>> To date, many malware distribution campaigns launch their attacks by compromising FTP servers Yes.. well, they can do the same by compromising servers that offer the payload via HTTP(S). At least when the payload is ftp, it stands out and you can catch it in your gateway/firewall devices. With https you now need https inspection at the border in order to be able to do that. These MITM devices do tend to cause a lo…
Stopping FTP support in Firefox 90
81–90 of 350 posts
Re: Stopping FTP support in Firefox 90
#82>If you are a Firefox user, you don’t have to do anything to benefit from this security advancement. The epitome of corporate speak: "we're taking away a feature of this software. You're welcome." I expect that kind of talk from Google; hearing it from Mozilla makes me a little sad.
I think what really hurts, for me, is that this has become the general tone from Mozilla - whether the changes are ones I'd agree with or not. I remember back when the Spread Firefox campaign was still around - at the time, Firefox and Mozilla in general felt grassroots, fun, and human. Like a club anyone could join and that anyone would want their friends, family, coworkers, and even strangers or people they didn't…
Re: Stopping FTP support in Firefox 90
#83Earlier quoted context omitted.
FTP is Internet browsing, it's just not not "web".
Yes, good point. Gopher is internet browsing too but is Firefox the best way to experience FTP and Gopher? How many different protocols should Firefox support? Firefox does not have the same resources as Google so focusing on what Firefox is known to do best such as HTTP and its supporting protocols, like WebSocket, really well looks like a good strategy.
Re: Stopping FTP support in Firefox 90
#84>If you are a Firefox user, you don’t have to do anything to benefit from this security advancement. The epitome of corporate speak: "we're taking away a feature of this software. You're welcome." I expect that kind of talk from Google; hearing it from Mozilla makes me a little sad.
However, there is no need to characterizes FTP being dangerous by jumping from FTP is old and is in plaintext, to FTP servers are being exploited and used to distribute malware, to FUD-type statement implying that there are [unspecified] exploits now available to attack Firefox if FTP was enabled.
This is just plain disgusting and it leaves a bad taste in my mouth.
Re: Stopping FTP support in Firefox 90
#85Re: Stopping FTP support in Firefox 90
#86Re: Stopping FTP support in Firefox 90
#87I don't understand all the negativity around this. People complained when Firefox added Pocket, in part because they took a browser extension and made it a feature that was ostensibly unrelated to web browsing. Now they're taking an old feature that's definitely not related to web browsing and removing it, and people are still complaining? Firefox can't be everything. It should focus on being a great browser and not…
Re: Stopping FTP support in Firefox 90
#88Earlier quoted context omitted.
Perhaps one day we can have a programming language that allows us to write software that doesn't rot or corrode.
As long as code connects to other code, it will need to be updated whenever the other code is updated. Maintenance-free code is a chimera.
Re: Stopping FTP support in Firefox 90
#89FTP might be dying in other sectors, but at least in biomed research, I would use FTP anyday when the alternative protocol needs a client app and a bunch of configurations. It's also handy when sharing data. Browser support is important here because those files are often not explored from command line etc, but rather the FTP links are placed on individual pages as a quick download. At least for me, it's much more con…
Why not rsync, scp, https, or any other plethora of much better alternatives?
Re: Stopping FTP support in Firefox 90
#90Earlier quoted context omitted.
It's old, but "ftp://" is a valid uri scheme that has established use, and lots of valid links on existing, live web pages. Browsers removing support are breaking part of the web that was working fine.
Agreed. There are old drivers from established vendors that only send drivers over FTP links. It's an edge case these days though as more are moving to https:// links so I can understand the browser vendors wanting to make the code base smaller. They have enough to do. Especially for Mozilla given what they charge for us to use their product.
Wouldn't help for internal network ftp servers, but would ease the publicly accessible part.
(Note that the dreamhost site has a little link icon in the lower left that will generate a link/landing page with all the important bits filled out.)