them by "HowToGeek". Of course there is trustworthy freeware. You can get it using Apt, Yum, Ninite, Chocolatey, Homebrew, or just by going to the actual site of a trustworthy software product. The fact that the people who run most download sites are scum isn't a problem wit…

Um, the download section on the vendors website contains the text "This installer may include bundled offers. Check below for more options." https://imgur.com/a/Xrc1jMy You can download FileZilla without the bundled "offers". If the average hacker news reader is capable of doing that, then whats left is just a criticism of ALL bundled installers, in which case, pick a number and join the queue.

HN readers are capable of not using FileZilla, because its admin is actively trying to mislead its users into running malware.

Are you associated with FileZilla? Why are you here bringing out the "everyone is doing it" defense?

Re: Filezilla installer is suspicious again

#39
Sophisticated users will know to download the unbundled installer, and maybe even go so far as to verify the hash.

But that sideskirts the question of whether to continue using software where the authors are willing to put their users at risk by monetizing with what is apparently malware bundles.

FileZilla is by all accounts a fantastic piece of software. I’ve used it for years, both the client and the server, and it’s no doubt provided significant value to me over the years.

And yet I’ve never paid the FileZilla authors a penny for their services.

So while I didn’t force the FileZilla authors down this dark path that they’ve chosen to use for monetization, I accept that I am part of the problem.

Re: Filezilla installer is suspicious again

#40
post #26

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

Vendors who have partaken in the "bundled crapware" model of distribution - Google, Amazon, Yahoo, Microsoft, Adobe, Oracle, etc, etc. >They have decided that tricking people into downloading malware is a reasonable alternative to charging money for their software or soliciting donations. If you would be so kind enough as to show them how to make money perhaps they'll stop doing it. >Its truly amazing to me that inst…

I got tricked into installing adware as part of a java install, and took me many hours to get it back off my system.

I don’t get why microsoft isn’t pushing all these vendors really hard to distribute through the windows store. The windows store is a graveyard compared to the mac app store, despite having a head start and a bigger target audience, and it’s basically impossible to use windows without sideloading apps. Microsoft is pushing windows S at people, where you can’t sideload software, but the windows store just isn’t ready for that and all it will do is push people to the mac when they inevitably have a bad experience.

Post reply on HN