7 ms·
Filezilla blocks download for EU users
- pseudotrash 3y agoTLDR: In protest of the Cyber Resilience Act. FOSS projects have been raising alarms for a while. Today ITRE voted. Now it's game over for FOSS in Europe
- Dah00n 3y agoNo it isn't. These kind of laws and doom saying is repeated again and again. Wait a week and see. Nothing changed.
- rs999gti 3y ago> it's game over for FOSS in Europe You mean the European Union. The rest of the world will be fine.
- jeroenhd 3y agoThe CRA isn't law yet. Also, I don't see the problem myself: > In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable. In the context of software, a commercial activity might be characterized not only by charging a price for a product, but also by charging a price for technical support services, by providing a software platform through which the manufacturer monetises other services, or by the use of personal data for reasons other than exclusively for improving the security, compatibility or interoperability of the software. I'm not sure where people get the idea that donations are considered commercial activity. Support subscriptions and such make you liable (but I don't see why that would be a problem). Ubuntus's Snap store is a platform through which the manufacturer monetises other services. Half open source (i.e. FileZilla Pro) also counts as closed source software, of course. Most of the protests seem to come from people who operate a business that sells their open source software and wants to remain off the hook to get an advantage over their closed source competition.
- 2Gkashmiri 3y agois there a explainer of what the legislation is supposed to do and how does it harm foss? i have had trouble with understanding the push for EVERYONE doing https even in localhost because "security". boo. i live in a place where by law ISPs need to have DPI. they can access any communication regardless of SSL or https or anything in between so why should i bother with the added nonsense of "much security" when it is not supposed to even work? i understand there are attempts to make https to be as transparent when it works but why should that not be restricted to banking transactions or login pages and payment links? again, DPI. now this cyber resillience act which i am assuming wants to "security". what kind of security?
- pseudotrash 3y agoThis post by the The Apache Software Foundation is fairly complete: > And what makes matters worse is that the type of open source organizations most affected are also exactly those that, today, tend to have very mature security processes, with vulnerabilities getting triaged, fixed, and disclosed responsibly with CVEs to match. While it generally is further downstream; with the companies that place the product on the market — that the CRA needs to drive significant improvement. It now risks doing the reverse. But all organizations (ECLIPSE, LINUX, ...) raised alarms https://news.apache.org/foundation/entry/save-open-source-the-impending-tragedy-of-the-cyber-resilience-act https://news.apache.org/foundation/entry/save-open-source-th... Edit: https://nitter.kavin.rocks/search?f=tweets&q=cyber+Resilience+act&since=&until=&near= https://nitter.kavin.rocks/search?f=tweets&q=cyber+Resilienc...
- raverbashing 3y agoVery good description, and if the protections from OSS are not enough I expect more noise in the next weeks/months > There is of course an elephant in the room: the well-oiled mechanism that “The internet treats censorship as a malfunction and routes around it” (John Perry Barlow). The parliament position reads: > Only free and open-source software made available on the market in the course of a commercial activity should be covered by this Regulation > Whether a free and open- source product has been made available as part of a commercial activity should be assessed on a product-by-product basis, looking at both the development model and the supply phase of the free and open-source product with digital elements. > (10a) For example, a fully decentralised development model, where no single commercial entity exercises control over what is accepted into the project’s code base, should be taken as an indication that the product has been developed in a non-commercial setting.
- kevincox 3y agoI see that the Linux Foundation has posted a blog opposed to this. I wonder if they could single-handedly destroy this legislation by revoking the license for Linux in the EU. Of course this would be difficult because existing contributions can't be relicensed. But they could maybe start accepting new patches with a non-Eurpoe license. Or does the GPL prevent this as they are building on GPL code and need the same license? I double the EU would be ok with running on outdated Linux or trying to maintain their own.
- perceptronas 3y agoMy gut feeling is that EU wouldn't cave and would be OK on running on outdated Linux. There is really no citizen influence on block wide policies so I doubt a protests would work or that any majority of non-technical people would care.
- peddling-brink 3y agoMicrosoft would be thrilled.
- joshuaissac 3y agoThey cannot revoke the licence under the GPL. If new patches are under a non-Europe licence, then they cannot be combined and redistributed with the existing GPLv2 codebase. There is a provision in section 8 of the GPLv2 that allows excluding certain countries, but it can only be activated in the face of copyright or patent restrictions on the distribution of the software. IANAL, but one approach to activate this provision might be to implement a patented technique within the kernel, for which the patent licence only allows implementations outside the EU.
- veave 3y ago[flagged]
- Proven 3y ago[dead]
- davidebaldini 3y agoRegulations become unpalatable when they hit too close to home.
- gndk 3y agoI just downloaded an update through my already installed client. I'm in Germany, so obviously the block is not working.
- orangepurple 3y agoFile sharing program with dwindling userbase embargoes itself in EU political protest; fails
- petre 3y agoWe'll just get it off torrents with malware embedded. Very cyber resilient.
- justinclift 3y agoThat is incredibly rich coming from __FileZilla__, one of the few OSS projects that accepts money from malware makers to catch out unwary windows users. I wonder if they're actually more worried about having the EU go after them legally if some EU member loses data or money directly because of that malware?
- jdboyd 3y agoIt may be rich coming from them, but it doesn't mean they are wrong in this case.
- TedDoesntTalk 3y ago> money from malware makers to catch out unwary windows users. As an active user of FileZilla, can you elaborate on this? Any links or sources where I can read about it? Thank you.
- speps 3y agoThe default download link installs malware/adware alongside FileZilla. If you go to the actual downloads page, you get the vanilla version.
- this_steve_j 3y agoIt was adware and not malware, from what I can tell.
- justinclift 3y agoJust do a Google search for FileZilla and malware. It's been an issue for many years now, and lots of people have written about it.
- this_steve_j 3y agoThere was a thread on the old FileZilla support forum[1] where the developer describes the adware included in the installer offered to unwary downloaders, which sounds a but shady but is probably not malware. A lot of AV engines use crowdsourced classifiers like virustotal to flag “potentially unwanted applications (PUA)” as a threat and quarantine, but the term “malware” is a category reserved for destructive or criminal application behavior. I’m not convinced that is what was or is bundled with “sponsored” Filezilla installers. At some point the bundled adware was apparently something called OpenCandy related to ask.com, and the developer of FileZilla is alleged to have concealed rather than disclosed it.[2] The adware-free installer was/is reported to be available for download freely on the same site, but for the extra browsing effort. [1] https://web.archive.org/web/20190526065704/https://forum.filezilla-project.org/viewtopic.php?f=2&t=48441 https://web.archive.org/web/20190526065704/https://forum.fil... [2] https://malwaretips.com/threads/sourceforge-net-adds-adware-installers-provided-by-ask-com.17247/ https://malwaretips.com/threads/sourceforge-net-adds-adware-...
- antiloper 3y ago[flagged]
- aredox 3y agoAre you talking about the EU or all the GAFA you all work for/with/dream to join/exit to?
- perceptronas 3y agoDidn't we read about EU trying to put backdoors in E2E messaging apps like two months ago? I think parent comment has at least some truth to the claims
- aredox 3y agoHa, you mean the backdoors (and frontdoors) the GAFA and many other top players in the web ecosystem already have everywhere, so much that the US government just has to buy commercially available data to spy on its citizens - without having to change laws to do it by itself?
- pwdisswordfishc 3y agoYou’re confusing EU for Facebook.
- deleted 3y ago[deleted]
- rs999gti 3y ago> The CRA goes against this principle by imposing unavoidable liability on producers of free software, requiring them to make their development, testing, and documentation activities much harder and complex. If the EU wants this, they should use part of their budget to fund it. This is the same argument for businesses using FOSS, if you want support, pay for it, otherwise you get what you pay for.
- tough 3y agoEU does fund a lot of FOSS
- psychphysic 3y agoWell they're not wrong, despite being quite questionable themselves.
- _8j50 3y agoThe filezilla installer will install adware on a windows PC if you leave the default options (as of 1-2yrs ago)
- gumballindie 3y agoUnpopular thought, but eu’s CRA may reduce open source software availability, increasing scarcity and thus leading to a potential indie market. Software is one of the few industries where people have freely made the product of their labor available in large quantity, dramatically reducing their prospect of earning independently just by writing software. The more indie software makers the more proper engineering can be done - as opposed to simply giving it for free to corporations.