Live data from Hacker News

Filezilla installer is suspicious again

forum.filezilla-project.org

61–70 of 258 posts

Re: Filezilla installer is suspicious again

#63
post #43

Earlier quoted context omitted.

I don't see why, being on Linux, you would prefer to use FileZilla to transfer files to a remote machine over an insecure protocol when there are plenty of alternatives with better security. Rsync, for example, allows you to specify an SSH key. Or SCP, which also offers the same functionality.

This is a really toxic attitude in the open source community where when asked a question the answer is: "you're doing it wrong, just do it right". If I had a choice I would, but unless you have a few million dollars to give us to refactor 30 years of technical debt, please answer the question.

Are you a developer of filezilla?

Re: Filezilla installer is suspicious again

#64
post #52
post #38

Earlier quoted context omitted.

HN readers are capable of not using FileZilla, because its admin is actively trying to mislead its users into running malware. Are you associated with FileZilla? Why are you here bringing out the "everyone is doing it" defense?

>HN readers are capable of not using FileZilla, because its admin is actively trying to mislead its users into running malware. Then your prior comment makes no sense to me. >Of course there is trustworthy freeware. You can get it using Apt, Yum, Ninite, Chocolatey, Homebrew, or just by going to the actual site of a trustworthy software product. If you don't use the crapware downloader, then the vendor doesn't get an…

What doesn't make sense? FileZilla is a bad actor who is trying to infect people's computers with malware. Download sites are bad actors who are trying to infect people's computers with malware.

People should have all the information they need to avoid malware, so they can make good decisions, such as installing WinSCP from Ninite instead of installing FileZilla by any method.

You keep denying that trustworthy free software exists, and yet when anyone points out that it does, you change the topic to something fraud-ridden like download sites. People who cheat on tests believe everyone is cheating on tests.

I do not care one bit for your business model. Please go out of business ASAP.

Re: Filezilla installer is suspicious again

#65
I doubt the legal system that the publisher reside in would accept the excuse that giving control over to a third-party will protect them from liability if malware get installed from the installer. No amount of eula, disclaimer, or calling it "bundle" can do that, and now that there is a public documented discussion that the developer knowingly allowed it. That sound like some significant risk, one which I would never bet my own personal life on.

It will only take a security researcher that identify one of those unsigned processes, in the past or future, as malware and people who is infected by the same malware can check if they also has filezilla installed, and boom. A lawsuit is born.

Re: Filezilla installer is suspicious again

#67
post #64
post #52

Earlier quoted context omitted.

>HN readers are capable of not using FileZilla, because its admin is actively trying to mislead its users into running malware. Then your prior comment makes no sense to me. >Of course there is trustworthy freeware. You can get it using Apt, Yum, Ninite, Chocolatey, Homebrew, or just by going to the actual site of a trustworthy software product. If you don't use the crapware downloader, then the vendor doesn't get an…

What doesn't make sense? FileZilla is a bad actor who is trying to infect people's computers with malware. Download sites are bad actors who are trying to infect people's computers with malware. People should have all the information they need to avoid malware, so they can make good decisions, such as installing WinSCP from Ninite instead of installing FileZilla by any method. You keep denying that trustworthy free s…

>Such as installing WinSCP from Ninite instead of installing FileZilla by any method.

https://en.wikipedia.org/wiki/WinSCP#Advertisements_in_insta...

>You keep denying that trustworthy free software exists, and yet when anyone points out that it does, you change the topic. People who cheat on tests believe everyone is cheating on tests.

You are unable to understand how "trustworthy free software" vendors make money. Rather than wild accusations and hysteria, I'd recommend calm collected analytical thinking.

Re: Filezilla installer is suspicious again

#68

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

The long term solution is to get off the platform.

Never any malware on other platforms? Do you not remember Sourceforge?

And let’s not forget that so much Linux software installs these days via curl|sh...

Re: Filezilla installer is suspicious again

#70
post #68

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

The long term solution is to get off the platform. Never any malware on other platforms? Do you not remember Sourceforge? And let’s not forget that so much Linux software installs these days via curl|sh...

That's why I use my distro's package manager and review external scripts before running them.
Post reply on HN