Always allow insecure plain FTP for this server? - Does nothing

Need help with FileZilla Client? Something does not work as expected? In this forum you may find an answer.

Moderator: Project members

Post Reply
Message
Author
flagpole
450 Internal Error
Posts: 37
Joined: 2013-07-30 14:45
First name: nigel
Last name: coldwell

Always allow insecure plain FTP for this server? - Does nothing

#1 Post by flagpole » 2019-07-17 09:00

Image1.png
Image1.png (4.72 KiB) Viewed 577 times
Checking this option does nothing. It asks the same question next time you connect regardless. The server in question is on my lan as you can see.

Do I need to delete and re-add the sever? Is it a bug?
Last edited by flagpole on 2019-07-17 15:01, edited 1 time in total.

User avatar
botg
Site Admin
Posts: 32267
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse
Contact:

Re: Always allow insecure plain FTP for this server? - Does nothing

#2 Post by botg » 2019-07-17 11:23

It's a bug.

Probably for the better though, the more annoying plaintext FTP becomes, the faster people switch to FTP over TLS.

flagpole
450 Internal Error
Posts: 37
Joined: 2013-07-30 14:45
First name: nigel
Last name: coldwell

Re: Always allow insecure plain FTP for this server? - Does nothing

#3 Post by flagpole » 2019-07-17 13:48

Is it going to be fixed?

Like i say it's on my lan, it not externally facing anywhere.

Maybe it could be an undocumented feature requiring a manual edit of the xml file.

User avatar
botg
Site Admin
Posts: 32267
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse
Contact:

Re: Always allow insecure plain FTP for this server? - Does nothing

#4 Post by botg » 2019-07-17 15:24

Even though the server is in your LAN, there's no reason not to enable TLS on it.

flagpole
450 Internal Error
Posts: 37
Joined: 2013-07-30 14:45
First name: nigel
Last name: coldwell

Re: Always allow insecure plain FTP for this server? - Does nothing

#5 Post by flagpole » 2019-07-17 15:37

It's a PVR. I can't enable TLS on it.

User avatar
boco
Contributor
Posts: 24596
Joined: 2006-05-01 03:28
Location: Germany

Re: Always allow insecure plain FTP for this server? - Does nothing

#6 Post by boco » 2019-07-17 19:02

@botg: I'm with the users, here. There are simply cases where FTP over TLS cannot be enabled, even if desired. Not only in case of embedded things on read-only media, but also in the case of too weak hardware. TLS needs resources (CPU time and memory for encryption) and would slow down such devices (like PVR etc.) to a crawl.

I know that you are planning to do away with plain FTP, altogether, however, there should be exceptions (with warning):

1. LAN-only servers, to cover local embedded devices. Connection over public nets should be disallowed, OTOH.
2. Anonymous connections to public servers, to cover simple file downloads from public drop-off servers. Uploads and non-anonymous connections should be blocked, for the sake of security.
### BEGIN SIGNATURE BLOCK ###
No support requests per PM! You will NOT get any reply!!!
FTP connection problems? Do yourself a favor and read Network Configuration.
All FileZilla products fully support IPv6. http://worldipv6launch.org
### END SIGNATURE BLOCK ###

User avatar
botg
Site Admin
Posts: 32267
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse
Contact:

Re: Always allow insecure plain FTP for this server? - Does nothing

#7 Post by botg » 2019-07-18 07:17

flagpole wrote:Is it going to be fixed?
"Going to" only if you travel back in time. It was already fixed in the repository on the 5th of July.
flagpole wrote:It's a PVR. I can't enable TLS on it.
What date has the vendor agreed upon by with it will release a firmware update adding TLS support?
boco wrote:in the case of too weak hardware.
You buy new hardware.
boco wrote:TLS needs resources (CPU time and memory for encryption)
Just a few KB of memory. And modern CPUs all have hardware acceleration for AES, even in the embedded world.

flagpole
450 Internal Error
Posts: 37
Joined: 2013-07-30 14:45
First name: nigel
Last name: coldwell

Re: Always allow insecure plain FTP for this server? - Does nothing

#8 Post by flagpole » 2019-07-18 08:31

You know the problem here. Lack of empathy. You can not imagine that anyone else's use case is differnt from yours.

What will happen if you disable support for legacy protcols? People will continue to use the old version which you will not be able to patch.

This reminds me of when you refused for years to to add any kind of encryption to the passwords stored in filezilla.

As for when the manufacturer plans to add support for TLS, they don't which I suspect you knew. You were making rhetorical point, the nature of which escapes me.

User avatar
botg
Site Admin
Posts: 32267
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse
Contact:

Re: Always allow insecure plain FTP for this server? - Does nothing

#9 Post by botg » 2019-07-18 10:27

My whole point is this: Don't be lazy, don't be cheap. Get hard- and software that is secure and configure it accordingly.

User avatar
boco
Contributor
Posts: 24596
Joined: 2006-05-01 03:28
Location: Germany

Re: Always allow insecure plain FTP for this server? - Does nothing

#10 Post by boco » 2019-07-18 20:11

Obviously, we don't live in the same worlds.
### BEGIN SIGNATURE BLOCK ###
No support requests per PM! You will NOT get any reply!!!
FTP connection problems? Do yourself a favor and read Network Configuration.
All FileZilla products fully support IPv6. http://worldipv6launch.org
### END SIGNATURE BLOCK ###

User avatar
botg
Site Admin
Posts: 32267
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse
Contact:

Re: Always allow insecure plain FTP for this server? - Does nothing

#11 Post by botg » 2019-07-18 20:56

Are you forced by law to use outdated hard- or software?

User avatar
boco
Contributor
Posts: 24596
Joined: 2006-05-01 03:28
Location: Germany

Re: Always allow insecure plain FTP for this server? - Does nothing

#12 Post by boco » 2019-07-18 21:35

No, just by wallet.
### BEGIN SIGNATURE BLOCK ###
No support requests per PM! You will NOT get any reply!!!
FTP connection problems? Do yourself a favor and read Network Configuration.
All FileZilla products fully support IPv6. http://worldipv6launch.org
### END SIGNATURE BLOCK ###

Post Reply