updated filezilla and then server got compromised

Come here to discuss FileZilla and FTP in general

Moderator: Project members

Message
Author
User avatar
botg
Site Admin
Posts: 35565
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: updated filezilla and then server got compromised

#16 Post by botg » 2013-09-14 21:31

You can disable saving of passwords in the settings dialog of FileZilla if you do not wish to store passwords.

ftanner
503 Bad sequence of commands
Posts: 20
Joined: 2013-08-07 16:17
First name: Frank
Last name: Tanner

Re: updated filezilla and then server got compromised

#17 Post by ftanner » 2013-09-16 16:13

botg wrote:You can disable saving of passwords in the settings dialog of FileZilla if you do not wish to store passwords.
Your logic is like saying, "Why put locks on my house or car because someone can throw a rock through a window and get in."

User avatar
botg
Site Admin
Posts: 35565
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: updated filezilla and then server got compromised

#18 Post by botg » 2013-09-17 06:18

Exactly the opposite. My stance is that you need to protect your home, then you don't have to wrap all your tableware in bubblewrap. However if you let a crazed elephant in musth into your home, then not even the bubble wrap will help.

ftanner
503 Bad sequence of commands
Posts: 20
Joined: 2013-08-07 16:17
First name: Frank
Last name: Tanner

Re: updated filezilla and then server got compromised

#19 Post by ftanner » 2013-09-18 15:09

botg wrote:Exactly the opposite. My stance is that you need to protect your home, then you don't have to wrap all your tableware in bubblewrap. However if you let a crazed elephant in musth into your home, then not even the bubble wrap will help.
Yours is a flawed analogy...

Despite having door locks, someone can put a rock through your window and steal your possessions. THAT is the correct analogy.

Someone can have a secured system and STILL be compromised through a buggy app, such as a web browser. THIS is why your password file should be encrypted. Security through LAYERS.

Why don't you just admit it and say that you don't give a shit about the users of your software. Because if you did, encrypting the password file as an ADDED layer of security is trivial and you would implement it. putty has it. Keepass has it. Linux has it. Firefox has it. Chrome has it. Even Internet Explorer has it. Just about every other piece of software on the planet that stores passwords has it. Your software doesn't have it.

You're spending more time arguing why it's not your concern than it would actually take to implement it to make people happy. That is the telling action about your feelings towards the users of your software.

User avatar
botg
Site Admin
Posts: 35565
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: updated filezilla and then server got compromised

#20 Post by botg » 2013-09-19 06:09

So why are you using cheap glass that breaks with the first stone?

ftanner
503 Bad sequence of commands
Posts: 20
Joined: 2013-08-07 16:17
First name: Frank
Last name: Tanner

Re: updated filezilla and then server got compromised

#21 Post by ftanner » 2013-09-19 15:45

botg wrote:So why are you using cheap glass that breaks with the first stone?
Really??

That's your answer??

I'm done with this conversation. You're being willfully stupid. I say stupid rather than ignorant because ignorance can be solved, usually by education. Stupid is intentional.

You *KNOW* that people don't like you saving the password file in an unencrypted format. You *KNOW* that it is trivial to solve that. You *KNOW* that other Open Source and Closed Source projects don't save their password files in an unencrypted format. Yet you intentionally *CHOOSE* to do nothing about it.

That, my friend, is the textbook definition of stupid.

User avatar
botg
Site Admin
Posts: 35565
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: updated filezilla and then server got compromised

#22 Post by botg » 2013-09-20 06:20

You *KNOW* that people don't like you saving the password file in an unencrypted format
I know, that's why you can disable saving of passwords in the settings dialog of FileZilla.

Post Reply