Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > alt.comp.software.firefox > #398 > unrolled thread

Firefox ESR

Started byMichael Trew <mt999999@ymail.com>
First post2021-04-27 23:29 -0400
Last post2021-04-27 23:26 -0500
Articles 20 on this page of 58 — 19 participants

Back to article view | Back to alt.comp.software.firefox


Contents

  Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-27 23:29 -0400
    Re: Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-27 23:30 -0400
      Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-27 23:27 -0500
        Re: Firefox ESR Andy Burns <usenet@andyburns.uk> - 2021-04-28 07:13 +0100
          Re: Firefox ESR Andy Burns <usenet@andyburns.uk> - 2021-04-28 07:17 +0100
          Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-28 02:01 -0500
            Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-28 02:03 -0500
            Firefox ESR Dave <dave@triffid.co.uk> - 2021-04-28 08:57 +0100
              Re: Firefox ESR Andy Burns <usenet@andyburns.uk> - 2021-04-28 10:39 +0100
                Firefox ESR Dave <dave@triffid.co.uk> - 2021-04-28 14:49 +0100
          Re: Firefox ESR PietB <www.godfatherof.nl/@opt-in.invalid> - 2021-04-28 10:00 +0200
        Re: Firefox ESR "J. P. Gilliver (John)" <G6JPG@255soft.uk> - 2021-04-28 18:00 +0100
          Re: Firefox ESR PietB <www.godfatherof.nl/@opt-in.invalid> - 2021-04-28 20:55 +0200
          Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-28 14:50 -0500
            Re: Firefox ESR Dave Royal<dave@dave123royal.com> - 2021-04-28 20:46 +0000
            Re: Firefox ESR "J. P. Gilliver (John)" <G6JPG@255soft.uk> - 2021-04-28 21:54 +0100
            Re: Firefox ESR Eli the Bearded <*@eli.users.panix.com> - 2021-04-28 21:02 +0000
              Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-29 00:12 -0500
                Keywords header (was: Re: Firefox ESR) Eli the Bearded <*@eli.users.panix.com> - 2021-04-29 17:37 +0000
                  Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-06 05:52 -0500
                    Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-06 06:06 -0500
                      Re: Keywords header !@!.invalid (Ï) - 2021-05-06 14:39 +0100
                      Re: Keywords header "Adam H. Kerman" <ahk@chinet.com> - 2021-05-06 15:14 +0000
                        Re: Keywords header "J. P. Gilliver (John)" <G6JPG@255soft.uk> - 2021-05-06 18:04 +0100
                        Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-08 15:01 -0500
                          Re: Keywords header "Adam H. Kerman" <ahk@chinet.com> - 2021-05-08 21:08 +0000
                            Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-08 16:37 -0500
                            Re: Keywords header !@!.invalid (Ï) - 2021-05-08 22:52 +0100
                    Re: Keywords header Frank Slootweg <this@ddress.is.invalid> - 2021-05-06 17:49 +0000
                      Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-08 15:40 -0500
                        Re: Keywords header Miguel Tomar Nogueira <mnogueira@mail.telepac.pt> - 2021-05-09 05:58 +0000
                        Re: Keywords header Frank Slootweg <this@ddress.is.invalid> - 2021-05-09 17:24 +0000
                    Re: Keywords header Eli the Bearded <*@eli.users.panix.com> - 2021-05-06 18:11 +0000
                      Panix spammifying of submissions (was: Keywords header) VanguardLH <V@nguard.LH> - 2021-05-08 16:30 -0500
                        Re: Panix spammifying of submissions (was: Keywords header) danny burstein <dannyb@panix.com> - 2021-05-08 21:52 +0000
                        Re: Panix spammifying of submissions (was: Keywords header) Eli the Bearded <*@eli.users.panix.com> - 2021-05-10 02:34 +0000
        Re: Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-28 13:52 -0400
          Re: Firefox ESR Eli the Bearded <*@eli.users.panix.com> - 2021-04-28 18:29 +0000
            Re: Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-28 23:26 -0400
              Re: Firefox ESR Rich <rich@example.invalid> - 2021-04-29 12:52 +0000
          Re: Firefox ESR Rich <rich@example.invalid> - 2021-04-29 12:45 +0000
            Re: Firefox ESR "Adam H. Kerman" <ahk@chinet.com> - 2021-04-29 13:22 +0000
              Re: Firefox ESR Rich <rich@example.invalid> - 2021-04-29 13:53 +0000
                Re: Firefox ESR "Adam H. Kerman" <ahk@chinet.com> - 2021-04-29 18:32 +0000
                  Re: Firefox ESR Rich <rich@example.invalid> - 2021-04-29 20:31 +0000
              Re: Firefox ESR "OldbieOne" <me@here.com> - 2021-05-03 14:17 -0400
                Re: Firefox ESR PietB <www.godfatherof.nl/@opt-in.invalid> - 2021-05-08 16:58 +0200
                  Re: Firefox ESR "OldbieOne" <me@here.com> - 2021-05-19 10:52 -0400
                    Re: Firefox ESR Ant <ant@zimage.comANT> - 2021-05-19 09:10 -0700
                      Re: Firefox ESR "Adam H. Kerman" <ahk@chinet.com> - 2021-05-19 16:35 +0000
                        Re: Firefox ESR "OldbieOne" <me@here.com> - 2021-05-19 15:16 -0400
                          Re: Firefox ESR Job Bautista <jobbautista9@aol.com> - 2021-05-20 18:35 +0800
                          Re: Firefox ESR "OldbieOne" <me@here.com> - 2021-05-25 12:32 -0400
                            Re: Firefox ESR WaltS48 <schw01@invalid.net> - 2021-05-25 15:16 -0400
            Re: Firefox ESR Miguel Tomar Nogueira <mnogueira@mail.telepac.pt> - 2021-05-09 06:18 +0000
      Re: Firefox ESR chris@here.com - 2021-04-27 23:31 -0500
        Re: Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-28 13:53 -0400
    Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-27 23:26 -0500

Page 1 of 3  [1] 2 3  Next page →


#398 — Firefox ESR

FromMichael Trew <mt999999@ymail.com>
Date2021-04-27 23:29 -0400
SubjectFirefox ESR
Message-ID<s6akrj$di4$8@dont-email.me>
I'm on the firefox 78 ESR on Windows 7... any clue if this will be the 
last ESR for Win 7, or do you guys think they'll put another one out?

[toc] | [next] | [standalone]


#399

FromMichael Trew <mt999999@ymail.com>
Date2021-04-27 23:30 -0400
Message-ID<s6aksm$di4$9@dont-email.me>
In reply to#398
On 4/27/2021 11:29 PM, Michael Trew wrote:
> I'm on the firefox 78 ESR on Windows 7... any clue if this will be the
> last ESR for Win 7, or do you guys think they'll put another one out?

Not so sure that I even want to upgrade with the discontinuation of FTP, 
but I suppose I have other browsers on here.

[toc] | [prev] | [next] | [standalone]


#401

FromVanguardLH <V@nguard.LH>
Date2021-04-27 23:27 -0500
Message-ID<lzn6c3qs59j0$.dlg@v.nguard.lh>
In reply to#399
Michael Trew <mt999999@ymail.com> wrote:

> Michael Trew wrote:
>
>> I'm on the firefox 78 ESR on Windows 7... any clue if this will be
>> the last ESR for Win 7, or do you guys think they'll put another one
>> out?
> 
> Not so sure that I even want to upgrade with the discontinuation of
> FTP, but I suppose I have other browsers on here.

There are plenty of free FTP clients available.  Since you mentioned
Windows, popular ones there are FileZilla and WinSCP.

So, how often per year do you click on ftp:// hyperlinks in web pages?

[toc] | [prev] | [next] | [standalone]


#403

FromAndy Burns <usenet@andyburns.uk>
Date2021-04-28 07:13 +0100
Message-ID<iescohFiu10U1@mid.individual.net>
In reply to#401
VanguardLH wrote:

> Michael Trew wrote:
> 
>> Not so sure that I even want to upgrade with the discontinuation of
>> FTP
> 
> There are plenty of free FTP clients available.  Since you mentioned
> Windows, popular ones there are FileZilla and WinSCP.

Yep, I use both.

> So, how often per year do you click on ftp:// hyperlinks in web pages?

Launching filezilla for FTP URLs already works in firefox v80.

[toc] | [prev] | [next] | [standalone]


#404

FromAndy Burns <usenet@andyburns.uk>
Date2021-04-28 07:17 +0100
Message-ID<iesd09Fiu10U2@mid.individual.net>
In reply to#403
Andy Burns wrote:

> Launching filezilla for FTP URLs already works in firefox v80.

Make that v88.

[toc] | [prev] | [next] | [standalone]


#405

FromVanguardLH <V@nguard.LH>
Date2021-04-28 02:01 -0500
Message-ID<et7xtzcq2ac3.dlg@v.nguard.lh>
In reply to#403
Andy Burns <usenet@andyburns.uk> wrote:

> VanguardLH wrote:
> 
>> Michael Trew wrote:
>> 
>>> Not so sure that I even want to upgrade with the discontinuation of
>>> FTP
>> 
>> There are plenty of free FTP clients available.  Since you mentioned
>> Windows, popular ones there are FileZilla and WinSCP.
> 
> Yep, I use both.
> 
>> So, how often per year do you click on ftp:// hyperlinks in web pages?
> 
> Launching filezilla for FTP URLs already works in firefox v80.

Yep, I changed the default from Prompt to select Filezilla.  Firefox
passes the FTP URL as an command-line argument to FileZilla.  Makes it
seamless to get ftp:// URLs in a web page shown in Firefox to open using
a 3rd party FTP client.

[toc] | [prev] | [next] | [standalone]


#406

FromVanguardLH <V@nguard.LH>
Date2021-04-28 02:03 -0500
Message-ID<lfv50uwuka6r$.dlg@v.nguard.lh>
In reply to#405
VanguardLH <V@nguard.LH> wrote:

> Andy Burns <usenet@andyburns.uk> wrote:
> 
>> VanguardLH wrote:
>> 
>>> Michael Trew wrote:
>>> 
>>>> Not so sure that I even want to upgrade with the discontinuation of
>>>> FTP
>>> 
>>> There are plenty of free FTP clients available.  Since you mentioned
>>> Windows, popular ones there are FileZilla and WinSCP.
>> 
>> Yep, I use both.
>> 
>>> So, how often per year do you click on ftp:// hyperlinks in web pages?
>> 
>> Launching filezilla for FTP URLs already works in firefox v80.
> 
> Yep, I changed the default from Prompt to select Filezilla.  Firefox
> passes the FTP URL as an command-line argument to FileZilla.  Makes it
> seamless to get ftp:// URLs in a web page shown in Firefox to open using
> a 3rd party FTP client.

Well, of course there's the initial setup of installing the 3rd party
FTP client so the linkage in Firefox will work.

I never liked the inbuilt FTP client in any web browser.  Too
simplistic, and doesn't show the file system hierarchy at the server.

[toc] | [prev] | [next] | [standalone]


#407

FromDave <dave@triffid.co.uk>
Date2021-04-28 08:57 +0100
Message-ID<592425c2f9dave@triffid.co.uk>
In reply to#405
In article <et7xtzcq2ac3.dlg@v.nguard.lh>,
   VanguardLH <V@nguard.LH> wrote:

[Snip]

> Yep, I changed the default from Prompt to select Filezilla.  Firefox
> passes the FTP URL as an command-line argument to FileZilla.  Makes it
> seamless to get ftp:// URLs in a web page shown in Firefox to open using
> a 3rd party FTP client.

I use Filezilla but have never used it as you note above.

Please, could you expand a bit on how it is done?

Thanks
Dave

-- 

Dave Triffid

[toc] | [prev] | [next] | [standalone]


#409

FromAndy Burns <usenet@andyburns.uk>
Date2021-04-28 10:39 +0100
Message-ID<iesor0Fl73gU1@mid.individual.net>
In reply to#407
Dave wrote:

> I use Filezilla but have never used it as you note above.
> Please, could you expand a bit on how it is done?

Current firefox has "soft disabled" the FTP feature, I believe there is 
an about:config setting somewhere to override that, but given that it 
will be "hard disabled" in V90, so I thought I'd take the leap now 
rather than later.

After upgrading to V88, the first click of an FTP URL will bring up a 
dialogue just like for any other unrecognised MIME type or protocol, 
Filezilla could be picked from the list ...

<http://andyburns.uk/misc/firefox-external-ftp.png>

WinSCP was not on the list, so presumably has not registered itself with 
windows as an FTP handler, and when I tried pointing direct to the 
winscp.exe, it did launch it, but winscp insisted on trying to 
authenticate to the FTP site, which then complained saying it was for 
anonymous access only.

[toc] | [prev] | [next] | [standalone]


#410

FromDave <dave@triffid.co.uk>
Date2021-04-28 14:49 +0100
Message-ID<592445fc41dave@triffid.co.uk>
In reply to#409
In article <iesor0Fl73gU1@mid.individual.net>,
   Andy Burns <usenet@andyburns.uk> wrote:
> Dave wrote:

> > I use Filezilla but have never used it as you note above.
> > Please, could you expand a bit on how it is done?

> Current firefox has "soft disabled" the FTP feature, I believe there is 
> an about:config setting somewhere to override that, but given that it 
> will be "hard disabled" in V90, so I thought I'd take the leap now 
> rather than later.

> After upgrading to V88, the first click of an FTP URL will bring up a 
> dialogue just like for any other unrecognised MIME type or protocol, 
> Filezilla could be picked from the list ...

I've got it setup okay now, thanks.

Dave

-- 

Dave Triffid

[toc] | [prev] | [next] | [standalone]


#408

FromPietB <www.godfatherof.nl/@opt-in.invalid>
Date2021-04-28 10:00 +0200
Message-ID<s6b4m9$nan$1@gioia.aioe.org>
In reply to#403
Andy Burns wrote:
> Launching filezilla for FTP URLs already works in firefox v80.

Thanks. So there still is some hope for the future.

-p

[toc] | [prev] | [next] | [standalone]


#411

From"J. P. Gilliver (John)" <G6JPG@255soft.uk>
Date2021-04-28 18:00 +0100
Message-ID<XLb1pIPDTZigFwYM@255soft.uk>
In reply to#401
On Tue, 27 Apr 2021 at 23:27:14, VanguardLH <V@nguard.LH> wrote (my 
responses usually follow points raised):
>Michael Trew <mt999999@ymail.com> wrote:
>
>> Michael Trew wrote:
>>
>>> I'm on the firefox 78 ESR on Windows 7... any clue if this will be
>>> the last ESR for Win 7, or do you guys think they'll put another one
>>> out?
>>
>> Not so sure that I even want to upgrade with the discontinuation of
>> FTP, but I suppose I have other browsers on here.
>
>There are plenty of free FTP clients available.  Since you mentioned
>Windows, popular ones there are FileZilla and WinSCP.
>
>So, how often per year do you click on ftp:// hyperlinks in web pages?

About once or twice a year, if that; but the point is, why remove it? 
The work involved in retaining it must surely be minuscule, and the only 
_active_ reason I've heard given for its removal is someone waving the 
old safety/security flag that's used as an excuse for anything and 
everything - and since most ftp is anonymous (I certainly haven't used a 
non-anonymous site for decades, and had forgotten they existed until 
this thread), I don't think that's valid.

They'll be removing support for http next (insisting on https 
everywhere).

[Not that either of these matter to me, as I use a very old Firefox, and 
other browsers for where that doesn't work; I just follow with 
interest.]
-- 
J. P. Gilliver. UMRA: 1960/<1985 MB++G()AL-IS-Ch++(p)Ar@T+H+Sh0!:`)DNAf

We no longer make things, but sell each other consultancy on how to run
consulatancies better. (Michael Cross, Computing 1999-3-4 [p. 28].)

[toc] | [prev] | [next] | [standalone]


#415

FromPietB <www.godfatherof.nl/@opt-in.invalid>
Date2021-04-28 20:55 +0200
Message-ID<s6cb3m$13ru$1@gioia.aioe.org>
In reply to#411
J. P. Gilliver (John) wrote:
> They'll be removing support for http next (insisting on https 
> everywhere).

If that would happen, it would break a LOT of sites and it would
greatly speed up the Bye FF process.

-p

[toc] | [prev] | [next] | [standalone]


#416

FromVanguardLH <V@nguard.LH>
Date2021-04-28 14:50 -0500
Message-ID<fr7vhjq8uft6$.dlg@v.nguard.lh>
In reply to#411
"J. P. Gilliver (John)" <G6JPG@255soft.uk> wrote:

> VanguardLH <V@nguard.LH> wrote:
>
>> So, how often per year do you click on ftp:// hyperlinks in web
>> pages?
> 
> About once or twice a year, if that; but the point is, why remove it? 
> The work involved in retaining it must surely be minuscule, and the
> only _active_ reason I've heard given for its removal is someone
> waving the old safety/security flag that's used as an excuse for
> anything and everything - and since most ftp is anonymous (I
> certainly haven't used a non-anonymous site for decades, and had
> forgotten they existed until this thread), I don't think that's
> valid.

FTP sends login credentials in the clear (plain text).  In fact, the URL
syntax for FTP allows adding the username and password into the URL.
Firefox's FTP does not support FTPS or SFTP which isn't just aboout
encrypting the traffic but also means you also cannot be sure the site
you visit is the one you intended to visit.  Data sent viat FTP is
subject to sniffing and spoofing (the file you got might not be the one
you want).

If a web site is going to provide a link to a file, they already have
their web server in place to handle the download.  Setting up a separate
FTP server and securing it in a corporate environment, especially to
ensure what customers get has not been corrupted, requires extra
manpower just for an alternate and superfluous file transfer scheme.  If
you're using anonymous (no login) FTP connections, you better have an
alternate method of obtaining the CRC for the file to verify what they
intended to offer is actually what you got (both from malicious
interference or due to corruption), but many FTP sites do not provide a
hash to let you check their files.  It isn't just about encrypting your
login credentials, or visiting where you intended, but also about making
sure the file you get or send is true.

Even if an FTP server allows anonmous connections, many still require
some login credentials, like username is "FTP" (case insensitive), but
some use the customer's e-mail address.  Well, since FTP traffic is easy
to sniff, you've divulged your e-mail address.  Yes, you could use a
bogus e-mail address, but that's not the modus operandi of users
requested to provide an e-mail address.  They're trusting the FTP server
to deliver a non-malicious file, so they'll trust doling out their
e-mail address, too.  In 2017, teh FBI discovered hackers targeting
medical and dental companies using FTP to gain health info.  See
https://www.globalscape.com/blog/fbi-alerts-medical-and-dental-facilities-anonymous-ftp-security-vulnerability.
Yeah, those were anonymous FTP servers, too, but that didn't stop the
hackers from obtaining sensitive or personal info.  Should the companies
have operated an anonymous FTP server?  Nope, but then there are still
sites that have you login that are still using just HTTP, too.

FTP is vulnerable to directory traversal attack which, if successful,
allows a malcontent to overwrite or create unauthorized files with
permissions controlled by the hacker.  The malcontent could ransom the
content or deliver malicious files to users.

You don't need to login to be a vulnerable user of FTP.  If FTP isn't
made secure, you don't know where you visited, or if the file you got or
sent is okay.  FTP is insecure whether you login or not.  Also, half of
FTP becomes disabled (to upload) as a first-level stab at preventing
malicious uploads.  FTP was not designed to be a download-only scheme.

FTP has no resume function.  If a transfer is interrupted, you start all
over, even if it were the last few bytes out of a gigabyte file.  Not
only do you have to redo the transfer, but the FTP server could be
throttle, so you get very little bandwidth, and it could be days before
you find out whether the 2nd try worked or not, or you have to do it
again.  Both FileZilla and WinSCP support resume.  Firefox's FTP client
is very minimal, like what you can do with the ftp.exe command-line
client.

Firefox's FTP code is minimal, but it is part of the codebase for
Firefox hence subject to periodic code review.  You don't just test new
code.  You also periodically do retro testing to make sure new code
hasn't affected old code.  

> They'll be removing support for http next (insisting on https 
> everywhere).

Yes, they're already in the process for removing HTTP-only support.
Look in about:preferences#privacy and scroll to the bottom.  I've tried
the "Enable HTTPS-Only Mode in all windows", but I've hit too many HTTP
only sites where I had to okay the intervening the prompt.  Eventually
many more HTTP-only sites will migrate to HTTPS, so the option will
offer added protection without overwhelming nuisance.

Many sites cannot afford SSL/TLS certificates.  Those can only be
leased: you buy them for a fixed term, and have to pay to renew.  That
was then.  Now there are some free or cheap CAs (Certificate
Authorities).  ZeroSSL is free, requires renewal within 90 days, but you
can use their client for auto-renewal (max of 3 certs in free plan).
Let's Encrypt (and SSL For Free which using Let's Encrypt) are free.
Cloudflare doles out free certs.  So, there really isn't an excuse not
to have an HTTPS site other than, yeah, it requires a more effort or
expertise to setup correctly.

A lot of sites are web hosted.  They don't provide their own resources,
and instead contract with a web hosting provider to supply the web site.
The web hoster would have to provide some means of allowing certs at
each site which, my guess, means each web-hosted HTTPS site would have
to register its own domain (even if free from the web hoster) to allow a
cert that is defined for just that domain.  HTTPS everywhere (not the
extension) is possible, but overcoming inertia to tackle adaption is the
problem.  After all, how many computer users even read a Dummies book?
OMG, they have to read?  Such tragedy.

[toc] | [prev] | [next] | [standalone]


#417

FromDave Royal<dave@dave123royal.com>
Date2021-04-28 20:46 +0000
Message-ID<s6chin$mjn$1@dont-email.me>
In reply to#416
On 28 Apr 2021 14:50:29 -0500 VanguardLH wrote:
>Firefox's FTP code is minimal, but it is part of the codebase for
>Firefox hence subject to periodic code review.  You don't just test new
>code.  You also periodically do retro testing to make sure new code
>hasn't affected old code.  

And they have to maintain test cases for FTP.
And there is the risk of regression because maintainers forget, or never 
knew, that Firefox does FTP.


>Many sites cannot afford SSL/TLS certificates.  Those can only be
>leased: you buy them for a fixed term, and have to pay to renew.  That
>was then.  Now there are some free or cheap CAs (Certificate
>Authorities).  ZeroSSL is free, requires renewal within 90 days, but you
>can use their client for auto-renewal (max of 3 certs in free plan).
>Let's Encrypt (and SSL For Free which using Let's Encrypt) are free.
>Cloudflare doles out free certs.  So, there really isn't an excuse not
>to have an HTTPS site other than, yeah, it requires a more effort or
>expertise to setup correctly.

One good excuse is that enthusiasts have developed websites containing 
valuable but arcane information which is still valuable and consulted.  
They often started as free 'personal' websites but were moved to a 
private domain when the author changed ISP, or the host closed down - 
remember Geocities? Some of these sites have not changed in years and 
their authors have grown old, or have moved on to other interests. But 
they've continued paying the hosting fee so their work is not lost, and 
they often respond to email. They usually know nothing about the internet, 
or https. The sites are static, and the information public. HTTPS is 
utterly irrelevant.

These sites sometimes come up on folk music forums. Someone posts that 
they can no longer access waulkingsongs.org.uk (I made that up) - does 
anbody know why? Sometimes we establish the Hamish McDuaroch (I made him 
up too) is in a home, or has died. I've known acquaintances or fellow 
enthusiasts contact the bereaved family and take over the site.

So http should certainly not disappear. And I don't think it will.
-- 
(Remove numerics from email address)

[toc] | [prev] | [next] | [standalone]


#418

From"J. P. Gilliver (John)" <G6JPG@255soft.uk>
Date2021-04-28 21:54 +0100
Message-ID<vbe79dbWucigFwua@255soft.uk>
In reply to#416
On Wed, 28 Apr 2021 at 14:50:29, VanguardLH <V@nguard.LH> wrote (my 
responses usually follow points raised):
>"J. P. Gilliver (John)" <G6JPG@255soft.uk> wrote:
>
>> VanguardLH <V@nguard.LH> wrote:
>>
>>> So, how often per year do you click on ftp:// hyperlinks in web
>>> pages?
>>
>> About once or twice a year, if that; but the point is, why remove it?
[]
>FTP sends login credentials in the clear (plain text).  In fact, the URL
>syntax for FTP allows adding the username and password into the URL.

I'm not bothered; I haven't used other than a free (anonymous) access 
FTP site for decades (I think since before I had a GUI), and had 
forgotten they existed until this thread.
[]
>subject to sniffing and spoofing (the file you got might not be the one
>you want).

I don't trust any file I download, by whatever protocol (including 
https).
>
>If a web site is going to provide a link to a file, they already have
>their web server in place to handle the download.  Setting up a separate
>FTP server and securing it in a corporate environment, especially to
>ensure what customers get has not been corrupted, requires extra
>manpower just for an alternate and superfluous file transfer scheme.  If

Valid point, but not relevant to whether FTP functionality remains in a 
browser.
[]
>some login credentials, like username is "FTP" (case insensitive), but
>some use the customer's e-mail address.  Well, since FTP traffic is easy
>to sniff, you've divulged your e-mail address.  Yes, you could use a

I do that whenever I post. I don't think I've had 20 spams this year - 
might be less than five.
[]
>sent is okay.  FTP is insecure whether you login or not.  Also, half of
>FTP becomes disabled (to upload) as a first-level stab at preventing
>malicious uploads.  FTP was not designed to be a download-only scheme.

But - at least through a browser - that's how I (and I suspect most 
users who use it through a browser) use it. (I don't think I even know 
_how_ to _up_load through a browser, using FTP or anything else, for 
that matter, other than on websites that have some sort of upload 
button, such as http://www.extractpdf.com/ .)
>
>FTP has no resume function.  If a transfer is interrupted, you start all

That _is_ a valid point. Though I can't remember downloading anything 
big from an FTP site.
[]
>again.  Both FileZilla and WinSCP support resume.  Firefox's FTP client
>is very minimal, like what you can do with the ftp.exe command-line
>client.

(I didn't even know that was there!)
>
>Firefox's FTP code is minimal, but it is part of the codebase for
>Firefox hence subject to periodic code review.  You don't just test new
>code.  You also periodically do retro testing to make sure new code
>hasn't affected old code.

Valid.
>
>> They'll be removing support for http next (insisting on https
>> everywhere).
>
>Yes, they're already in the process for removing HTTP-only support.
>Look in about:preferences#privacy and scroll to the bottom.  I've tried
>the "Enable HTTPS-Only Mode in all windows", but I've hit too many HTTP
>only sites where I had to okay the intervening the prompt.  Eventually
>many more HTTP-only sites will migrate to HTTPS, so the option will
>offer added protection without overwhelming nuisance.
>
>Many sites cannot afford SSL/TLS certificates.  Those can only be
>leased: you buy them for a fixed term, and have to pay to renew.  That

I have no intention of buying anything like that for my (mostly very 
ancient) site. Or organising it even if free.
[]
-- 
J. P. Gilliver. UMRA: 1960/<1985 MB++G()AL-IS-Ch++(p)Ar@T+H+Sh0!:`)DNAf

He [Alfred Kinsey] wouldn't ask 'Have you ever slept with a horse?' He would
say, 'When did you first sleep with a horse?' [RT 2018/5/5-11]

[toc] | [prev] | [next] | [standalone]


#419

FromEli the Bearded <*@eli.users.panix.com>
Date2021-04-28 21:02 +0000
Message-ID<eli$2104281702@qaz.wtf>
In reply to#416
In alt.comp.software.firefox, VanguardLH  <invalid@invalid.invalid> wrote:
> Yes, they're already in the process for removing HTTP-only support.
> Look in about:preferences#privacy and scroll to the bottom.  I've tried
> the "Enable HTTPS-Only Mode in all windows", but I've hit too many HTTP
> only sites where I had to okay the intervening the prompt.

I have seen that but I don't see that as step towards removing HTTP-only
support but instead a step towards helping people protect themselves
from HTTP-only security issues.

Because of embedded http servers in hardware devices, I suspect
HTTP-only support is going to be needed for a LONG time. Let's Encrypt
and the like is good for things that can reach the internet, but stuff
that is intended to be local network only will not be as easy to secure.

> Many sites cannot afford SSL/TLS certificates.  Those can only be
> leased: you buy them for a fixed term, and have to pay to renew.  That
> was then.  Now there are some free or cheap CAs (Certificate
> Authorities).  ZeroSSL is free, requires renewal within 90 days, but you
> can use their client for auto-renewal (max of 3 certs in free plan).
> Let's Encrypt (and SSL For Free which using Let's Encrypt) are free.

The short renewal time on free SSL certs is part of a tradeoff for
reduced scrutiny about who is getting the cert. Someone who gets one via
nefarious means will have a smaller window to operate with it.

FWIW, I did an audit of my spam about two years ago and found that email
trying to get me to go to an http site (instead of an https site) was
about 98% correlated with email being spam.

(A lot of spam at the time -- and possibly now but I haven't checked
recently -- was trying to use the small window of time between when a
domain could first be resolved at the DNS root and when any other
information about the domain is available. Beause of that tight window,
the time to get an SSL cert becomes expensive, even one as fast as Let's
Encrypt.)

> Cloudflare doles out free certs.  So, there really isn't an excuse not
> to have an HTTPS site other than, yeah, it requires a more effort or
> expertise to setup correctly.

I don't really want the built-in webserver in my printer talking to the
internet, because I don't trust that someone couldn't find a way to run
code or siphon information out of it. I do want my printer on the local
net so I can print without being physically next to the machine. And
since I reach it at http://192.168.1.168/ I can't even get a cert:
there's no domain name and no hostname, just an IP address likely used
by thousands of other devices.

(Further, I don't really care that my printer _has_ a built-in
webserver, since I only print to it using IPP. But it does speak on port
80 and I've used it while searching for obscure settings, and presumably
some people do use it.)

> A lot of sites are web hosted.  They don't provide their own resources,
> and instead contract with a web hosting provider to supply the web site.
> The web hoster would have to provide some means of allowing certs at
> each site which, my guess, means each web-hosted HTTPS site would have
> to register its own domain (even if free from the web hoster) to allow a
> cert that is defined for just that domain.

The standard Let's Encrypt proof of domain ownership is being able to
place a specially crafted file at a particular "well known" location at
a particular time (namely within a few seconds of asking for a cert).
The domain registrars don't need to get involved at all.

More advanced Let's Encrypt proof of domain ownership involves DNS
record changes (well-known and at a particular time). I've set that up
in order to get a wildcard cert (*.example.com for all first level
subdomains of example.com). Again the domain registrars are not
involved.

Elijah
------
imagines there are a lot of people with a lot of http only home devices

[toc] | [prev] | [next] | [standalone]


#421

FromVanguardLH <V@nguard.LH>
Date2021-04-29 00:12 -0500
Message-ID<1k7vwsvkotabm$.dlg@v.nguard.lh>
In reply to#419
Eli the Bearded <*@eli.users.panix.com> wrote:

> Keywords: VanguardLH VLH811

I see you decided to steal my Keywords string.

[toc] | [prev] | [next] | [standalone]


#436 — Keywords header (was: Re: Firefox ESR)

FromEli the Bearded <*@eli.users.panix.com>
Date2021-04-29 17:37 +0000
SubjectKeywords header (was: Re: Firefox ESR)
Message-ID<eli$2104291337@qaz.wtf>
In reply to#421
Crossposted and follow-ups set.

In alt.comp.software.firefox, VanguardLH  <invalid@invalid.invalid> wrote:
> Eli the Bearded <*@eli.users.panix.com> wrote:
>> Keywords: VanguardLH VLH811
> I see you decided to steal my Keywords string.

It is a rn / trn feature to preserve the Keywords: in follow-ups. I
seldom examine them, since they are usually blank. Checking my post
archive I see this is not the first time you've gotten me like that.
The first appears to be my reply to <h1qr5g0nm2qu$.dlg@v.nguard.lh>
in comp.mobile.android from way back in February 2018.

And golly gee, there's an earlier time I caught it.

Message-ID: <eli$1712201641@qz.little-neck.ny.us>
Newsgroups: news.software.readers
References: <fa00hdFhu6jU4@mid.individual.net> <anl6wshc1lwb.dlg@v.nguard.lh>
Keywords: VanguardLH likes to stuff things in keywords.
Date: Wed, 20 Dec 2017 16:41:31 -0500 (EST)

March 2019 is the last time I posted with keywords that were not yours
nor added by me. I've added keywords to three posts of my own in that
period, most recently a post about headers to news.software.readers
on April third.

I found twenty-four posts since last rotating my "outposts" file in 2014
with keywords. Seven of them were replies to you, including that one I
caught.

Can I ask why? Or what you hope to get out of those keywords?

Elijah
------
will accept "for fun" as a good enough reason

[toc] | [prev] | [next] | [standalone]


#491 — Re: Keywords header

FromVanguardLH <V@nguard.LH>
Date2021-05-06 05:52 -0500
SubjectRe: Keywords header
Message-ID<5xpuhyxthcy3.dlg@v.nguard.lh>
In reply to#436
Eli the Bearded <*@eli.users.panix.com> wrote:

> Crossposted and follow-ups set.

FollowUp-To ignored.  It is rude to yank away a conversation from other
readers in the original newsgroup to which you posted by redirecting
replies to elsewhere than the original location.

> VanguardLH <invalid@invalid.invalid> wrote:
>
>> I see you decided to steal my Keywords string.
> 
> It is a rn / trn feature to preserve the Keywords: in follow-ups. I
> seldom examine them, since they are usually blank. Checking my post
> archive I see this is not the first time you've gotten me like that.
> ...
> 
> Can I ask why? Or what you hope to get out of those keywords?

In addition to the From header, I use both the right token of the
Message-ID and the Keywords headers to make sure anyone that wants to
identify me, even to plonk me, has multiple and stable headers on which
to filter.  If they wanted to ensure their filter only targeted me, or
they wanted to ensure a search only showed my posts, and not
accidentally on someone else, they can test on:

- Path injection node 
- AND From 
- AND Organization 
- AND Message-ID 
- AND Keywords.  

Or, they could use just the From header for easy if filter definition,
too, but it's easy to catch forgers, especially since their Path
injection node won't be the same as mine (well, not for long since I use
responsive Usenet providers that can kill the forger's account very
quickly, and another reason I quit using freebie Usenet providers since
the forger would have to pay to get an account).  I give lots of
compounded targets to identify me.

  https://tools.ietf.org/html/rfc1036
  Section 2.2.9
  A few well-selected keywords identifying the message should be on this
  line.  This is used as an aid in determining if this message is
  interesting to the reader.
    
  https://tools.ietf.org/html/rfc5322#section-3.6.5
  The "Keywords:" field contains a comma-separated list of one or more
  words or quoted-strings.
  ...
  These three fields are intended to have only human-readable content 
  with information about the message.
  ...
  The "Keywords:" field contains a comma- separated list of important
  words and phrases that might be useful for the recipient.
  
I would also use the "Comments:" header to further strengthen my Usenet
identity, but my client doesn't let me add that one.  No, I'm not going
to PGP-sign my posts, because it is stupid since no one in Usenet is
going to bother doing the lookup.

While I can select a view that always shows all headers, that is usually
a bunch of noise (as is often the attribution lines where posters think
they have to add lots of duplicated info that is already available in
the headers).  I only occasionally look at all headers, so it is
possible that I previously missed someone just copying my Keywords
header into their reply.  From what I seen in many NNTP clients, they
generate their own Keywords header, if specified (non-blank), not
forward a value from what some other client specified in a parent post.
The RFC definition of the Keywords header is rather vague and very
terse.  Just didn't figure any client would not use its own value.

I don't delete any unwanted posts.  Instead my filters colorize them and
add an Ignore flag.  I use a default view of Hide Ignored Posts;
however, if I need to check my filters for false positives or someone
mentions something in an otherwise hidden post, I can just switch to the
Show All Messages view.  When I showed all messages, including the
ignore-flagged ones, I saw your post.  It was colorized, because it
originated from Panix.  So, I looked at the raw source of your message
to see your Keywords header duplicated mine instead of your client
adding its own value.  Panix has been ignored-flagged by me ever since
they decided to spamify all posts that originate at them by appending a
deliberately invalid signature (so clients that hide sigs won't work).
I wasn't interested in seeing posts by users of a spamifying Usenet
provider.

I've see Avast users, and other anti-virus program users, that spamify
their Usenet posts (and e-mails).  Avast does the same as did/does
Panix: use an invalid sigdash line followed by 1, or more, lines of spam
announcing the users employs Avast.  The default config in Avast is to
add the invalid sigblock.  I'll alert such users that they are spamming
their choice of anti-virus software, and to turn it off.  If they
continue to refuse, and because they choose to be spamming affiliates,
they'll get kill filed.  I did the same to Panix when they were
appending their invalid sigblock to all submissions.

Has Panix ceased spamifying the articles submitted to them?  I don't see
it in your posts.  Did they ever offer free trials, and those are the
submissions they spamified (as a lure to get those users to move to
their pay service)?  If Panix is no longer spammifying their articles, I
will modify my filter on them to stop flagging them as ignored.  I'll
still colorize them for awhile to watch if any spammified posts show up.

[toc] | [prev] | [next] | [standalone]


Page 1 of 3  [1] 2 3  Next page →

Back to top | Article view | alt.comp.software.firefox


csiph-web