Oh ... Fudge This Pandemic! Google walks back on decision to switch off FTP in Chrome 81
- Reference: 1586957408
- News link: https://www.theregister.co.uk/2020/04/15/ftp_chrome_deprecation_on_hold/
- Source link:
The Chocolate Factory has been keen to kill off the venerable protocol for some time, and after a succession of prunings, disabled it by default in version 81 having [1]tinkered with disablement in version 80 . The plan, according to Google, was "to deprecate and remove this remaining functionality rather than maintain an insecure FTP implementation." At least up until the pandemic hit.
Last week (as first [2]noted by BleepingComputer ) a Google engineer [3]posted: "In light of the current crisis, we are going to "undeprecate" FTP on the Chrome stable channel. I.e. FTP will start working again."
The reprieve is temporary, as he added: "We'll recommence the deprecation once people are in a better position to deal with potential outages and migrations."
While only a fraction of the browser's users still use it to access FTP sites, that fraction is a whole lot of people when one considers the sheer size of Chrome's userbase. A swift query using Google's own search engine also shows up an awful lot of governmental sites still making data available via FTP sites.
Google is not the only browser maker with FTP in its crosshairs. Rival Mozilla also plans to strip the relic from its code by the start of 2021 and had initially planned to adopt a similar approach of sticking the protocol behind a setting and leaving it disabled.
However, as March drew to a close it backed away as an engineer [4]commented : "In light of recent events, we will only disable FTP in Nightly, starting from 77. FTP will remain enabled in release until further notice." ®
Sponsored: [5]How To Accelerate Brilliant Digital Experiences With Low-Code
[1] https://www.theregister.co.uk/2020/02/05/ftp_deprecated_chrome/
[2] https://www.bleepingcomputer.com/news/google/google-reenables-ftp-support-in-chrome-due-to-pandemic/
[3] https://bugs.chromium.org/p/chromium/issues/detail?id=333943#c43
[4] https://groups.google.com/d/msg/mozilla.dev.platform/FqCZUT9ay_o/Sa327-ufBQAJ
[5] https://go.theregister.co.uk/tl/1936/-8552/how-to-accelerate-brilliant-digital-experiences-with-low-code?td=wptl1936
Re: and here's the proof.
If you're worried about Javascript driven trackable shiny why are you using a browser as an ftp client?
Re: and here's the proof.
I'm happy to use a browser as an FTP client knowing that if I do there's no JavaScript-driven trackable shiny. Point your question to Google, why are they unhappy there's no JavaScript-driven trackable shiny?
Re: Obsession with JavaScript-driven trackable shiny
Doesn't Google want to axe it for some nefarious reason to do with $$$ ?
Re: Obsession with JavaScript-driven trackable shiny
I completely agree with this!
@Dan 55
I agree that it doesn't have to be removed, but conversely, a browser should just browse (at least in my mind). I'm not looking for a single Swiss-army penknife that has the potential for more and more security bugs.
I wonder if they will remove other protocols from Chrome that are a security risk - examples could include their PDF viewer, since PDF's have security issues too. Oh and JavaScript - that can be used for bad things too.
I wonder what their real aim is ? Removal of insecure transfer protocols, even though much of what is FTP'ed is using the anonymous user anyhow and if people want to do secure FTP, then there is always SFTP and FTPS.
Personally, I'd prefer if they left the choice to users who can determine whats right for them, rather than someone doing a nanny knows best approach.
It's a fair point about PDF but a balance should be struck somewhere, nowadays vast majority of users are not power users and if they have to have a separate piece of software installed as a PDF viewer that means it has to be kept up to date as well as the browser, and if they don't they'll be more succeptible to being offered malicious or dangerous viewers (*cough* like the adobe one *cough*), while a browser one could be sandboxed and would "just work" (hopefully (who am I kidding)) and would have more frequent updates.
Don't GAS
I deprecated Chrome years ago.
Bin it and focus on security. Just because people are working from home doesn't mean they can't find another way to transfer files insecurely.
> The change was made "via server-side configuration."
So does this mean Chrome phones home to check for configurations?
Or does this just mean they changed their build config? If so, why would they state it in such a strange phrasing?
they seem to say the old code is hard to maintain
But I just keep thinking that generic plain text ftp which is probably 99% of ftp sites out there hasn't changed much at all in probably 20+ years so there shouldn't really be much of anything to maintain.
I don't use ftp too often, and generally when I do I use ncftp.
Checking ncftp's changelog they released version 3.0.0 in March 2000, now they are at 3.2.6(from late 2016), for a dedicated ftp client just a point as to how little ftp has changed over the past 20 years.
Obsession with JavaScript-driven trackable shiny
There's no real reason to axe FTP support, and here's the proof.