Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > alt.comp.software.firefox > #398 > unrolled thread
| Started by | Michael Trew <mt999999@ymail.com> |
|---|---|
| First post | 2021-04-27 23:29 -0400 |
| Last post | 2021-04-27 23:26 -0500 |
| Articles | 20 on this page of 58 — 19 participants |
Back to article view | Back to alt.comp.software.firefox
Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-27 23:29 -0400
Re: Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-27 23:30 -0400
Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-27 23:27 -0500
Re: Firefox ESR Andy Burns <usenet@andyburns.uk> - 2021-04-28 07:13 +0100
Re: Firefox ESR Andy Burns <usenet@andyburns.uk> - 2021-04-28 07:17 +0100
Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-28 02:01 -0500
Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-28 02:03 -0500
Firefox ESR Dave <dave@triffid.co.uk> - 2021-04-28 08:57 +0100
Re: Firefox ESR Andy Burns <usenet@andyburns.uk> - 2021-04-28 10:39 +0100
Firefox ESR Dave <dave@triffid.co.uk> - 2021-04-28 14:49 +0100
Re: Firefox ESR PietB <www.godfatherof.nl/@opt-in.invalid> - 2021-04-28 10:00 +0200
Re: Firefox ESR "J. P. Gilliver (John)" <G6JPG@255soft.uk> - 2021-04-28 18:00 +0100
Re: Firefox ESR PietB <www.godfatherof.nl/@opt-in.invalid> - 2021-04-28 20:55 +0200
Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-28 14:50 -0500
Re: Firefox ESR Dave Royal<dave@dave123royal.com> - 2021-04-28 20:46 +0000
Re: Firefox ESR "J. P. Gilliver (John)" <G6JPG@255soft.uk> - 2021-04-28 21:54 +0100
Re: Firefox ESR Eli the Bearded <*@eli.users.panix.com> - 2021-04-28 21:02 +0000
Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-29 00:12 -0500
Keywords header (was: Re: Firefox ESR) Eli the Bearded <*@eli.users.panix.com> - 2021-04-29 17:37 +0000
Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-06 05:52 -0500
Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-06 06:06 -0500
Re: Keywords header !@!.invalid (Ï) - 2021-05-06 14:39 +0100
Re: Keywords header "Adam H. Kerman" <ahk@chinet.com> - 2021-05-06 15:14 +0000
Re: Keywords header "J. P. Gilliver (John)" <G6JPG@255soft.uk> - 2021-05-06 18:04 +0100
Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-08 15:01 -0500
Re: Keywords header "Adam H. Kerman" <ahk@chinet.com> - 2021-05-08 21:08 +0000
Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-08 16:37 -0500
Re: Keywords header !@!.invalid (Ï) - 2021-05-08 22:52 +0100
Re: Keywords header Frank Slootweg <this@ddress.is.invalid> - 2021-05-06 17:49 +0000
Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-08 15:40 -0500
Re: Keywords header Miguel Tomar Nogueira <mnogueira@mail.telepac.pt> - 2021-05-09 05:58 +0000
Re: Keywords header Frank Slootweg <this@ddress.is.invalid> - 2021-05-09 17:24 +0000
Re: Keywords header Eli the Bearded <*@eli.users.panix.com> - 2021-05-06 18:11 +0000
Panix spammifying of submissions (was: Keywords header) VanguardLH <V@nguard.LH> - 2021-05-08 16:30 -0500
Re: Panix spammifying of submissions (was: Keywords header) danny burstein <dannyb@panix.com> - 2021-05-08 21:52 +0000
Re: Panix spammifying of submissions (was: Keywords header) Eli the Bearded <*@eli.users.panix.com> - 2021-05-10 02:34 +0000
Re: Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-28 13:52 -0400
Re: Firefox ESR Eli the Bearded <*@eli.users.panix.com> - 2021-04-28 18:29 +0000
Re: Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-28 23:26 -0400
Re: Firefox ESR Rich <rich@example.invalid> - 2021-04-29 12:52 +0000
Re: Firefox ESR Rich <rich@example.invalid> - 2021-04-29 12:45 +0000
Re: Firefox ESR "Adam H. Kerman" <ahk@chinet.com> - 2021-04-29 13:22 +0000
Re: Firefox ESR Rich <rich@example.invalid> - 2021-04-29 13:53 +0000
Re: Firefox ESR "Adam H. Kerman" <ahk@chinet.com> - 2021-04-29 18:32 +0000
Re: Firefox ESR Rich <rich@example.invalid> - 2021-04-29 20:31 +0000
Re: Firefox ESR "OldbieOne" <me@here.com> - 2021-05-03 14:17 -0400
Re: Firefox ESR PietB <www.godfatherof.nl/@opt-in.invalid> - 2021-05-08 16:58 +0200
Re: Firefox ESR "OldbieOne" <me@here.com> - 2021-05-19 10:52 -0400
Re: Firefox ESR Ant <ant@zimage.comANT> - 2021-05-19 09:10 -0700
Re: Firefox ESR "Adam H. Kerman" <ahk@chinet.com> - 2021-05-19 16:35 +0000
Re: Firefox ESR "OldbieOne" <me@here.com> - 2021-05-19 15:16 -0400
Re: Firefox ESR Job Bautista <jobbautista9@aol.com> - 2021-05-20 18:35 +0800
Re: Firefox ESR "OldbieOne" <me@here.com> - 2021-05-25 12:32 -0400
Re: Firefox ESR WaltS48 <schw01@invalid.net> - 2021-05-25 15:16 -0400
Re: Firefox ESR Miguel Tomar Nogueira <mnogueira@mail.telepac.pt> - 2021-05-09 06:18 +0000
Re: Firefox ESR chris@here.com - 2021-04-27 23:31 -0500
Re: Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-28 13:53 -0400
Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-27 23:26 -0500
Page 1 of 3 [1] 2 3 Next page →
| From | Michael Trew <mt999999@ymail.com> |
|---|---|
| Date | 2021-04-27 23:29 -0400 |
| Subject | Firefox ESR |
| Message-ID | <s6akrj$di4$8@dont-email.me> |
I'm on the firefox 78 ESR on Windows 7... any clue if this will be the last ESR for Win 7, or do you guys think they'll put another one out?
[toc] | [next] | [standalone]
| From | Michael Trew <mt999999@ymail.com> |
|---|---|
| Date | 2021-04-27 23:30 -0400 |
| Message-ID | <s6aksm$di4$9@dont-email.me> |
| In reply to | #398 |
On 4/27/2021 11:29 PM, Michael Trew wrote: > I'm on the firefox 78 ESR on Windows 7... any clue if this will be the > last ESR for Win 7, or do you guys think they'll put another one out? Not so sure that I even want to upgrade with the discontinuation of FTP, but I suppose I have other browsers on here.
[toc] | [prev] | [next] | [standalone]
| From | VanguardLH <V@nguard.LH> |
|---|---|
| Date | 2021-04-27 23:27 -0500 |
| Message-ID | <lzn6c3qs59j0$.dlg@v.nguard.lh> |
| In reply to | #399 |
Michael Trew <mt999999@ymail.com> wrote: > Michael Trew wrote: > >> I'm on the firefox 78 ESR on Windows 7... any clue if this will be >> the last ESR for Win 7, or do you guys think they'll put another one >> out? > > Not so sure that I even want to upgrade with the discontinuation of > FTP, but I suppose I have other browsers on here. There are plenty of free FTP clients available. Since you mentioned Windows, popular ones there are FileZilla and WinSCP. So, how often per year do you click on ftp:// hyperlinks in web pages?
[toc] | [prev] | [next] | [standalone]
| From | Andy Burns <usenet@andyburns.uk> |
|---|---|
| Date | 2021-04-28 07:13 +0100 |
| Message-ID | <iescohFiu10U1@mid.individual.net> |
| In reply to | #401 |
VanguardLH wrote: > Michael Trew wrote: > >> Not so sure that I even want to upgrade with the discontinuation of >> FTP > > There are plenty of free FTP clients available. Since you mentioned > Windows, popular ones there are FileZilla and WinSCP. Yep, I use both. > So, how often per year do you click on ftp:// hyperlinks in web pages? Launching filezilla for FTP URLs already works in firefox v80.
[toc] | [prev] | [next] | [standalone]
| From | Andy Burns <usenet@andyburns.uk> |
|---|---|
| Date | 2021-04-28 07:17 +0100 |
| Message-ID | <iesd09Fiu10U2@mid.individual.net> |
| In reply to | #403 |
Andy Burns wrote: > Launching filezilla for FTP URLs already works in firefox v80. Make that v88.
[toc] | [prev] | [next] | [standalone]
| From | VanguardLH <V@nguard.LH> |
|---|---|
| Date | 2021-04-28 02:01 -0500 |
| Message-ID | <et7xtzcq2ac3.dlg@v.nguard.lh> |
| In reply to | #403 |
Andy Burns <usenet@andyburns.uk> wrote: > VanguardLH wrote: > >> Michael Trew wrote: >> >>> Not so sure that I even want to upgrade with the discontinuation of >>> FTP >> >> There are plenty of free FTP clients available. Since you mentioned >> Windows, popular ones there are FileZilla and WinSCP. > > Yep, I use both. > >> So, how often per year do you click on ftp:// hyperlinks in web pages? > > Launching filezilla for FTP URLs already works in firefox v80. Yep, I changed the default from Prompt to select Filezilla. Firefox passes the FTP URL as an command-line argument to FileZilla. Makes it seamless to get ftp:// URLs in a web page shown in Firefox to open using a 3rd party FTP client.
[toc] | [prev] | [next] | [standalone]
| From | VanguardLH <V@nguard.LH> |
|---|---|
| Date | 2021-04-28 02:03 -0500 |
| Message-ID | <lfv50uwuka6r$.dlg@v.nguard.lh> |
| In reply to | #405 |
VanguardLH <V@nguard.LH> wrote: > Andy Burns <usenet@andyburns.uk> wrote: > >> VanguardLH wrote: >> >>> Michael Trew wrote: >>> >>>> Not so sure that I even want to upgrade with the discontinuation of >>>> FTP >>> >>> There are plenty of free FTP clients available. Since you mentioned >>> Windows, popular ones there are FileZilla and WinSCP. >> >> Yep, I use both. >> >>> So, how often per year do you click on ftp:// hyperlinks in web pages? >> >> Launching filezilla for FTP URLs already works in firefox v80. > > Yep, I changed the default from Prompt to select Filezilla. Firefox > passes the FTP URL as an command-line argument to FileZilla. Makes it > seamless to get ftp:// URLs in a web page shown in Firefox to open using > a 3rd party FTP client. Well, of course there's the initial setup of installing the 3rd party FTP client so the linkage in Firefox will work. I never liked the inbuilt FTP client in any web browser. Too simplistic, and doesn't show the file system hierarchy at the server.
[toc] | [prev] | [next] | [standalone]
| From | Dave <dave@triffid.co.uk> |
|---|---|
| Date | 2021-04-28 08:57 +0100 |
| Message-ID | <592425c2f9dave@triffid.co.uk> |
| In reply to | #405 |
In article <et7xtzcq2ac3.dlg@v.nguard.lh>, VanguardLH <V@nguard.LH> wrote: [Snip] > Yep, I changed the default from Prompt to select Filezilla. Firefox > passes the FTP URL as an command-line argument to FileZilla. Makes it > seamless to get ftp:// URLs in a web page shown in Firefox to open using > a 3rd party FTP client. I use Filezilla but have never used it as you note above. Please, could you expand a bit on how it is done? Thanks Dave -- Dave Triffid
[toc] | [prev] | [next] | [standalone]
| From | Andy Burns <usenet@andyburns.uk> |
|---|---|
| Date | 2021-04-28 10:39 +0100 |
| Message-ID | <iesor0Fl73gU1@mid.individual.net> |
| In reply to | #407 |
Dave wrote: > I use Filezilla but have never used it as you note above. > Please, could you expand a bit on how it is done? Current firefox has "soft disabled" the FTP feature, I believe there is an about:config setting somewhere to override that, but given that it will be "hard disabled" in V90, so I thought I'd take the leap now rather than later. After upgrading to V88, the first click of an FTP URL will bring up a dialogue just like for any other unrecognised MIME type or protocol, Filezilla could be picked from the list ... <http://andyburns.uk/misc/firefox-external-ftp.png> WinSCP was not on the list, so presumably has not registered itself with windows as an FTP handler, and when I tried pointing direct to the winscp.exe, it did launch it, but winscp insisted on trying to authenticate to the FTP site, which then complained saying it was for anonymous access only.
[toc] | [prev] | [next] | [standalone]
| From | Dave <dave@triffid.co.uk> |
|---|---|
| Date | 2021-04-28 14:49 +0100 |
| Message-ID | <592445fc41dave@triffid.co.uk> |
| In reply to | #409 |
In article <iesor0Fl73gU1@mid.individual.net>, Andy Burns <usenet@andyburns.uk> wrote: > Dave wrote: > > I use Filezilla but have never used it as you note above. > > Please, could you expand a bit on how it is done? > Current firefox has "soft disabled" the FTP feature, I believe there is > an about:config setting somewhere to override that, but given that it > will be "hard disabled" in V90, so I thought I'd take the leap now > rather than later. > After upgrading to V88, the first click of an FTP URL will bring up a > dialogue just like for any other unrecognised MIME type or protocol, > Filezilla could be picked from the list ... I've got it setup okay now, thanks. Dave -- Dave Triffid
[toc] | [prev] | [next] | [standalone]
| From | PietB <www.godfatherof.nl/@opt-in.invalid> |
|---|---|
| Date | 2021-04-28 10:00 +0200 |
| Message-ID | <s6b4m9$nan$1@gioia.aioe.org> |
| In reply to | #403 |
Andy Burns wrote: > Launching filezilla for FTP URLs already works in firefox v80. Thanks. So there still is some hope for the future. -p
[toc] | [prev] | [next] | [standalone]
| From | "J. P. Gilliver (John)" <G6JPG@255soft.uk> |
|---|---|
| Date | 2021-04-28 18:00 +0100 |
| Message-ID | <XLb1pIPDTZigFwYM@255soft.uk> |
| In reply to | #401 |
On Tue, 27 Apr 2021 at 23:27:14, VanguardLH <V@nguard.LH> wrote (my responses usually follow points raised): >Michael Trew <mt999999@ymail.com> wrote: > >> Michael Trew wrote: >> >>> I'm on the firefox 78 ESR on Windows 7... any clue if this will be >>> the last ESR for Win 7, or do you guys think they'll put another one >>> out? >> >> Not so sure that I even want to upgrade with the discontinuation of >> FTP, but I suppose I have other browsers on here. > >There are plenty of free FTP clients available. Since you mentioned >Windows, popular ones there are FileZilla and WinSCP. > >So, how often per year do you click on ftp:// hyperlinks in web pages? About once or twice a year, if that; but the point is, why remove it? The work involved in retaining it must surely be minuscule, and the only _active_ reason I've heard given for its removal is someone waving the old safety/security flag that's used as an excuse for anything and everything - and since most ftp is anonymous (I certainly haven't used a non-anonymous site for decades, and had forgotten they existed until this thread), I don't think that's valid. They'll be removing support for http next (insisting on https everywhere). [Not that either of these matter to me, as I use a very old Firefox, and other browsers for where that doesn't work; I just follow with interest.] -- J. P. Gilliver. UMRA: 1960/<1985 MB++G()AL-IS-Ch++(p)Ar@T+H+Sh0!:`)DNAf We no longer make things, but sell each other consultancy on how to run consulatancies better. (Michael Cross, Computing 1999-3-4 [p. 28].)
[toc] | [prev] | [next] | [standalone]
| From | PietB <www.godfatherof.nl/@opt-in.invalid> |
|---|---|
| Date | 2021-04-28 20:55 +0200 |
| Message-ID | <s6cb3m$13ru$1@gioia.aioe.org> |
| In reply to | #411 |
J. P. Gilliver (John) wrote: > They'll be removing support for http next (insisting on https > everywhere). If that would happen, it would break a LOT of sites and it would greatly speed up the Bye FF process. -p
[toc] | [prev] | [next] | [standalone]
| From | VanguardLH <V@nguard.LH> |
|---|---|
| Date | 2021-04-28 14:50 -0500 |
| Message-ID | <fr7vhjq8uft6$.dlg@v.nguard.lh> |
| In reply to | #411 |
"J. P. Gilliver (John)" <G6JPG@255soft.uk> wrote: > VanguardLH <V@nguard.LH> wrote: > >> So, how often per year do you click on ftp:// hyperlinks in web >> pages? > > About once or twice a year, if that; but the point is, why remove it? > The work involved in retaining it must surely be minuscule, and the > only _active_ reason I've heard given for its removal is someone > waving the old safety/security flag that's used as an excuse for > anything and everything - and since most ftp is anonymous (I > certainly haven't used a non-anonymous site for decades, and had > forgotten they existed until this thread), I don't think that's > valid. FTP sends login credentials in the clear (plain text). In fact, the URL syntax for FTP allows adding the username and password into the URL. Firefox's FTP does not support FTPS or SFTP which isn't just aboout encrypting the traffic but also means you also cannot be sure the site you visit is the one you intended to visit. Data sent viat FTP is subject to sniffing and spoofing (the file you got might not be the one you want). If a web site is going to provide a link to a file, they already have their web server in place to handle the download. Setting up a separate FTP server and securing it in a corporate environment, especially to ensure what customers get has not been corrupted, requires extra manpower just for an alternate and superfluous file transfer scheme. If you're using anonymous (no login) FTP connections, you better have an alternate method of obtaining the CRC for the file to verify what they intended to offer is actually what you got (both from malicious interference or due to corruption), but many FTP sites do not provide a hash to let you check their files. It isn't just about encrypting your login credentials, or visiting where you intended, but also about making sure the file you get or send is true. Even if an FTP server allows anonmous connections, many still require some login credentials, like username is "FTP" (case insensitive), but some use the customer's e-mail address. Well, since FTP traffic is easy to sniff, you've divulged your e-mail address. Yes, you could use a bogus e-mail address, but that's not the modus operandi of users requested to provide an e-mail address. They're trusting the FTP server to deliver a non-malicious file, so they'll trust doling out their e-mail address, too. In 2017, teh FBI discovered hackers targeting medical and dental companies using FTP to gain health info. See https://www.globalscape.com/blog/fbi-alerts-medical-and-dental-facilities-anonymous-ftp-security-vulnerability. Yeah, those were anonymous FTP servers, too, but that didn't stop the hackers from obtaining sensitive or personal info. Should the companies have operated an anonymous FTP server? Nope, but then there are still sites that have you login that are still using just HTTP, too. FTP is vulnerable to directory traversal attack which, if successful, allows a malcontent to overwrite or create unauthorized files with permissions controlled by the hacker. The malcontent could ransom the content or deliver malicious files to users. You don't need to login to be a vulnerable user of FTP. If FTP isn't made secure, you don't know where you visited, or if the file you got or sent is okay. FTP is insecure whether you login or not. Also, half of FTP becomes disabled (to upload) as a first-level stab at preventing malicious uploads. FTP was not designed to be a download-only scheme. FTP has no resume function. If a transfer is interrupted, you start all over, even if it were the last few bytes out of a gigabyte file. Not only do you have to redo the transfer, but the FTP server could be throttle, so you get very little bandwidth, and it could be days before you find out whether the 2nd try worked or not, or you have to do it again. Both FileZilla and WinSCP support resume. Firefox's FTP client is very minimal, like what you can do with the ftp.exe command-line client. Firefox's FTP code is minimal, but it is part of the codebase for Firefox hence subject to periodic code review. You don't just test new code. You also periodically do retro testing to make sure new code hasn't affected old code. > They'll be removing support for http next (insisting on https > everywhere). Yes, they're already in the process for removing HTTP-only support. Look in about:preferences#privacy and scroll to the bottom. I've tried the "Enable HTTPS-Only Mode in all windows", but I've hit too many HTTP only sites where I had to okay the intervening the prompt. Eventually many more HTTP-only sites will migrate to HTTPS, so the option will offer added protection without overwhelming nuisance. Many sites cannot afford SSL/TLS certificates. Those can only be leased: you buy them for a fixed term, and have to pay to renew. That was then. Now there are some free or cheap CAs (Certificate Authorities). ZeroSSL is free, requires renewal within 90 days, but you can use their client for auto-renewal (max of 3 certs in free plan). Let's Encrypt (and SSL For Free which using Let's Encrypt) are free. Cloudflare doles out free certs. So, there really isn't an excuse not to have an HTTPS site other than, yeah, it requires a more effort or expertise to setup correctly. A lot of sites are web hosted. They don't provide their own resources, and instead contract with a web hosting provider to supply the web site. The web hoster would have to provide some means of allowing certs at each site which, my guess, means each web-hosted HTTPS site would have to register its own domain (even if free from the web hoster) to allow a cert that is defined for just that domain. HTTPS everywhere (not the extension) is possible, but overcoming inertia to tackle adaption is the problem. After all, how many computer users even read a Dummies book? OMG, they have to read? Such tragedy.
[toc] | [prev] | [next] | [standalone]
| From | Dave Royal<dave@dave123royal.com> |
|---|---|
| Date | 2021-04-28 20:46 +0000 |
| Message-ID | <s6chin$mjn$1@dont-email.me> |
| In reply to | #416 |
On 28 Apr 2021 14:50:29 -0500 VanguardLH wrote: >Firefox's FTP code is minimal, but it is part of the codebase for >Firefox hence subject to periodic code review. You don't just test new >code. You also periodically do retro testing to make sure new code >hasn't affected old code. And they have to maintain test cases for FTP. And there is the risk of regression because maintainers forget, or never knew, that Firefox does FTP. >Many sites cannot afford SSL/TLS certificates. Those can only be >leased: you buy them for a fixed term, and have to pay to renew. That >was then. Now there are some free or cheap CAs (Certificate >Authorities). ZeroSSL is free, requires renewal within 90 days, but you >can use their client for auto-renewal (max of 3 certs in free plan). >Let's Encrypt (and SSL For Free which using Let's Encrypt) are free. >Cloudflare doles out free certs. So, there really isn't an excuse not >to have an HTTPS site other than, yeah, it requires a more effort or >expertise to setup correctly. One good excuse is that enthusiasts have developed websites containing valuable but arcane information which is still valuable and consulted. They often started as free 'personal' websites but were moved to a private domain when the author changed ISP, or the host closed down - remember Geocities? Some of these sites have not changed in years and their authors have grown old, or have moved on to other interests. But they've continued paying the hosting fee so their work is not lost, and they often respond to email. They usually know nothing about the internet, or https. The sites are static, and the information public. HTTPS is utterly irrelevant. These sites sometimes come up on folk music forums. Someone posts that they can no longer access waulkingsongs.org.uk (I made that up) - does anbody know why? Sometimes we establish the Hamish McDuaroch (I made him up too) is in a home, or has died. I've known acquaintances or fellow enthusiasts contact the bereaved family and take over the site. So http should certainly not disappear. And I don't think it will. -- (Remove numerics from email address)
[toc] | [prev] | [next] | [standalone]
| From | "J. P. Gilliver (John)" <G6JPG@255soft.uk> |
|---|---|
| Date | 2021-04-28 21:54 +0100 |
| Message-ID | <vbe79dbWucigFwua@255soft.uk> |
| In reply to | #416 |
On Wed, 28 Apr 2021 at 14:50:29, VanguardLH <V@nguard.LH> wrote (my responses usually follow points raised): >"J. P. Gilliver (John)" <G6JPG@255soft.uk> wrote: > >> VanguardLH <V@nguard.LH> wrote: >> >>> So, how often per year do you click on ftp:// hyperlinks in web >>> pages? >> >> About once or twice a year, if that; but the point is, why remove it? [] >FTP sends login credentials in the clear (plain text). In fact, the URL >syntax for FTP allows adding the username and password into the URL. I'm not bothered; I haven't used other than a free (anonymous) access FTP site for decades (I think since before I had a GUI), and had forgotten they existed until this thread. [] >subject to sniffing and spoofing (the file you got might not be the one >you want). I don't trust any file I download, by whatever protocol (including https). > >If a web site is going to provide a link to a file, they already have >their web server in place to handle the download. Setting up a separate >FTP server and securing it in a corporate environment, especially to >ensure what customers get has not been corrupted, requires extra >manpower just for an alternate and superfluous file transfer scheme. If Valid point, but not relevant to whether FTP functionality remains in a browser. [] >some login credentials, like username is "FTP" (case insensitive), but >some use the customer's e-mail address. Well, since FTP traffic is easy >to sniff, you've divulged your e-mail address. Yes, you could use a I do that whenever I post. I don't think I've had 20 spams this year - might be less than five. [] >sent is okay. FTP is insecure whether you login or not. Also, half of >FTP becomes disabled (to upload) as a first-level stab at preventing >malicious uploads. FTP was not designed to be a download-only scheme. But - at least through a browser - that's how I (and I suspect most users who use it through a browser) use it. (I don't think I even know _how_ to _up_load through a browser, using FTP or anything else, for that matter, other than on websites that have some sort of upload button, such as http://www.extractpdf.com/ .) > >FTP has no resume function. If a transfer is interrupted, you start all That _is_ a valid point. Though I can't remember downloading anything big from an FTP site. [] >again. Both FileZilla and WinSCP support resume. Firefox's FTP client >is very minimal, like what you can do with the ftp.exe command-line >client. (I didn't even know that was there!) > >Firefox's FTP code is minimal, but it is part of the codebase for >Firefox hence subject to periodic code review. You don't just test new >code. You also periodically do retro testing to make sure new code >hasn't affected old code. Valid. > >> They'll be removing support for http next (insisting on https >> everywhere). > >Yes, they're already in the process for removing HTTP-only support. >Look in about:preferences#privacy and scroll to the bottom. I've tried >the "Enable HTTPS-Only Mode in all windows", but I've hit too many HTTP >only sites where I had to okay the intervening the prompt. Eventually >many more HTTP-only sites will migrate to HTTPS, so the option will >offer added protection without overwhelming nuisance. > >Many sites cannot afford SSL/TLS certificates. Those can only be >leased: you buy them for a fixed term, and have to pay to renew. That I have no intention of buying anything like that for my (mostly very ancient) site. Or organising it even if free. [] -- J. P. Gilliver. UMRA: 1960/<1985 MB++G()AL-IS-Ch++(p)Ar@T+H+Sh0!:`)DNAf He [Alfred Kinsey] wouldn't ask 'Have you ever slept with a horse?' He would say, 'When did you first sleep with a horse?' [RT 2018/5/5-11]
[toc] | [prev] | [next] | [standalone]
| From | Eli the Bearded <*@eli.users.panix.com> |
|---|---|
| Date | 2021-04-28 21:02 +0000 |
| Message-ID | <eli$2104281702@qaz.wtf> |
| In reply to | #416 |
In alt.comp.software.firefox, VanguardLH <invalid@invalid.invalid> wrote: > Yes, they're already in the process for removing HTTP-only support. > Look in about:preferences#privacy and scroll to the bottom. I've tried > the "Enable HTTPS-Only Mode in all windows", but I've hit too many HTTP > only sites where I had to okay the intervening the prompt. I have seen that but I don't see that as step towards removing HTTP-only support but instead a step towards helping people protect themselves from HTTP-only security issues. Because of embedded http servers in hardware devices, I suspect HTTP-only support is going to be needed for a LONG time. Let's Encrypt and the like is good for things that can reach the internet, but stuff that is intended to be local network only will not be as easy to secure. > Many sites cannot afford SSL/TLS certificates. Those can only be > leased: you buy them for a fixed term, and have to pay to renew. That > was then. Now there are some free or cheap CAs (Certificate > Authorities). ZeroSSL is free, requires renewal within 90 days, but you > can use their client for auto-renewal (max of 3 certs in free plan). > Let's Encrypt (and SSL For Free which using Let's Encrypt) are free. The short renewal time on free SSL certs is part of a tradeoff for reduced scrutiny about who is getting the cert. Someone who gets one via nefarious means will have a smaller window to operate with it. FWIW, I did an audit of my spam about two years ago and found that email trying to get me to go to an http site (instead of an https site) was about 98% correlated with email being spam. (A lot of spam at the time -- and possibly now but I haven't checked recently -- was trying to use the small window of time between when a domain could first be resolved at the DNS root and when any other information about the domain is available. Beause of that tight window, the time to get an SSL cert becomes expensive, even one as fast as Let's Encrypt.) > Cloudflare doles out free certs. So, there really isn't an excuse not > to have an HTTPS site other than, yeah, it requires a more effort or > expertise to setup correctly. I don't really want the built-in webserver in my printer talking to the internet, because I don't trust that someone couldn't find a way to run code or siphon information out of it. I do want my printer on the local net so I can print without being physically next to the machine. And since I reach it at http://192.168.1.168/ I can't even get a cert: there's no domain name and no hostname, just an IP address likely used by thousands of other devices. (Further, I don't really care that my printer _has_ a built-in webserver, since I only print to it using IPP. But it does speak on port 80 and I've used it while searching for obscure settings, and presumably some people do use it.) > A lot of sites are web hosted. They don't provide their own resources, > and instead contract with a web hosting provider to supply the web site. > The web hoster would have to provide some means of allowing certs at > each site which, my guess, means each web-hosted HTTPS site would have > to register its own domain (even if free from the web hoster) to allow a > cert that is defined for just that domain. The standard Let's Encrypt proof of domain ownership is being able to place a specially crafted file at a particular "well known" location at a particular time (namely within a few seconds of asking for a cert). The domain registrars don't need to get involved at all. More advanced Let's Encrypt proof of domain ownership involves DNS record changes (well-known and at a particular time). I've set that up in order to get a wildcard cert (*.example.com for all first level subdomains of example.com). Again the domain registrars are not involved. Elijah ------ imagines there are a lot of people with a lot of http only home devices
[toc] | [prev] | [next] | [standalone]
| From | VanguardLH <V@nguard.LH> |
|---|---|
| Date | 2021-04-29 00:12 -0500 |
| Message-ID | <1k7vwsvkotabm$.dlg@v.nguard.lh> |
| In reply to | #419 |
Eli the Bearded <*@eli.users.panix.com> wrote: > Keywords: VanguardLH VLH811 I see you decided to steal my Keywords string.
[toc] | [prev] | [next] | [standalone]
| From | Eli the Bearded <*@eli.users.panix.com> |
|---|---|
| Date | 2021-04-29 17:37 +0000 |
| Subject | Keywords header (was: Re: Firefox ESR) |
| Message-ID | <eli$2104291337@qaz.wtf> |
| In reply to | #421 |
Crossposted and follow-ups set. In alt.comp.software.firefox, VanguardLH <invalid@invalid.invalid> wrote: > Eli the Bearded <*@eli.users.panix.com> wrote: >> Keywords: VanguardLH VLH811 > I see you decided to steal my Keywords string. It is a rn / trn feature to preserve the Keywords: in follow-ups. I seldom examine them, since they are usually blank. Checking my post archive I see this is not the first time you've gotten me like that. The first appears to be my reply to <h1qr5g0nm2qu$.dlg@v.nguard.lh> in comp.mobile.android from way back in February 2018. And golly gee, there's an earlier time I caught it. Message-ID: <eli$1712201641@qz.little-neck.ny.us> Newsgroups: news.software.readers References: <fa00hdFhu6jU4@mid.individual.net> <anl6wshc1lwb.dlg@v.nguard.lh> Keywords: VanguardLH likes to stuff things in keywords. Date: Wed, 20 Dec 2017 16:41:31 -0500 (EST) March 2019 is the last time I posted with keywords that were not yours nor added by me. I've added keywords to three posts of my own in that period, most recently a post about headers to news.software.readers on April third. I found twenty-four posts since last rotating my "outposts" file in 2014 with keywords. Seven of them were replies to you, including that one I caught. Can I ask why? Or what you hope to get out of those keywords? Elijah ------ will accept "for fun" as a good enough reason
[toc] | [prev] | [next] | [standalone]
| From | VanguardLH <V@nguard.LH> |
|---|---|
| Date | 2021-05-06 05:52 -0500 |
| Subject | Re: Keywords header |
| Message-ID | <5xpuhyxthcy3.dlg@v.nguard.lh> |
| In reply to | #436 |
Eli the Bearded <*@eli.users.panix.com> wrote:
> Crossposted and follow-ups set.
FollowUp-To ignored. It is rude to yank away a conversation from other
readers in the original newsgroup to which you posted by redirecting
replies to elsewhere than the original location.
> VanguardLH <invalid@invalid.invalid> wrote:
>
>> I see you decided to steal my Keywords string.
>
> It is a rn / trn feature to preserve the Keywords: in follow-ups. I
> seldom examine them, since they are usually blank. Checking my post
> archive I see this is not the first time you've gotten me like that.
> ...
>
> Can I ask why? Or what you hope to get out of those keywords?
In addition to the From header, I use both the right token of the
Message-ID and the Keywords headers to make sure anyone that wants to
identify me, even to plonk me, has multiple and stable headers on which
to filter. If they wanted to ensure their filter only targeted me, or
they wanted to ensure a search only showed my posts, and not
accidentally on someone else, they can test on:
- Path injection node
- AND From
- AND Organization
- AND Message-ID
- AND Keywords.
Or, they could use just the From header for easy if filter definition,
too, but it's easy to catch forgers, especially since their Path
injection node won't be the same as mine (well, not for long since I use
responsive Usenet providers that can kill the forger's account very
quickly, and another reason I quit using freebie Usenet providers since
the forger would have to pay to get an account). I give lots of
compounded targets to identify me.
https://tools.ietf.org/html/rfc1036
Section 2.2.9
A few well-selected keywords identifying the message should be on this
line. This is used as an aid in determining if this message is
interesting to the reader.
https://tools.ietf.org/html/rfc5322#section-3.6.5
The "Keywords:" field contains a comma-separated list of one or more
words or quoted-strings.
...
These three fields are intended to have only human-readable content
with information about the message.
...
The "Keywords:" field contains a comma- separated list of important
words and phrases that might be useful for the recipient.
I would also use the "Comments:" header to further strengthen my Usenet
identity, but my client doesn't let me add that one. No, I'm not going
to PGP-sign my posts, because it is stupid since no one in Usenet is
going to bother doing the lookup.
While I can select a view that always shows all headers, that is usually
a bunch of noise (as is often the attribution lines where posters think
they have to add lots of duplicated info that is already available in
the headers). I only occasionally look at all headers, so it is
possible that I previously missed someone just copying my Keywords
header into their reply. From what I seen in many NNTP clients, they
generate their own Keywords header, if specified (non-blank), not
forward a value from what some other client specified in a parent post.
The RFC definition of the Keywords header is rather vague and very
terse. Just didn't figure any client would not use its own value.
I don't delete any unwanted posts. Instead my filters colorize them and
add an Ignore flag. I use a default view of Hide Ignored Posts;
however, if I need to check my filters for false positives or someone
mentions something in an otherwise hidden post, I can just switch to the
Show All Messages view. When I showed all messages, including the
ignore-flagged ones, I saw your post. It was colorized, because it
originated from Panix. So, I looked at the raw source of your message
to see your Keywords header duplicated mine instead of your client
adding its own value. Panix has been ignored-flagged by me ever since
they decided to spamify all posts that originate at them by appending a
deliberately invalid signature (so clients that hide sigs won't work).
I wasn't interested in seeing posts by users of a spamifying Usenet
provider.
I've see Avast users, and other anti-virus program users, that spamify
their Usenet posts (and e-mails). Avast does the same as did/does
Panix: use an invalid sigdash line followed by 1, or more, lines of spam
announcing the users employs Avast. The default config in Avast is to
add the invalid sigblock. I'll alert such users that they are spamming
their choice of anti-virus software, and to turn it off. If they
continue to refuse, and because they choose to be spamming affiliates,
they'll get kill filed. I did the same to Panix when they were
appending their invalid sigblock to all submissions.
Has Panix ceased spamifying the articles submitted to them? I don't see
it in your posts. Did they ever offer free trials, and those are the
submissions they spamified (as a lure to get those users to move to
their pay service)? If Panix is no longer spammifying their articles, I
will modify my filter on them to stop flagging them as ignored. I'll
still colorize them for awhile to watch if any spammified posts show up.
[toc] | [prev] | [next] | [standalone]
Page 1 of 3 [1] 2 3 Next page →
Back to top | Article view | alt.comp.software.firefox
csiph-web