10 ms·
Mozilla will remove FTP support in Firefox
- yingw787 7y agoAre there security issues with FTP, or do people just not use it enough because HTTP supplants it? I haven't used FTP in a while to download files.
- liquidify 7y agoThe article indicates that it is insecure.... "The main reason why FTP is being removed is that it is considered insecure but Google's decision to remove support from Chrome certainly played a role in Mozilla's decision to remove support as well."
- yingw787 7y agoDamn. I should be downvoted, that's pretty blantant i-didnt-read-the-article. Thanks for the clarification.
- tyingq 7y agoPlaintext passwords over the net. Also, it's somewhat painful for NAT because it opens up a second port that isn't a named one, the client sends that port number to the server, then the server opens a connection to the client.
- duskwuff 7y agoThat's for active FTP, which basically nobody uses anymore (since it's incompatible with most firewalls). Most clients use the passive FTP extension, in which the server sends the client a host/port pair to connect to for the data connection. Still painful, but slightly less so.
- okraszo 7y agoFor sure it is unencrypted, so it is vulnerable to man-in-the-middle attacks.
- karatestomp 7y agoftps? Not to be confused with SFTP.
- sabujp 7y agoftp over ssl
- weare138 7y agoI'm sure the majority of people that still use FTP aren't relying on a browser for access but people still use it. Why not just deprecate standard FTP and only support FTPS and SFTP?
- duskwuff 7y agoBecause that'd amount to the same result as removing FTP. The "installed base" of web-accessible FTPS and SFTP resources is essentially zero, and that's unlikely to change -- if a web site was previously using FTP, they're probably going to move those resources to HTTP/S, not to another protocol which has limited browser support.
- weare138 7y ago> The "installed base" of web-accessible FTPS and SFTP resources is essentially zero Well that's true of SFTP, browsers don't support that protocol but I think they should. But FTP is still ubiquitous on the internet and most browsers like FF already support FTPS. To me it would make more sense to deprecate FTP like HTTP and warn users when their logging in over an insecure protocol than just kill the feature all together, especially if one of the primary reasons is because "Google did it". FTPS uses the same URI as FTP (ftp://). FTPS is common now, most people don't even realize they're using it. There are those of us that still need to deal with FTP and being able to click on a link in the browser rather than use a separate FTP client is just convenient. Just make it an optional feature and disable it by default.
- calvinmorrison 7y agoWell it reeks a bit because from the article "Mozilla could have opted for implementing support for secure FTP in Firefox; a bug was filed 19 years ago to introduce support for SFTP in Firefox but nothing ever came out of it."
- duskwuff 7y agoNever happened because there was no use case for it. FTP made some sense to have in a browser because it supported unauthenticated downloads. SFTP, as a protocol which runs over SSH, basically requires authentication. (You could conceivably set up an SSH server to allow authentication against a "guest" user, but that gives security folks the heebie-jeebies.) So it doesn't really make sense to link to an SFTP resource in a web context, making it very low value to support in a browser.
- calvinmorrison 7y agoThat is extremely common no? Ex: checking out as an anonymous git user?
- duskwuff 7y ago> That is extremely common no? Ex: checking out as an anonymous git user? That almost always happens over the git protocol or git+http, not git+ssh.
- philipov 7y agoThe only FTP I use these days is really SFTP
- layoutIfNeeded 7y agoLast I’ve checked SFTP was much slower than FTP unless you used the HPN-SSH patches. Is this still the case?
- Someone 7y agohttps://en.wikipedia.org/wiki/File_Transfer_Protocol#Security https://en.wikipedia.org/wiki/File_Transfer_Protocol#Securit... lists many issues. The worst is that FTP transmits user names and passwords in cleartext. Having said that: nowadays it isn’t uncommon to say “FTP server” for a server running SFTP, its secure replacement, so it isn’t clear to me what exactly is being removed from Firefox.
- duskwuff 7y agoFTP is FTP. SFTP is SFTP -- a protocol which runs over SSH -- and Firefox doesn't support that. It wouldn't really make sense for it to do so, either; SFTP more or less requires SSH authentication, making it a poor fit for a web browser. There is FTPS (FTP + SSL/TLS), which Mozilla might support -- but that's rather rare.
- jcranmer 7y agoThe entirety of changes to one of the files in the past 13 years is here: https://hg.mozilla.org/mozilla-central/log/tip/netwerk/streamconv/converters/ParseFTPList.cpp https://hg.mozilla.org/mozilla-central/log/tip/netwerk/strea... There's more changes on nsFtpConnectionThread.cpp: https://hg.mozilla.org/mozilla-central/log/tip/netwerk/protocol/ftp/nsFtpConnectionThread.cpp https://hg.mozilla.org/mozilla-central/log/tip/netwerk/proto... Looking at those changes, it's clear that there has been very little substantive modifications to the FTP code itself, as opposed to keeping up with style guide changes, mass renamings, and API changes. So either you believe this 15 year old code is really rock-solid, stable, high-quality code, or you believe that it's a massive pile of bugs and security holes that no one's examined too closely. I know which one I believe.
- saagarjha 7y agoPerhaps they should take the opportunity to rewrite it in Rust.
- jcranmer 7y agoIf I'm reading the telemetry correctly (https://mzl.la/3bq5oFZ https://mzl.la/3bq5oFZ), there are ~6k people who used FTP to download a file in the past week or so. That's not enough users to really justify spending manpower rewriting it.
- jovial_cavalier 7y agoWhy is this comment grey?
- rhencke 7y agoYour monitor is likely running low on black ink.
- liquidify 7y agoI'm curious as to how many people use FTP in the browser?
- charlesdaniels 7y agoI use it from time to time to download ISOs or source tarballs. It's handy not to have to use an external program for that.
- gregf 7y agoI never seen a distro that didn't have a http mirror for those things myself. Even the ones that offer ftp.debian.org for example are accessibly over http as well.
- charlesdaniels 7y agoAgreed. I can’t think of the last time I had to use FTP.
- im3w1l 7y agoFirmwares, drivers, distro isos, tarballs are traditionally distributed on (anonymous) ftp. Given that such downloads should be authenticated using ftp is non-ideal though, I guess.
- _jal 7y agoYeah, this. I suppose the closest substitute will be to configure directory listings at the http server, although I suspect UX people will get their hooks in to make it pretty instead of efficient. (Ever tried to find something specific but not currently promoted on Dell's site?)
- danudey 7y agoDell's site is a nightmare. Shopping for monitors has been one of the most inexplicably complex affairs I've ever seen. It also doesn't help that any link to their US site redirects to the dell.ca front page, making it extremely difficult to follow links from forums, google searches, etc.
- coribuci 7y agoOne more reason not to use firefox. Firefox became the younger brother of Chrome. Why they can't be independent and think for themselves ?
- preinheimer 7y agoSo what are you suggesting?
- codr7 7y agoFlagging a problem doesn't mean you're required to provide a solution. Mozilla has been cutting useful features from Firefox at an increasing rate, and there are no real alternatives out there. The whole point of having multiple implementations is that they are different, and Firefox is quickly turning into Chrome with a new logo just like Internet Explorer.
- wolco 7y agoHe is suggesting by removing this feature to keep pace with chrome firefox is acting as the younger brother or junior partner. Probably true in this case. I'm a little disapppinted but if I really cared I would fork the repo remove those changes and spend my life trying to manually keep things in sync. Or just use a different browser.
- Fiveplus 7y agoNo Gecko and no Chrome? I'm waiting for you to say we should all start using Brave. Please say it.
- coribuci 7y ago> No Gecko and no Chrome? I'm waiting for you to say we should all start using Brave. Please say it. To be honest i like Seamonkey :) Maybe i am too old.
- OptionX 7y agoLitteraly the only major player in the browser market thats not chromium based.
- getpolarized 7y agoI love discussions about browsers on Hacker News! They're amazing. Half the people ranting how some insanely complicated technical decision is going to ruin the world, the other half yelling at them that this is necessary, others ranting about how the vendor is evil for some reason, etc. Just lovely!
- Arubis 7y agoYou're going to love http://n-gate.com/ http://n-gate.com/.
- arkitaip 7y agoI can't believe they have a dysfunctional captcha (doesn't display a captcha at all). That's hilarious considering how critical n-gate is about useless tech.
- OptionX 7y ago1. Open comment section in a browser related topic. 2. Complains about the people discussing a browser related topic. 3. ???? 4. Profit
- seemslegit 7y agoNOOOOOOOOOOOOOO... yeah ok.
- kingpiss 7y agoI wasn't aware that was even a feature in Firefox. fun fact, Windows has a built in FTP client in Explorer. Just enter an FTP address into the address bar and then right click to login.
- bifrost 7y agoOh wow, thats really lame. I actually use that pretty regularly....
- Someone1234 7y agoJust map the URI to a real FTP client using the operating system.
- throw7 7y agoInsecure? Bullshit. They should remove http then. I'd respect them if they just said they're lazy and don't want to support the ftp protocol.
- Someone1234 7y ago> They should remove http then. They're working on it. It has and will continue to be deprecated with ever increasing security warnings. But the reason why FTP got pulled and HTTP hasn't is simply usage. The FTP client in browsers is terrible, and anyone using FTP professionally is using a better client (e.g. multiple connection modes, resume downloads, concurrent streams, etc) or has already migrated to FTPS or SFTP. FTP just adds attack surface and maintenance cost.
- wolco 7y agoYou probably don't realize many links you click are ftp links that will now be broken for you.
- Someone1234 7y agoI'd realize immediately since those links would be broken. I have had: network.ftp.enabled: false set since it was introduced in Firefox 60 (over a year ago). I've had a total of one link broken in that time.
- untog 7y agoThe great thing is we don’t need to guess about this! Firefox and Chrome have user telemetry showing that FTP is barely ever used.
- throw7 7y agoSo why aren't you arguing that firefox support migration to ftps or sftp?
- Someone1234 7y ago
- zzo38computer 7y agoI think FTP isn't a very good protocol anyways. HTTP and Gopher are better. (HTTP does support most of the features, including authentication, uploads, etc. The thing HTTP doesn't have is proper directory listings; I wrote a document suggesting how this could be done, calling it "httpdirlist" specification; it is a new MIME type, and then each record is a list of records (formatted like a list of HTTP headers) separated by blank lines.)
- Exmoor 7y agoI'm sorry, Gopher? Has anything outside of some incredibly archaic library system even used Gopher in the last 20 years? To me its one of those protocols that I only remember because I hope to use it to answer some trivia question someday. Right up there with Archie and Veronica.
- zzo38computer 7y agoYes; Gopher is still in use, although not much. You could probably find a few Gopher servers still in use (I have found a few). I have my own Gopher server, too.
- rolph 7y agothere are still FTP clients, and servers around. there is even an FTP indexer: https://www.securitynewspaper.com/2018/12/10/list-of-all-open-ftp-servers-in-the-world/ https://www.securitynewspaper.com/2018/12/10/list-of-all-ope... https://www.searchftps.net/ https://www.searchftps.net/
- RandyRanderson 7y agoI can see many tech ppl switching over to a chromium browser because they might possibly use ftp in the future and just want to install one browser. It's those ppl that install (or even know about) FF, generally. Other than a part time dev and some testing, it's hard to see the costs of supporting ftp. It's a string of decision-making like this that has made FF drop off the list of "supported" browsers in many organizations and may lead to a 2 engine Internet. This is bad for everyone, IMO. Mozilla board: Look at your browser share: you need to replace the management team immediately - we need FF.
- untog 7y agoChrome is also deprecating FTP so I don’t think that’ll happen. Plus Mozilla isn’t an organisation the size of Google. They have to prioritise what they’re going to support and it makes total sense to ditch FTP support. I’m a professional web developer and I’d never choose which browser I use based on whether it supports FTP. I barely ever use it, and when I do I just use FileZilla or something similar that makes much more sense for FTP.
- RandyRanderson 7y agoRe: chrome right but this would give ppl at least one reason to use FF. Mozilla just does a browser (at least they should only do one) so 500MM USD /year or whatever their budget is should suffice, right? [0] I would be careful with FZ: https://www.reddit.com/r/technology/comments/8pdubg/filezilla_contains_malware_in_latest_version/ https://www.reddit.com/r/technology/comments/8pdubg/filezill... [0] https://www.computerworld.com/article/3322912/mozillas-2017-expenses-grew-twice-the-rate-of-revenue.html https://www.computerworld.com/article/3322912/mozillas-2017-...
- JohnTHaller 7y agoThis was an old version of FileZilla from 2016 from a relatively short-lived experiment when a previous incarnation of SourceForge was helping open source projects 'monetize'. There was no malware and no infection. It was an online downloader with bundleware. FileZilla is solid software and every version has been clean. I know because I scan every release in dozens of antivirus engines via VirusTotal as part of packaging FileZilla Portable for PortableApps.com.