unable to prevent 'new version available' popup

Need help with FileZilla Client? Something does not work as expected? In this forum you may find an answer.

Moderator: Project members

Message
Author
User avatar
botg
Site Admin
Posts: 35492
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: unable to prevent 'new version available' popup

#16 Post by botg » 2021-12-01 09:09

Updating doesn't even take 10 seconds. Surely you can spend 10 seconds once per month. Have a sip of coffee/tee/beer/cowjuice while it updates.

User avatar
boco
Contributor
Posts: 26899
Joined: 2006-05-01 03:28
Location: Germany

Re: unable to prevent 'new version available' popup

#17 Post by boco » 2021-12-02 01:01

botg wrote:
2021-12-01 09:09
cowjuice
It's "udder liqueur", you cretin. :mrgreen: :mrgreen: :mrgreen:
### BEGIN SIGNATURE BLOCK ###
No support requests per PM! You will NOT get any reply!!!
FTP connection problems? Please do yourself a favor and read Network Configuration.
FileZilla connection test: https://filezilla-project.org/conntest.php
### END SIGNATURE BLOCK ###

Passant
504 Command not implemented
Posts: 6
Joined: 2021-12-27 11:47

Re: unable to prevent 'new version available' popup

#18 Post by Passant » 2021-12-27 12:03

I just created an account to give my +1 for @Ventures opinion. That popup is annoying.

Uh... and there is one other thing to metion:
Dear bocos and botgs out there, if people start programming autohotkey scrips to make filezilla useable for them, it may be worth considering to make that "popup feature" optional.

Lets copy that AHK code to my running background script.
Cheers :smoke:

User avatar
botg
Site Admin
Posts: 35492
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: unable to prevent 'new version available' popup

#19 Post by botg » 2021-12-27 14:34

You need to update FileZilla. Running outdated software is a security risk.

Passant
504 Command not implemented
Posts: 6
Joined: 2021-12-27 11:47

Re: unable to prevent 'new version available' popup

#20 Post by Passant » 2022-01-01 20:18

I can not see any risk, using a older filezilla version.
Where should be the entry gate for the exploit?

Can you please tell me a use case, how a pontentially weakness could be utilized to run harmful code?

User avatar
botg
Site Admin
Posts: 35492
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: unable to prevent 'new version available' popup

#21 Post by botg » 2022-01-03 11:40

Do you trust that 100% of the data you receive over the network is benevolent?

Processing any untrusted data poses a risk. Attackers have ample time analyzing outdated software for potential vulnerabilities.

Passant
504 Command not implemented
Posts: 6
Joined: 2021-12-27 11:47

Re: unable to prevent 'new version available' popup

#22 Post by Passant » 2022-01-14 17:38

Do you trust that 100% of the data you receive over the network is benevolent?
Processing any untrusted data poses a risk.
That is true. But how does an updated version of FileZilla increase data trustworthiness in any way?
FileZilla does not have the ability to detect, if a transfered file is malicious or not. So every file transfered by an old FileZilla version is as trustworthy as one transfered by an updated FileZilla version.
I may be thumb, but I see absolutely no reason to update here.

- - -
Attackers have ample time analyzing outdated software for potential vulnerabilities.
Yes, they have. But it is informative, that even a very experienced developer can not give us any use case of how they attacked an outdated FileZilla installation in the past.
To be honest: I am realy still waiting to see any rational reason to update (and and therefore a reason to nudge users by that popup).

Passant
504 Command not implemented
Posts: 6
Joined: 2021-12-27 11:47

Re: unable to prevent 'new version available' popup

#23 Post by Passant » 2022-01-20 12:16

No answer?

⠀⠀⠀⠀⠀⠀⠀Hm....
https://abload.de/img/meme-faces-png-free-fxakjg.png

Some weird people could think, there are other reasons than providing security for your absolute will to bring updated code on users computers.

User avatar
botg
Site Admin
Posts: 35492
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: unable to prevent 'new version available' popup

#24 Post by botg » 2022-01-20 13:42

What is there to answer? Just update. Updates bring fixes to bugs. Many classes of bugs are potential security vulnerabilities. Not updating leaves you vulnerable. Simple as that.

Update good, old version bad.

Passant
504 Command not implemented
Posts: 6
Joined: 2021-12-27 11:47

Re: unable to prevent 'new version available' popup

#25 Post by Passant » 2022-01-28 02:03

  1. Why did you disable the image in my last post?
    A small image of a thinking person is to offensive for you?
    Is it your daily business to alter other peoples postings to make them the way you like them?
    By the way, that does not increase your authenticity...
    ⠀⠀⠀⠀⠀⠀⠀Hm....
    https://abload.de/img/meme-faces-png-free-fxakjg.png
  2. Maybe you do not remember all the postings in this thread. So let me summarize them for you: No one had a problem with any bug. So your answer
    Updates bring fixes to bugs.
    is simply off-topic and - sorry - useless blabla. The only bug imho, is that annoying dialog.

  3. I know: repeating the same argument again and again in slightly other words is a legit way to muzzle an opponent. What do I mean? Do you see any similaritys between this both postings of yours?
    Many classes of bugs are potential security vulnerabilities.
    Attackers have ample time analyzing outdated software for potential vulnerabilities.
    I could also simply repeat my answer to that, but I hope you do not expect me to have a conversation on the same level as you, don't you? So let me change the way we talk: Dear Tim, please! Please give us one example of how an outdated FileZilla installation was attacked in the past. Seriously. Only one. And I really please you to do so.


PS. I like to make things correctly, so I save the complete thread every time after a new posting of mine as a mhtml-file and additionally as a PDF. So I can see if changes are made to any posting. And yes, I know how to use Beyod Compare.
Last edited by boco on 2022-01-28 03:17, edited 2 times in total.
Reason: Please don't link to external sites. That's advertising and not allowed here.

User avatar
botg
Site Admin
Posts: 35492
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: unable to prevent 'new version available' popup

#26 Post by botg » 2022-01-28 11:26

1) Protecting user privacy. No external auto-loaded content.
2) Most users don't realize they have problems with bugs, until they experience a bug. Updating ensures they never experience the known bugs in the first place. Car analogy: If the braking fluid in your car is worn down, you won't notice it until you have to make an emergency brake and then cannot stop in time (crash). So you exchange (update) the fluid regularly just in case.
3) Funny, I was thinking the same, I have to refute the same claims over and over again.

Passant
504 Command not implemented
Posts: 6
Joined: 2021-12-27 11:47

Re: unable to prevent 'new version available' popup

#27 Post by Passant » 2022-01-28 16:38

  1. OK.
  2. Nice comparison, but off topic. If users who opted out "automatic update checks" stumble on bugs, they can simply update.
  3. You did not "refute" anything.
By the way:
Please don't link to external sites. That's advertising and not allowed here.
Is a bit of schizophrenic, because you yourself link to external sites from time to time. For example here, here and here. But it is your forum and rules only seeem to apply to others, not yourself.

I will leave the conversation at this point, because there is no will to listen to the people using FileZilla. And there is no real conversation anymore as you also mentioned before.
At the end, I want to say one thing: Thank you and your team for creating and maintaining FileZilla. You spend a lot of time in this project and I appreciate that. Stay healthy.

User avatar
boco
Contributor
Posts: 26899
Joined: 2006-05-01 03:28
Location: Germany

Re: unable to prevent 'new version available' popup

#28 Post by boco » 2022-01-29 02:56

All links from us are on-topic. They apply to the questions asked. botg linked to Apple support and letsencrypt.org, a certification provider service that is even used by FileZilla Server directly. I linked to Wikipedia for an explanation. What a crime. I won't post clickable links to questionable or commercial sites, they are only plaintext, in this case.

You linked to Beyond Compare, a commercial product's site. They sell the product and they advertise it. You are therefore not allowed, by the forum TOS (you had to agree to them at time of registration), to link to such sites, as that is advertising the product. Stating the product's name is OK, and every user with at least half a brain and access to a search engine will be able easily find it. The rest doesn't need it.
### BEGIN SIGNATURE BLOCK ###
No support requests per PM! You will NOT get any reply!!!
FTP connection problems? Please do yourself a favor and read Network Configuration.
FileZilla connection test: https://filezilla-project.org/conntest.php
### END SIGNATURE BLOCK ###

User avatar
botg
Site Admin
Posts: 35492
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: unable to prevent 'new version available' popup

#29 Post by botg » 2022-01-31 12:10

Just update. If you don't want to update, that's fine as well, but don't complain to us if you don't like the consequences, such as the update dialog showing up. Ending this pointless discussion.

Locked