Always allow insecure plain FTP for this server? - Does nothing

Need help with FileZilla Client? Something does not work as expected? In this forum you may find an answer.

Moderator: Project members

Locked
Message
Author
flagpole
425 Can't open data connection
Posts: 46
Joined: 2013-07-30 14:45
First name: nigel
Last name: coldwell

Always allow insecure plain FTP for this server? - Does nothing

#1 Post by flagpole » 2019-07-17 09:00

Image1.png
Image1.png (4.72 KiB) Viewed 9349 times
Checking this option does nothing. It asks the same question next time you connect regardless. The server in question is on my lan as you can see.

Do I need to delete and re-add the sever? Is it a bug?
Last edited by flagpole on 2019-07-17 15:01, edited 1 time in total.

User avatar
botg
Site Admin
Posts: 35552
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: Always allow insecure plain FTP for this server? - Does nothing

#2 Post by botg » 2019-07-17 11:23

It's a bug.

Probably for the better though, the more annoying plaintext FTP becomes, the faster people switch to FTP over TLS.

flagpole
425 Can't open data connection
Posts: 46
Joined: 2013-07-30 14:45
First name: nigel
Last name: coldwell

Re: Always allow insecure plain FTP for this server? - Does nothing

#3 Post by flagpole » 2019-07-17 13:48

Is it going to be fixed?

Like i say it's on my lan, it not externally facing anywhere.

Maybe it could be an undocumented feature requiring a manual edit of the xml file.

User avatar
botg
Site Admin
Posts: 35552
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: Always allow insecure plain FTP for this server? - Does nothing

#4 Post by botg » 2019-07-17 15:24

Even though the server is in your LAN, there's no reason not to enable TLS on it.

flagpole
425 Can't open data connection
Posts: 46
Joined: 2013-07-30 14:45
First name: nigel
Last name: coldwell

Re: Always allow insecure plain FTP for this server? - Does nothing

#5 Post by flagpole » 2019-07-17 15:37

It's a PVR. I can't enable TLS on it.

User avatar
boco
Contributor
Posts: 26930
Joined: 2006-05-01 03:28
Location: Germany

Re: Always allow insecure plain FTP for this server? - Does nothing

#6 Post by boco » 2019-07-17 19:02

@botg: I'm with the users, here. There are simply cases where FTP over TLS cannot be enabled, even if desired. Not only in case of embedded things on read-only media, but also in the case of too weak hardware. TLS needs resources (CPU time and memory for encryption) and would slow down such devices (like PVR etc.) to a crawl.

I know that you are planning to do away with plain FTP, altogether, however, there should be exceptions (with warning):

1. LAN-only servers, to cover local embedded devices. Connection over public nets should be disallowed, OTOH.
2. Anonymous connections to public servers, to cover simple file downloads from public drop-off servers. Uploads and non-anonymous connections should be blocked, for the sake of security.
No support requests over PM! You will NOT get any reply!!!
FTP connection problems? Please read Network Configuration.
FileZilla connection test: https://filezilla-project.org/conntest.php
FileZilla Pro support: https://customerforum.fileZilla-project.org

User avatar
botg
Site Admin
Posts: 35552
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: Always allow insecure plain FTP for this server? - Does nothing

#7 Post by botg » 2019-07-18 07:17

flagpole wrote:Is it going to be fixed?
"Going to" only if you travel back in time. It was already fixed in the repository on the 5th of July.
flagpole wrote:It's a PVR. I can't enable TLS on it.
What date has the vendor agreed upon by with it will release a firmware update adding TLS support?
boco wrote:in the case of too weak hardware.
You buy new hardware.
boco wrote:TLS needs resources (CPU time and memory for encryption)
Just a few KB of memory. And modern CPUs all have hardware acceleration for AES, even in the embedded world.

flagpole
425 Can't open data connection
Posts: 46
Joined: 2013-07-30 14:45
First name: nigel
Last name: coldwell

Re: Always allow insecure plain FTP for this server? - Does nothing

#8 Post by flagpole » 2019-07-18 08:31

You know the problem here. Lack of empathy. You can not imagine that anyone else's use case is differnt from yours.

What will happen if you disable support for legacy protcols? People will continue to use the old version which you will not be able to patch.

This reminds me of when you refused for years to to add any kind of encryption to the passwords stored in filezilla.

As for when the manufacturer plans to add support for TLS, they don't which I suspect you knew. You were making rhetorical point, the nature of which escapes me.

User avatar
botg
Site Admin
Posts: 35552
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: Always allow insecure plain FTP for this server? - Does nothing

#9 Post by botg » 2019-07-18 10:27

My whole point is this: Don't be lazy, don't be cheap. Get hard- and software that is secure and configure it accordingly.

User avatar
boco
Contributor
Posts: 26930
Joined: 2006-05-01 03:28
Location: Germany

Re: Always allow insecure plain FTP for this server? - Does nothing

#10 Post by boco » 2019-07-18 20:11

Obviously, we don't live in the same worlds.
No support requests over PM! You will NOT get any reply!!!
FTP connection problems? Please read Network Configuration.
FileZilla connection test: https://filezilla-project.org/conntest.php
FileZilla Pro support: https://customerforum.fileZilla-project.org

User avatar
botg
Site Admin
Posts: 35552
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: Always allow insecure plain FTP for this server? - Does nothing

#11 Post by botg » 2019-07-18 20:56

Are you forced by law to use outdated hard- or software?

User avatar
boco
Contributor
Posts: 26930
Joined: 2006-05-01 03:28
Location: Germany

Re: Always allow insecure plain FTP for this server? - Does nothing

#12 Post by boco » 2019-07-18 21:35

No, just by wallet.
No support requests over PM! You will NOT get any reply!!!
FTP connection problems? Please read Network Configuration.
FileZilla connection test: https://filezilla-project.org/conntest.php
FileZilla Pro support: https://customerforum.fileZilla-project.org

Locked