xeon wrote:
While I disagree that DES-CBC3-SHA is a "weak" cipher I agree with botg's end decision to remove support for it.
This is mostly for performance reasons 3DES is one of the slowest ciphers around and does nothing but waste cpu cycles compared to superior alternatives.
My preference is always to use RC4-SHA or when possible ECDHE-RSA-RC4-SHA however not much supports ECDHE at the moment and vsftpd doesn't even support regular DHE to begin with much less ECDHE.
Using RC4-SHA in my opinion is the best choice as you get way better performance than any other cipher and it's not CBC based like everything else all while providing plenty enough protection and in some cases even more than alternatives due to it not being vulnerable to CBC based attacks.
This is a silly reason to agree with removing support for the cipher from the client. As long as you have the choice to choose your ciphers, why should you care what ciphers other users of the client prefer? Why do you agree with forcing users to either never upgrade or switch clients if they don't have control over the FTP servers that they are connecting to? What possible benefit does this provide to you personally?
As has been stated several times, this move seems to serve no purpose other than to frustrate users to no end when they cant connect to servers they had been able to connect to forever with this client.
If you want to change behavior, change the default. Don't remove all of the features that you don't like but which others find useful. The code already existed to support this. It would seem to be very easy to implement a checkbox to allow for its continued support while removing it from the program's default installation.
But I guess it's a free program so you can choose to do whatever you like. The irony of that donate button sitting in the top right of the screen is, however, most striking now; and I will be sure to never be fooled into clicking on it again after seeing the way all of the users are ignored in this way. "Yes, please donate to use so we can continue to code our own pet projects without regard for you, the one donating."