News: 1645173012

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

File suffixes: Who needs them? Well, this guy did

(2022/02/18)


On Call Welcome to another edition of [1]On Call in which minnows get munched and a Register reader recalls the headaches caused by the file extension shenanigans of a certain tech giant.

Our story today comes from "Rob" (not his name) who was working for a London-based tech company recently snapped up by one of their commercial clients keen not to lose access to their services.

"The result was that we found ourselves subordinated to their IT people in New York," said Rob, delicately adding, "who were most remarkable for how keen they were."

[2]

Unsurprisingly, it didn't go swimmingly. The Grand Poobahs over the Atlantic were not fond of their new subordinates' habit of not always following orders (normally when those orders would have resulted in the business foundering on the rocks of IT borkage). "One guy had a particularly high opinion of himself," remembered Rob, "and talked to me slowly in order that I could fully understand the complexity of whatever inappropriate or misconceived foul-up he was trying to persuade me to implement.

[3]

[4]

"Helpfully, he also pointed out how very significant their business was and how insignificant ours was."

Communications were always very polite, but we get the feeling that neither party would be buying the other a beer any time soon.

[5]

Hands needed to be joined across the Atlantic so Rob's bête noir had spun up a Windows Server VM, the sole purpose of which was to connect with the ones in London "to establish some kind of gateway between our domains, the exact function lost in the mists of time." This was, after all, more than a decade ago.

However, Rob did remember sending over the credentials for the link in a password-protected archive. All his counterpart had to do was stick the details into a file called credentials.txt , import it into the software, and lo – data would flow from nation unto nation.

But nothing happened. "A couple of days passed in which I was expecting at any moment to be told that the new gateway was up and running," Rob said, "but news came there none. No email, phone, fax, telex, telegram or pigeon arrived, no smoke signals were visible, no sound of conchs or drums. Nada."

[6]Real-time software? How about real-time patching?

[7]No, I've not read the screen. Your software must be rubbish

[8]Bouncing cheques or a bouncy landing? All in a day's work for the expert pilot

[9]Why should I pay for that security option? Hijacking only happens to planes

As Rob was pondering what could have happened, the phone rang. It was his US colleague. He had been unable to persuade the credentials.txt file to import. He sounded a bit sheepish, but we're sure there was an undertone of "this must be your fault" to proceedings, judging by Rob's descriptions thus far.

"When I offered to take a look, somewhat to my surprise he immediately accepted the offer and gave me the information I needed to log in to the new VM."

[10]

The joys of remote access thankfully existed back then so Rob began working through the instructions. Yep, there was the credentials.txt file. Yes, it was in the right place. He opened it in Notepad (which "even helpfully told me that it was dealing with a file called credentials.txt "). Still all good, and no naughty characters where they shouldn't be.

His colleague breathing down the phone, Rob pondered. "Then I used File Explorer to look at the file's detailed properties..."

Aha.

As a bit of background, Rob had set up hundreds of Windows Server VMs in his time and there was a standard list of setup tasks involved, some management software to install, and some tweaks to be made to the UI. "Microsoft, in their brilliance, had decided that none of its users on any machine or in any environment needed to see those stupid file suffixes, so they changed the default to hide them."

Thus one of the standard steps (in those days) was tick the filename extensions box to ensure they were visible.

Being the Grandest of Poobahs, his US pal had not bothered to check the box. The result was a file that looked like credentials.txt but was actually credentials.txt.txt and therefore would not import. It was in a folder with no other files so, to be fair to the user, the problem was not immediately obvious. Over the course of two days, Rob's colleague had struggled with the issue, been suspicious of the contents of the file and the competence of our hero. However, he missed the fundamental issue of the file name, which looked fine. So he'd made the call.

And now he would have to choke down some humble pie as well.

It took Rob less than 30 seconds to fix the problem followed by an intensely satisfying 10 minutes explaining it to the caller. "I was sure that could hear the sound of the gnashing of teeth," he recalled.

"Oh, the joy, the joy."

"After that we spoke less frequently, and when we did so, I couldn't help but notice that he sounded haunted and defensive, and no longer patronising," said Rob. "Then one day he was no longer there."

"Was it something I said?"

At least Rob was able to make use of the magic of remote access. Ever had to diagnose something similar, but with only the heavy breathing of the telephone caller to direct you to the always-simple problem? Tell us with an email to [11]On Call . ®

Get our [12]Tech Resources



[1] https://www.theregister.com/Tag/on-call

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/columnists&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yg98W1iXMZiUB26uduWhqgAAAAE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/columnists&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yg98W1iXMZiUB26uduWhqgAAAAE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/columnists&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yg98W1iXMZiUB26uduWhqgAAAAE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/columnists&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yg98W1iXMZiUB26uduWhqgAAAAE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2022/02/11/on_call/

[7] https://www.theregister.com/2022/02/04/on_call/

[8] https://www.theregister.com/2022/01/28/on_call/

[9] https://www.theregister.com/2022/01/21/on_call/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/columnists&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yg98W1iXMZiUB26uduWhqgAAAAE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] mailto:oncall@theregister.com

[12] https://whitepapers.theregister.com/



45RPM

File extensions are a horrible anachronism. I can’t understand why they’re still needed in most cases (all binary files should have a specification which mandates the use of a magic number - that some don’t just means that the specification of these outliers needs updating).

In fact the only possible use-case I can see is for text files which might contain different content (c code, c header) but even that might not be necessary in many cases - it should be possible to identify html or xml just by looking at the first few characters.

Extensions and the workaround of enabling them to be hidden just brings confusion and dismay. It’s a nasty throwback to the days of CP/M!

Paul Crawford

They are handy for humans to see from a list of files what they might be.

But equally they are a dumb idea to use for what happens with them once you get in to execution of binary/script. And DUMB with a monster-sized D when you look at MS's bone headed idea of hiding the extension but still using it to decide what to run if double clicked. Morons, morons, morons...

John Riddoch

file.txt.exe or file.pdf.exe being favoured filenames amongst those attempting to hack into computers, of course. If you're paying close enough attention, you might spot the duplicity, but it's easy to miss. Dumb UI choice, presumably in the name of "simplicity".

Pascal Monett

Dumb UI choice made by Marketing overriding Engineering, something that never should have been allowed but, Ballmer.

'Nuff said.

Doctor Syntax

"MS's bone headed idea of hiding the extension but still using it to decide what to run if double clicked."

I'd used KDE's Create New facility to create a LibreOffice text file but not noticed when I renamed it that I'd overwritten the whole of 'LibreOffice Writer.odt' instead of just the first part, leaving it without the extension. LO opened it OK and saved it, the GUI showed the correct icon. Nothing I used needed to see the extension to know what it was. I didn't notice at all until someone I'd emailed it to replied to say she couldn't open it with LO in Windows.

Still humans in the mix here not just machines

Ali Dodd

"it should be possible to identify html or xml just by looking at the first few characters" so you have to open the file??? Trusting the OS to identify it is recipe for disaster and doesn't work in a text interface.

How about you have a simple convention, say a 3 letter label on each file so it's easily human readable in every context to at least get an idea of what it contains BEFORE you look inside it.

They never should've been hidden imho, that way lies pain and confusion.

Re: Still humans in the mix here not just machines

JulieM

"it should be possible to identify html or xml just by looking at the first few characters" so you have to open the file??? Trusting the OS to identify it is recipe for disaster and doesn't work in a text interface. That's literally what the `file` command does.

Reading data from a file is not inherently dangerous. What's dangerous is executing instructions from an unknown file.

Re: Still humans in the mix here not just machines

45RPM

This is true. But even reading data can be dangerous - although I’m don’t know of any vulnerabilities in file off the top of my head.

But I really shouldn’t be thinking at all today.

Re: Still humans in the mix here not just machines

2+2=5

> This is true. But even reading data can be dangerous - although I’m don’t know of any vulnerabilities in file off the top of my head.

There have been a couple of "text of death" type bugs in Android and iPhone that meant nasties could happen simply by receiving a text. And there has been at least one image format exploit where opening a crafted image triggered a buffer overflow exploit. And, most recently, even logging (in Log4J) data can cause grief.

Re: Still humans in the mix here not just machines

Doctor Syntax

"That's literally what the `file` command does."

Yes, but you're talking about a real operating system there.

Re: Still humans in the mix here not just machines

45RPM

@ali dodd

Damn! Absolutely correct - have a thumbs up. Of course it could be unwise for the OS to have to probe into each file to get its type. That way malware lies. So the only issue is the hiding of the extension.

So obvious. So right. I’m going to blame my previous oversight on the fact that I’ve currently got Covid and any thinking is hard work.

(Shuffles back to bed in disgrace)

Re: Still humans in the mix here not just machines

tip pc

So obvious. So right. I’m going to blame my previous oversight on the fact that I’ve currently got Covid and any thinking is hard work.

(Shuffles back to bed in disgrace)

Is that what is meant when people mention COVIDIOTS?

Re: Still humans in the mix here not just machines

Doctor Syntax

Get well soon.

It should be safe enough for the OS to look at a few bytes to look at the magic number or other diagnostics.

file extensions

Hans Neeson-Bumpsadese

I find file extensions incredibly useful for organising things. For example, right now I'm doing some design work for a couple of projects, and I have Project1.docx and Project1.pptx open alongside Project2.docx, Project2.xlsx and project2.pptx

Dinanziame

Nowadays, file extensions are not really used by the computer — they're used by humans who want to know the file format. It's a buggy system, since the extensions can be wrong. The Word document can have .txt extension, the .html file can be a JPEG.

When you are using a GUI, you can have icons that do the same job, but you are not always using a GUI; the GUI often just repeats what the extension claims without checking; and the GUI might not even understand the proprietary format.

But personally, I'll keep using extensions. I'd rather have some indication of what the file format is, and hope it was set properly, rather than having to guess every time.

DJV

Of course, that never stops people thinking they can change a file type just by changing the extension. I had that recently on a website I built for a client where one of the client's staff had "helpfully" renamed some PNGs to a JPG extension and then complained that some resizing code wouldn't work on the affected images. I added a "deep code" check along with a warning when images were discovered with the incorrect extension.

the spectacularly refined chap

Magic numbers are not reliable either. There is no universal location or format for the magic string and so files can and do get misidentified. At least with extensions they are under the control of the user.

There are plenty of other cases too, such as layered formats such as .tar.gz or formats that package multiple elements in a single .zip. Using magic all you see is the outer container.

Finally it's an expensive way of doing it. Every file needs to be read and compared against a long list of possibilities. What if you are looking at a remote FTP server for example where you want as many clues at the directory level as possible.

Tim 11

surprised it took that long. The first thing I do when logging onto any server is check that explorer setting

Paul Crawford

You would like to think that any admin account, and ANY account on a server, would not be used by people afraid of file extensions, so would be disabled by default?

phuzz

That and unticking "Hide system files".

Lots of files with the same name

Emir Al Weeq

I remember when Microsoft did that trick of hiding the extensions, I was working on something using file names like:

projectname.txt

projectname.doc

projectname.xls

Oh fun! Yes, I could have learned to differentiate the subtle variations on the icons, but life's too short: I enabled extensions.

Re: Lots of files with the same name

Hans Neeson-Bumpsadese

I could have learned to differentiate the subtle variations on the icons, but life's too short

Not only is life too short, but so is my sight - in a lot of views the icons are too small for me to make out at a glance which is which.

Re: Lots of files with the same name

Fading

The icon showing is dependent on the associated program - hence with only a little nefarious fiddling you could have all the icons the same as well.

Re: Lots of files with the same name

Anonymous Coward

I think you only get the option(*) to associate a program now, so you get the icon for that program... used to be fun trawling dlls for useful icons

(* at least I haven't seen the option in Win8/8.1/10)

Control panel

pavel.petrman

Oh yes. The hidden file extension must have worked so well, that Mirosoft decided to build the whole control panel for Windows 10 the same way.

tiggity

They are useful for ordering data in a directory / folder / whatever you want to call it.

Very handy to search by extension.

Only problem with filenames is windows default of hiding them, irritating when app, config file / manifest etc then all appear just as the same name (as only the suffix identifies the difference)... and Windows irritating icons for identifying file type are far from ideal.

Competition time!

jonathan keith

I honestly can't think of a good reason for hiding file extensions in the first place. Not one.

A pint of --> for anybody who can.

Re: Competition time!

Aladdin Sane

File extensions can be changed using the rename function. If they're hidden then they can't be changed. It removes the opportunity for fuck ups.

Pascal Monett

It allows miscreants to send you Word.doc.exe and you see Word.doc and you execute it.

A big, fat FAIL in my book.

I prefer the opportunity for fuckups - they're my fault.

Re: Competition time!

AdamT

To look more like Apple?

Yes, I get that people's opinion on whether being more like Apple is a good or bad thing may vary but, around that time, Apple's look/feel and general user experience (for the non-techy at least) was better/cleaner. Personally it's not my taste but for many (e.g. my mum) picking Apple over Windows was a no-brainer and I think MS wanted to try and get some back.

Re: Competition time!

Totally not a Cylon

"To look more like Apple?"

I just checked and at least on Monterey you can hide extensions on a per file basis....

what fun?

Users!

Skiron

In my IT job over 12 years, a lot of the users were a bit clueless, and for some reason a lot of them used MS Word 'open' file dialogue to browse/search for files.

Of course, the file naming convention was just a stupid - a lot of word/excel names were the same, so all the files looked the same.

Enter the guessing game. The amount of times they opened excel files in word, and now the checkmate - the first thing they did was SAVE IT!

In the end my boss told me to ignore any request to restore these files.

This should be a setup item at best

Curtis

I've been railing on this "feature" since the Windows ME days at LEAST. Working front line support for an OEM, and having to talk grandma and grandpa through finding a file and the extensions are hidden is a nightmare. It got to a point that one of our first support steps was to disable "Hide file extensions for known file types" early in any call, and when reinstalling Windows would have the customer do this as soon as possible.

Anonymous Coward

Oh the fun caused by those dodgy 'file save' dialogues, where selecting something like 'file type: *.txt' then typing 'credentials.txt' would save it as 'credentials.txt.txt'

And the fun of forgetting to set the correct 'file type' then discovering 'credentials.txt' is saved as 'credentials.txt.rtf'

Pascal Monett

Yes, hiding file extensions really was a brilliant marketing idea.

Eh, Ballmer ?

Been there

Outski

Conversation with a usually competent colleague:

Him: I can't import this certificate

Me: Oh really? Let's have a look...

[Quick screen share]

Me: Right, so what you've got isn't cert.crt, it's cert.crt.txt, turn on your bloody file extensions

Him: D'oh, thanks, sorry Outski and rest of the team whose time I've wasted

----> one of many beers owed by the left pondian team for dumbass mistakes

If you think that's bad

JulieM

I wrote a nice web app where suppliers could upload data straight into our systems from a CSV file, to save me from 20 minutes of mucking about with awk every time anybody e-mailed us a spreadsheet. I already had a collection of headers, so I used them to make it smart enough to work out -- within limits, but those limits were still pretty broad -- which column was what.

Within minutes of putting it live, I had a customer on the line insisting that it was not accepting their .csv file.

It transpired that, instead of following the clear instructions with screenshots showing where to change the file type in OpenOffice.org Calc and Excel, they had simply used whatever the Windows equivalent of `mv` is to change the extension of an .xlsx file .....

Pascal Monett

Unfortunately, being stupid is not a disqualifying criteria for using a computer.

And if you think that just changing the file extension from xlsx to csv changes the file format, then you're too stupid to use a computer.

More unfortunately, there are many, many people who haven't got a clue what a file extension means, but they're still employed and using a computer.

That's the employer's fault : he doesn't know what a file extension means either.

Re: If you think that's bad

ColinPa

On the mainframe we had to worry about sources files in ascii and EBCDIC, and there was a setting which set the code page on the file. The various zip/pax commands did not always work.

Our simple instructions gave a nice little process for doing the work.

Some "clever" Windows expert thought 'I can do this with less typing and make it "quicker".' as a result his data was always in the wrong code page.

My colleague was on the phone for an hour trying to work out what the problem was.

The end of the conversation went

"Do step 1"

"Ok I've done step 1"

"Are you sure?"

"Yes"

"hmmm - what was the response from the command"

"xyz"

"But that's not the response from the command. It looks like you used the abc command"

"Well it works just well"

"No it doesn't it. Follow the instructions"

"OK Ive done step 1"

"Now do step 2"

"what response did you get?"

"That's not the response from the zyx command"

Loop:

Ian Johnston

Every file should have (a) an extension and (b) a version number. VAX/VMS roolz ok.

GlenP

VMS did have it's problems though, since devices and files were analogous.

Back in the mists of time when I worked at the local college (now university) we had a student type up a long dissertation about an on-site facility then save it, unfortunately she used the facility name which was also a printer in that facility.

Result was no file and a student in tears.

Once we figured out what had happened we retrieved the print out and got one of the department secretaries (I told you it was a long time ago) to retype it and save it under a different name.

It's magic

MrBanana

I've gone through the process of explaining to the noob about the possibility of the file extension being missing, wrong, or hidden. Use 'file wibble.xxx' and you'll get a fair idea of what you are dealing with, not infallible but good for 95% of cases, I say. That's magic they say. Yes it is: 'man 5 magic'.

extensions and version numbers

unbender

An ICI power station many years ago with a snazzy new VAX 11/780 optimising the combustion process. VAX/VMS introduced version numbers, so the filenames were all in the format filenames.ext;version (IIRC 9.3;3 characters), every time you edited a file it was saved in a new file with an auto incremented version number which saved many people's bacon over the year.

Space was always an issue as the HDDs were only 128MB, so the OS provided a handy utility to purge the old versions down to a sensible level.

The designers of the system came from PDP land and decided that these newfangled version number things could be utililised for something more useful. So cue a directory filled with files named thus:

tempinput.dat;1

tempinput.dat;2

tempinput.dat;3

.

.

.

tempinput.dat;150

Each one contained all of readings taken every 15 minutes for an individual sensor.

I (being a newbie muppet at this point) typed PURGE/KEEP=5 across the entire disk and left the scene of disaster chuffed at the amount of space that I had recovered.

wyatt

I hate that setting, first thing I change when working on a system.

Nothing will ever be attempted if all possible objections must be first
overcome.
-- Dr. Johnson