Slashdot Mirror


10 Years Later: FileZilla Adds Support For Master Password That Encrypts Your Logins (bleepingcomputer.com)

An anonymous reader writes: "Following years of criticism and user requests, the FileZilla FTP client is finally adding support for a master password that will act as a key for storing FTP login credentials in an encrypted format," reports BleepingComputer. "This feature is scheduled to arrive in FileZilla 3.26.0, but you can use it now if you download the 3.26.0 (unstable) release candidate from here." By encrypting its saved FTP logins, FileZilla will finally thwart malware that scrapes the sitemanager.xml file and steals FTP credentials, which were previously stolen in plain text. The move is extremely surprising, at least for the FileZilla user base. Users have been requesting this feature for a decade, since 2007, and they have asked it many and many times since then. All their requests have fallen on deaf ears and met with refusal from FileZilla maintainer, Tim Kosse. In November 2016, a user frustrated with Koose's stance forked the FileZilla FTP client and added support for a master password via a spin-off app called FileZilla Secure.

45 of 82 comments (clear)

  1. I use WinSCP now by nctritech · · Score: 1

    I've found WinSCP to be better than FileZilla especially since so many providers offer SFTP now anyway. I don't store my passwords so the master password thing is not an issue to me. Don't store passwords if you don't want them to be found.

    1. Re:I use WinSCP now by antdude · · Score: 1

      Can it resume downloads and uploads?

      --
      Ant(Dude) @ Quality Foraged Links (AQFL.net) & The Ant Farm (antfarm.ma.cx / antfarm.home.dhs.org).
    2. Re:I use WinSCP now by TheOuterLinux · · Score: 1

      FileZilla can do this. You right-click on the Queued Files section and select Export. It will save an XML file with all the queued items. Then, all you have to do is go to File-->Import and then right-click on the Queued Files section again and select Process Queue.

    3. Re:I use WinSCP now by TheOuterLinux · · Score: 3, Insightful

      Where are you getting your FileZilla from to have adware? Neither my Mac or Linux system's versions show ads, and I'm getting it from here: https://filezilla-project.org/. Maybe it's just a Window$ thing?

    4. Re:I use WinSCP now by antdude · · Score: 1

      Interesting! So, it can resume transfers for SCP? I will need to check it out again.

      --
      Ant(Dude) @ Quality Foraged Links (AQFL.net) & The Ant Farm (antfarm.ma.cx / antfarm.home.dhs.org).
    5. Re:I use WinSCP now by Zocalo · · Score: 3, Insightful

      At a guess, SourceForge, or maybe some other third party download mirror site with similar practices, and yeah, AFAIK, it's mostly a Windows thing. SourceForge - and others - went through a period of bundling crapware with tools being downloaded from them, and since they were a popular means for small projects to offset bandwidth costs a lot of projects got bitten until they were forced to provide an opt out - and FileZilla the poster child for projects involved. There was an outcry, as you'd expect, but I have no idea which the mirror sites stopped the practice or not because this pretty much killed my use of them for downloads (sorry, small projects!), but I believe most mirror sites that are claiming to be reputable either no longer do so at all, or at least provide projects an opt out.

      --
      UNIX? They're not even circumcised! Savages!
    6. Re:I use WinSCP now by nctritech · · Score: 1

      Yes. It will see the partial file and ask you if you want to resume or restart from scratch.

    7. Re:I use WinSCP now by LVSlushdat · · Score: 1

      AND if you don't use Windows anymore, WinSCP is a non-starter, and as far as I'm concerned, Filezilla is the best ftp/scp/ftps client for Linux....

      --
      THANK YOU, Edward Snowden!! Americans owe you a debt of gratitude (whether they know it or not..)
    8. Re:I use WinSCP now by 0111+1110 · · Score: 1

      Yeah I guess it's a Windows thing. The developers wanted to make some extra cash with bundled adware, but I think they left Linux and Mac users alone. The Windows version still has the bundled adware when you download it from the link you posted.

      The only way to avoid the adware on Windows is to compile the binary yourself from the source code or maybe use the Chocolatey package. There used to be download links that avoided the malware infected versions but those were taken down a long time ago. Presumably because the devs wanted to maximize their adware revenue. Every time someone downloaded the adware free version they probably figured they were losing money.

      The bundled adware is not any sort of accident. The devs admitted as much a long time ago. They wanted to make money. I don't understand why people give the Filezilla devs a pass for going the adware/malware route. Maybe because they left Linux users alone or because they kept it open source. IMO though they are still dicks.

      --
      Quite an experience to live in fear, isn't it? That's what it is to be a slave.
    9. Re:I use WinSCP now by antdude · · Score: 1

      Cool. In the past, I wasn't able to resume download and upload files with SCP, SFTP, etc.

      --
      Ant(Dude) @ Quality Foraged Links (AQFL.net) & The Ant Farm (antfarm.ma.cx / antfarm.home.dhs.org).
    10. Re:I use WinSCP now by nctritech · · Score: 1

      You can use it with WINE and when Linux was my primary desktop OS I used to use gFTP or lftp instead.

    11. Re:I use WinSCP now by TheOuterLinux · · Score: 1

      I haven't used Window$ since 2008 unless forced to in an office/mdeia center environment. When I see things like this on a Micro$oft system in an environment with a lot of people, it doesn't shock me at all. However, every now and then when I see a friend showinf off their new laptop, I cringe and complain about what they are using, yet they expect it from a Linux user like me. In other words, freemium/adware/30-day trial is socially excepted, even though they are paying $900 for a laptop on top of being locked into cloud computing software and everything else. That's probably why Linux users never complained all that much since we can just take the source code and fork it without ads. A few people did that for the Window$ version, but it never took off and with the Window$ Store becoming popular, it never will.

    12. Re:I use WinSCP now by indi0144 · · Score: 1

      [citation needed]

      The news was the Sourceforge was adding adware to the packages and the one that caused the outrage was FZ. Is not the developers that added the adware on their side, they might have signed up for the Ad program offered by SF which they dumped once they realized whats was all about.

      Also because I even got to download one of the bundled installers for FZ on windows and the AV picked the Adware package. Easily removed with 7z and FZ installed cleanly afterwards.

  2. Transmit by Idimmu+Xul · · Score: 1

    Filezilla is so behind the times I switched to Transmit on the mac and have never looked back

    --
    The problem with slashdot is that most of its users were bullied and stuffed into lockers as kids!
    1. Re:Transmit by 93+Escort+Wagon · · Score: 1

      Filezilla is so behind the times I switched to Transmit on the mac and have never looked back

      $34 seems like a bit much for an ftp/sftp app...

      --
      #DeleteChrome
    2. Re:Transmit by TheOuterLinux · · Score: 1

      Cyberduck is free and open source and very easy to use if you need a Mac client.

    3. Re:Transmit by thegarbz · · Score: 1

      Behind on the times? What is it that Filezilla is missing? A frigging like button or something?

  3. Do you have a point? by Anonymous Coward · · Score: 1

    "Criticism" huh?

    Yep. It's free and easy, and sometimes even helpful.

    Well it's free

    Yep. Free software. Yay.

    why is the developer obligated to do anything?

    The developers are not obligated to do anything.

    Don't like it?

    I don't use Filezilla and do not have a strong opinion regarding this feature.

    Fork it and add your own functionalty.

    It looks like that is what solved the problem.

    It's pretty fucking arrogant to think the developer is on the hook to add your oh-so-desired feature when you're not paying him.

    That would be pretty arrogant. Do you or anyone you know feel that way? Or are you just creating a strawman so that you can argue against it?

    You didn't say this exactly, but you seem to be implying that nobody should be allowed to criticize free software. If you were to say that, I would say bullshit, if you don't want your work criticized then don't share it. Everyone is free to give their opinion, to which you can choose to utilize it to make a better product or you can ignore it.

    1. Re: Do you have a point? by Vlad_the_Inhaler · · Score: 5, Informative

      Naming the developer is less of a deal here than you think - he has been notorious for years because of his stance on this matter. He has rejected patches from third parties trying to fix the deficiency, something which finally led to the fork a year or so ago. Oh, the person who forked the project had suffered a breach where the lack of this feature was a major contributing factor.

      I don't use FileZilla and never have, but for me the whole sordid tale raises a question mark against projects of this kind: Any project of this nature is substantially ego driven, the programmer is donating time and energy to provide a service. The problem is when that ego leads him (99% are male) to leave unnecessary deficiencies in the "product"? I'm running an old linux distribution on a machine in my internal network because an important tool was updated around 18 months ago to remove support for something I use a lot. It is a personality clash between the owners of two projects. My old version works.
      Look at the decisions Firefox has made recently, I consider some of them to be sabotage, vandalism.

      --
      Mielipiteet omiani - Opinions personal, facts suspect.
    2. Re: Do you have a point? by Anonymous Coward · · Score: 5, Informative

      Someone thanked the developer for adding this feature (after filing a request for it 9 years ago), and he replies

      "I'm glad you like a feature that doesn't even increase security."

      I hope to never meet or interact with this person, as it is highly frustrating to even read about this interchange from my position of removal (not a filezilla user).

      Link here: https://forum.filezilla-project.org/viewtopic.php?f=3&t=64&start=1005#p156191

    3. Re: Do you have a point? by misexistentialist · · Score: 1

      it's his personality, can't take it personally because he is consistent

  4. Holy crap by 93+Escort+Wagon · · Score: 4, Insightful

    By encrypting its saved FTP logins, FileZilla will finally thwart malware that scrapes the sitemanager.xml file and steals FTP credentials, which were previously stolen in plain text.

    You've got to be kidding me.

    --
    #DeleteChrome
    1. Re:Holy crap by PrimaryConsult · · Score: 2

      Thankfully pidgin has disappeared into irrelevance with the rise of cell phone messaging; they still store their passwords in plain text.

    2. Re:Holy crap by Anonymous Coward · · Score: 1

      Yes, how dare they use XML when they could have used SQLite and JSON like Firefox or instead do it like Chrome on Windows where Microsoft is expected to do the right thing.

      Storing passwords on a system where those passwords can be accessed by software without user interaction doesn't strike me as very secure. Then again, if malware is on the system you probably have already lost, so the keychain encryption schemes help against attacks on turned off/logged out devices.

      The integration of a password manager sure is a convenient thing, though. Good on them for finally implementing that.

    3. Re:Holy crap by Anonymous Coward · · Score: 1

      THEY (the original Filezilla devs) DIDN'T do that... Someone else forked Filezilla and added that feature.. Read the article ffs

    4. Re:Holy crap by SeaFox · · Score: 1

      Pidgin became irrelevant for two reasons -- in the following order chronologically:

      1) The developers only wanted to add features they personally were interested in, and their desires didn't correspond to those of anyone else who used the program.

      2) IM networks taking protocols private.

  5. Re:Does anyone... by MightyYar · · Score: 2

    My whole company has standardized on it. I can go to any PC in the building and find Filezilla. To be fair, they standardized on it perhaps 7 years ago. But hey, it still works.

    --
    W..w..W - Willy Waterloo washes Warren Wiggins who is washing Waldo Woo.
  6. I'm waiting for Archie and Gopher version by goombah99 · · Score: 1

    who uses FTP? isn't SCP the thing?

    --
    Some drink at the fountain of knowledge. Others just gargle.
    1. Re:I'm waiting for Archie and Gopher version by dissy · · Score: 1

      who uses FTP? isn't SCP the thing?

      Filezilla does SCP as well as SFTP, and FTPS.

      There are less and less things using plain FTP, mainly anonymous public file repositories.
      But they support full FTP authentication none the less.

      Since the vast majority of the transfer protocols it supports are encrypted specifically to not send your password in plain-text, it is fairly important to store them encrypted locally too if you will be storing them at all.

      Makes little since not to store FTP passwords right along with the others in the same place and would be silly not to.

      Personally the last time I used FTP sending a password was to upgrade the firmware on a network switch I had connected via cross over to a laptop, and it was the default user/pass from the manual. In that case the firmware upgrade required blowing away the config and starting over, so it made little sense to change the password ahead of time when I'd need to do it again after.
      Since this was before deploying the hardware, and in the fully configured state FTP was disabled completely, I don't feel it is fair to consider such a usage as insecure.

  7. Not using SCP? by Cmdln+Daco · · Score: 1

    I wince any time I have to access a logged account on a server with FTP. Isn't the password sent over the wire unencrypted? FTP has been replaced by SCP for a reason.

    If I am wrong please correct me.

    1. Re:Not using SCP? by Frosty+Piss · · Score: 1

      I wince any time I have to access a logged account on a server with FTP.

      For anything other than, for example public FTP software downloads, most people who use FileZilla use SFTP. The fools at WordPress still use FTP for auto-updating. Though SFTP is an option, noobs will probably use FTP.

      But why do hosting companies even allow it? It's got to be a HUGE vector, and although hosting companies generally will not take any responsibility for hacked sites that they host (and why should they), it's got to be a Help Desk pain in the ass.

      --
      If you want news from today, you have to come back tomorrow.
    2. Re:Not using SCP? by freeze128 · · Score: 1

      How is FTP *MORE* of a pain in the ass to the helpdesk than SFTP? The only thing they have to do is manage password resets. It's just as easy to do that for FTP as it is for SFTP.

    3. Re:Not using SCP? by Frosty+Piss · · Score: 1

      How is FTP *MORE* of a pain in the ass to the helpdesk than SFTP? The only thing they have to do is manage password resets. It's just as easy to do that for FTP as it is for SFTP.

      From the resulting account hacks was my thinking, but I can't confirm that.

      --
      If you want news from today, you have to come back tomorrow.
    4. Re:Not using SCP? by Frosty+Piss · · Score: 1

      That you don't appear to know this and yet feel free to opine on the matter tells me that you need to turn in your geek card at the door immediately, and leave Slashdot forever. Never come back.

      I would tell you to go fuck yourself, but as you are an over-weight neck-beard situated in a darkened basement where you consume copious quantities of Mountain Dew and Cheetos, I assume you already fuck yourself.

      --
      If you want news from today, you have to come back tomorrow.
    5. Re:Not using SCP? by Frosty+Piss · · Score: 1

      Cheers!

      How pretentious. Are you enjoying your quiche Lorraine and over-oaked Chardonnay?

      --
      If you want news from today, you have to come back tomorrow.
  8. Re:Filezilla = Adware by Anonymous Coward · · Score: 4, Informative

    It is *not* free software

    Yes, it is. On the main site I can download the source code and compile it, something I've had to do when the pre-built Linux binaries didn't work on older distros. The software license is GPL v2.

    How the fuck is it NOT free software? If you're still referring to it as adware, I'm assuming it's because of the partnership with SourceForge which bundled adware in certain versions of the software (of which you could easily still download a clean version if you knew what you were doing). That program ended quite a while ago. Of course, you'd know this if you bothered to be more understanding and check if what you actually typed matched reality, but that's too much work. Hatred is easier.

  9. Hard to believe by n3r0.m4dski11z · · Score: 2

    The fact that they have near daily updates (Basically every time i turn on filezilla, there is a new client), I am extremely surprised that they wouldn't handle feature requests promptly. What the hell are all the damn updates for then?? NO software can be THAT buggy!

    But back in the day, I do remember them implementing a suggestion I pushed for which was the addition of autoban. So I considered them quite responsive.

    And for saying "filezilla is DYING!" that hasnt been my experience. I thought it was considered the de-facto standard because: 1) they offer a client on virtually every platform and 2) its the ftp client that ninite installs. Most people who arent using filezilla, are using browser based FTP and locking out their accounts with unstandard behaviour. So i like being able to tell literally anyone, to just go to one website to get a great free ftp client.

    I personally don't save passwords in an ftp client in the first place. Perhaps that was why it was not a popular suggestion. The people who are concerned with security enough to know what a master password would do, and yet still want to store their passwords inside the program instead of in their head or document, has got to be a small group. I know its envogue for password managers now and maybe thats why he implemented it.

    This is really just a positive story for open source software in general. You can have a program constantly maintained for so long that it can accumulate 10 year old feature requests that ACTUALLY GET IMPLEMENTED! hooray!

    --
    -
  10. Re:Does anyone... by tonique · · Score: 1

    Our corporate software center allows all users to install Filezilla with just two clicks! I think it might be there because some employees use it to transmit big files to clients. Ok, honestly, I don't know why it's there.

  11. Re:Filezilla = Adware by Zocalo · · Score: 2

    FileZilla has its faults, but being adware is NOT one of them. It was one of many victims (GIMP and VLC were others) of third party mirror sites like SourceForge that decided to make some additional money by bundling crapware with downloads, often without the knowledge of the projects involved. Unless you've been sourcing your software from a particularly shady mirror site, this bundling was usually made pretty clear during the install process, such as the screenshot in the link.

    --
    UNIX? They're not even circumcised! Savages!
  12. Re: It's Open Source by Joce640k · · Score: 2, Informative

    Why would anybody still use it?

    It turned into spyware years ago and WinSCP is 3000% better.

    --
    No sig today...
  13. Re:Filezilla = Adware by thegarbz · · Score: 2

    So you clearly don't use Filezilla.

  14. Re:Filezilla = Adware by LVSlushdat · · Score: 1

    I use Filezilla extensively on Linux and I gar-on-tee you theres NO ads here.... Couldn't say about the Winblows version, as I quit fucking with Microsoft crap over 7 years ago.....

    --
    THANK YOU, Edward Snowden!! Americans owe you a debt of gratitude (whether they know it or not..)
  15. Re:Filezilla = Adware by Anonymous Coward · · Score: 1

    Actually, the maintainer of FileZilla repeatedly defended this practice of SourceForge in their forums. He also made money from the bundled software. He insisted repeatedly in the forums that it was not malware, and that people were free to choose not to install them. I think *technically* they were not malware, but they were certainly unwanted by the vast majority of the people who installed them.

    I do believe that the program has been ended (by SourceForge's action, not by FileZilla), but FileZilla does now have ads on the new version screen. I think it is fair to call it ad-supported.

  16. SFTP by DrYak · · Score: 1

    I've found WinSCP to be better than FileZilla especially since so many providers offer SFTP now anyway.

    Note that Filezilla support SFTP too.

    I don't store my passwords so the master password thing is not an issue to me. Don't store passwords if you don't want them to be found.

    Even better :
    don't use passwords. Use Public Keys pairs.

    (Filezilla supports them, and can use Putty's key agent to handle them)
    (I'm sure that WinSCP can too, just didn't bother to check).

    Best part : you can then completely switch off the support for password on the SSH/SFTP server.
    Your server is then (obviously) immune to brute force / password guessing.

    --
    "Sufficiently advanced satire is indistinguishable from reality." - [Tips: 1DrYakQDKCQ6y52z6QbnkxHXAocMZJE61o ]
  17. Maybe FileZilla Server can add SFTP support... by rklrkl · · Score: 1

    I guess there's still hope for FileZilla Server to eventually get SFTP support before I die. It's quite astonishing that this "obvious" feature of file transfer server software hasn't been implemented yet (despite the FileZilla Client having had SFTP support for years). I mean, it's "only" been 13 years since the feature was originally requested - easily beating the master password encryption feature request by a full 3 years. And, yep, someone recently suggested closing the SFTP feature request because Tim Kosse has done nothing about it for well over a decade :-(