Firefox to burn FTP out of its browser, starting slowly in version 77 due in April
- Reference: 1584699310
- News link: https://www.theregister.co.uk/2020/03/20/firefox_deprecates_ftp/
- Source link:
In a March 19 [1]post on the mozilla.dev.platform list, developer Michal Novotny announced “We plan to remove FTP protocol implementation from our code.”
But the change will be slow. The protocol will remain in place but be turned off by default for Firefox 77, due in May 2020.
But it will remain on by default in Firefox’s extended support release version 78. Version 99 is due in early 2021!
Novotny’s explanation for FTP’s removal is that “FTP is an insecure protocol and there are no reasons to prefer it over HTTPS for downloading resources.”
“Also, a part of the FTP code is very old, unsafe and hard to maintain and we found a lot of security bugs in it in the past.”
FTP becoming Forgotten Transfer Protocol as Debian turns it off [2]READ MORE
Firefox developers have known this for almost two years: The Register reported in April 2018 that the team decided to [3]block FTP requests inside web pages way back in version 61. And if they didn’t remember that, there’s also the example of [4]Chrome binning FTP in February 2020 .
Your humble vulture occasionally hears of ancient mainframe apps using FTP within the walls of some organisations. In those environments the buggy FTP codebase and its use of plaintext data transmission might be acceptable risks. But out here on the Internet? Get the FTP outta here! ®
[1] https://groups.google.com/forum/#!topic/mozilla.dev.platform/FqCZUT9ay_o
[2] https://www.theregister.co.uk/2017/04/27/debian_to_turn_off_ftp/
[3] https://www.theregister.co.uk/2018/04/11/firefox_deprecates_ftp/
[4] https://www.theregister.co.uk/2020/02/05/ftp_deprecated_chrome/
Re: "FTP is an insecure protocol and there are no reasons to prefer it over HTTPS"
So its just an operationally difficult to manage, dual port connection protocol, that on some platforms uses an extremely wide number of random ports and if you look at available comments, even without shell, can do nice amount of reconnaissance on the target file system. Add to this even file transfers themselves are not assured delivery unless your tool of choice adds this on.. putting an S on it does not change any of these aspects.
Addressing this as just an "insecure" protocol substantially under-represents its deficiencies, and there are alternatives …
Re: "FTP is an insecure protocol and there are no reasons to prefer it over HTTPS"
"One reason to prefer it over HTTP is that is much easier to manage remote files with FTP than with HTTP - and WebDAV is not exactly a solution - plus not every machine and his e-dog runs a web server."
It has never been easy to manage remote files through any browser. Some allowed you to drag and drop files up over ftp but most were one-way, download only. And no renaming, deleting etc.
And despite its name sftp is a new protocol over a SSH transport layer with remote management functionality. You can't just slap some TLS on the existing ftp protocol to implement it - it is a substantial thing to implement in its own right.
If you want to manage a remote server you should be using a dedicated client. Either the console or something like Filezilla which supports ftp, sftp and scp. Chances are that anyone doing stuff over ftp was already doing that to begin with.
"FTP is an insecure protocol..."
http://ftp.mozilla.org/pub/
Re: "FTP is an insecure protocol..."
The clue is in the http://. Presumably somebody couldn't be bothered to change the subdomain name.
Does that mean that hosted servers are not going to use FTP anymore ?
I have two hosted servers and I need FTP to update the files and check the local versions. I am, obviously, using a dedicated FTP client to do that, but if everyone is throwing FTP to the dogs, I do hope someone is going to think of a solution because managing my hosted files via a browser would be, I believe, a pain in the neck.
I rather like LDS's idea of an FTPS. Is there a good reason not to do that ?
Re: Does that mean that hosted servers are not going to use FTP anymore ?
FTP in browsers is download only.
This doesn't stop a website from generating a directory listing of files allowing them to be downloaded using the browser (non-FTP) or applying whatever management functions they want to these files, including uploading new or updated files.
FTPS already exists, as does SFTP. I suspect that LDS was suggesting that rather calling the protocol insecure, compared to HTTP, they could just support secure FTP.
Re: Does that mean that hosted servers are not going to use FTP anymore ?
It's already being done - FTPS already exists.
However, if you are using an upload/download "file-manager" type FTP client, I'd suggest switching to an SFTP client instead of FTPS. The front ends are basically the same, but use sftp underneath. (If your servers ssh doesn't have sftp-server then most clients can emulate it to some extend using scp under the hood, but you shouldn't have that issue)
EDIT: Nick got in there before me!
Use a real FTP client
Filezilla is my go-to opensource FTP client
https://filezilla-project.org/
Actively maintained and still generating a stream of bug fixes to cope with all of those "not quite right" servers
I can see why pulling an afterthought FTP function from a browser is a good idea.
It supports FTPS and SFTP as well
"FTP is an insecure protocol and there are no reasons to prefer it over HTTPS"
There are many reasons to get rid of half-baked FTP features from a browser and leave them to a real FTP client, but that's not the right one.
Sure, FTP is as much insecure as HTTP. So add an S to it to just you did to HTTP and it becomes as secure as well. One reason to prefer it over HTTP is that is much easier to manage remote files with FTP than with HTTP - and WebDAV is not exactly a solution - plus not every machine and his e-dog runs a web server.
But I'm sure Firefox "consumer-oriented developers" meant "downloads" only, what they think everybody does only. Just they should tell it.
PS: there also reason to give some people a FTP access only and not a SSH ones to some machines. The former doesn't give you a shell into a remote machine.