Live data from Hacker News

Filezilla installer is suspicious again

forum.filezilla-project.org

81–90 of 258 posts

Re: Filezilla installer is suspicious again

#81
post #68

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

The long term solution is to get off the platform. Never any malware on other platforms? Do you not remember Sourceforge? And let’s not forget that so much Linux software installs these days via curl|sh...

FYI the SourceForge version of FileZilla is clean, and has been since 2016. The official FileZilla installer has been doing this for some time now though. In case people don’t know, a lot has changed at SourceForge since my company acquired them in 2016. All projects are scanned for malware. We covered the improvements again here https://sourceforge.net/blog/brief-history-sourceforge-look-...

Re: Filezilla installer is suspicious again

#82

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

Why can't someone just check the digital signature like he says?

Re: Filezilla installer is suspicious again

#83

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

> Its truly amazing to me that installing windows software is still like this It doesn't have to be that way, since there is a Windows/Microsoft Store since plenty of years now. But then you have gamers and game devs spreading FUD about UWP and the the MS Store, while they praise 3rd party platforms like Steam and GoG that actively refuse UWP apps in their store, while allowing Spyware like this. https://www.reddit.c…

Microsoft itself is collecting a lot of telemetry even in Basic configuration [1], for example, if you use UAC (privileges elevation popup) they collect "the full command line arguments being used to elevate.". Also they collect a lot of hardware identifiers (including IMEI - unique phone identifier that allows to track it) so later they can reliably prove that some user was using this computer at this time. What a nice feature.

They also collect information on files that are " part of an app and either have a block in the compatibility database or are part of an anti-virus program.".

How can we trust Microsoft after this?

[1] https://docs.microsoft.com/en-us/windows/privacy/basic-level...

Re: Filezilla installer is suspicious again

#84
post #67
post #64

Earlier quoted context omitted.

What doesn't make sense? FileZilla is a bad actor who is trying to infect people's computers with malware. Download sites are bad actors who are trying to infect people's computers with malware. People should have all the information they need to avoid malware, so they can make good decisions, such as installing WinSCP from Ninite instead of installing FileZilla by any method. You keep denying that trustworthy free s…

>Such as installing WinSCP from Ninite instead of installing FileZilla by any method. https://en.wikipedia.org/wiki/WinSCP#Advertisements_in_insta... >You keep denying that trustworthy free software exists, and yet when anyone points out that it does, you change the topic. People who cheat on tests believe everyone is cheating on tests. You are unable to understand how "trustworthy free software" vendors make money.…

The post which you've replied to raised a question which you've chosen not to answer. Are you at all connected to the FileZilla project?

Re: Filezilla installer is suspicious again

#85
post #68

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

The long term solution is to get off the platform. Never any malware on other platforms? Do you not remember Sourceforge? And let’s not forget that so much Linux software installs these days via curl|sh...

"And let’s not forget that so much Linux software installs these days via curl|sh... "

Actually virtually everything is packaged for at least the major linux platforms an exhortation on a web site saying you can install foo via curl |sh can in fact normally be reasonably followed by apt install foo or insert gui/cli package manager of your choice.

Re: Filezilla installer is suspicious again

#86

Botg site admin "The hash doesn't match because the filename doesn't match." A fully descriptive answer is that they don't have a checksum for the bundled package but botg doesn't want to say this. " Dangerously ignorant user. Not matching filename = the checksum is NOT for that file. Checksums can only be provided for the non-bundled packages, because they're static. Bundled installers are not." Dangerously ignorant…

Its truly amazing to me that installing windows software is still like this. You think this is bad, you should try the Windows 10 auto updater. Disclaimer: It's broken on my brand new PC and no helpful on-line fix has worked so far. So I might hold hate in my heart.

Similar experience here; Windows Update has been completely broken since shortly after I upgraded from Win7 to Win10.

It tries to update -- it downloads several GB of patches, reboots and spends about 20 minutes installing -- then it tells me something along the lines of my system being "incompatible" with Windows (I forget the details, it's been a while) and rolls everything back.

Every six months or so I let it try again, in vain hope that the latest version will have fixed the problem. At some point I should get around to doing a clean reinstall, but that means taking the risk that my old Win7 product key would no longer validate.

Re: Filezilla installer is suspicious again

#87

Earlier quoted context omitted.

Its truly amazing to me that installing windows software is still like this. You think this is bad, you should try the Windows 10 auto updater. Disclaimer: It's broken on my brand new PC and no helpful on-line fix has worked so far. So I might hold hate in my heart.

Similar experience here; Windows Update has been completely broken since shortly after I upgraded from Win7 to Win10. It tries to update -- it downloads several GB of patches, reboots and spends about 20 minutes installing -- then it tells me something along the lines of my system being "incompatible" with Windows (I forget the details, it's been a while) and rolls everything back. Every six months or so I let it try…

Risk should be minimal. If you installed Windows 10 and it's activated, it should work after reinstall, you don't even need to type product key, MS servers remember that your hardware is authorized to run Windows 10.

Re: Filezilla installer is suspicious again

#88
post #39

Sophisticated users will know to download the unbundled installer, and maybe even go so far as to verify the hash. But that sideskirts the question of whether to continue using software where the authors are willing to put their users at risk by monetizing with what is apparently malware bundles. FileZilla is by all accounts a fantastic piece of software. I’ve used it for years, both the client and the server, and it…

I don't really see the problem. If the developers want to get paid for they work they can just sell their software. The problem is when someone tries to monetize their product by deceiving users. This is the case: they prevent user from knowing what is happening on their computer, download and run suspicious binaries and use EULA as an excuse. And I suspect, they themselves don't even know for sure what is bundled into the installer.

User should know exactly what they are offered. Hiding a clause like "you allow us to do anything we want" in EULA should not work.

Re: Filezilla installer is suspicious again

#89
post #68

Earlier quoted context omitted.

The long term solution is to get off the platform. Never any malware on other platforms? Do you not remember Sourceforge? And let’s not forget that so much Linux software installs these days via curl|sh...

"And let’s not forget that so much Linux software installs these days via curl|sh... " Actually virtually everything is packaged for at least the major linux platforms an exhortation on a web site saying you can install foo via curl |sh can in fact normally be reasonably followed by apt install foo or insert gui/cli package manager of your choice.

When I use apt-get I am downloading from debian.org, where at least there will be a record of what was executed. Further, I trust debian.org more than some random github repo.

When I use curl|sh, I could execute hidden text, e.g. through a Javascript command, which automatically executes the code and then deletes it from my history. At a future date, there is no way for me to know whether something malicious was executed, since the website may remove the malicious code when they get called out.

Re: Filezilla installer is suspicious again

#90
post #84
post #67

Earlier quoted context omitted.

>Such as installing WinSCP from Ninite instead of installing FileZilla by any method. https://en.wikipedia.org/wiki/WinSCP#Advertisements_in_insta... >You keep denying that trustworthy free software exists, and yet when anyone points out that it does, you change the topic. People who cheat on tests believe everyone is cheating on tests. You are unable to understand how "trustworthy free software" vendors make money.…

The post which you've replied to raised a question which you've chosen not to answer. Are you at all connected to the FileZilla project?

I choose to ignore irrelevant questions to avoid derailing the conversation.
Post reply on HN