Merlin’s weekly podcast with Dan Benjamin. We talk about creativity, independence, and making things you love.
Merlin’s weekly podcast with Dan Benjamin. We talk about creativity, independence, and making things you love.
”What’s 43 Folders?”
43Folders.com is Merlin Mann’s website about finding the time and attention to do your best creative work.
Panic's stevenf: Time to Dump FTP
Merlin Mann | Jul 14 2008
stevenf.com ("Don't Use FTP") Steven Frank, one of the boys wonder behind Panic and their excellent Transmit app says it’s high time to dump FTP in favor of its smarter, sexier sister, SFTP. Of which Steven says “It’s secure, it’s consistently implemented, and it’s machine-readable.” A lot of people who have used FTP daily for years are surprised to learn that they're sending everything in the clear -- that means the stuff you're uploading as well as your actual password. Makes you think twice about what you're throwing through the air as you update your blog templates via "free WiFi." Steven says:
I agree. If you're unsure whether your host will let you do SFTP (and SSH in general), ask. You may indeed need special permission (many providers "jail" garden-variety users in a way that disallows SSH without special permission). You may also need to find the correct port. On my host, A2, for example, you have to run SSH and SFTP on the unconventional port 7822, but it works like a charm once you're up. Great suggestion, Steven. Worth getting the word out. 9 Comments
POSTED IN:
SFTP has its problems, tooSubmitted by Nate on July 14, 2008 - 1:59pm.
That's silly: SFTP has problems of its own. There's no perfect solution, but most regular FTP servers can support SSL or TLS encryption, making them secure. Many of his other complaints are legitimate issues from his point of view as someone who writes an FTP client. But from a hosting provider's point of view:
To mitigate these problems, you can use various "fake" shells that provide just enough functionality to support SFTP. But that's kind of dodgy and not nearly as simple as the virtual users approach. For small-scale use (i.e., a few users whom you trust with a shell account), SFTP is great. For commercial users, FTP-TLS can be a better choice, especially if you only want to enable file transfers and aren't looking to give every user a shell account. With that said, if your hosting provider doesn't provide SFTP or FTP-TLS, then yes, dump them! » POSTED IN:
|
|
EXPLORE 43Folders | THE GOOD STUFF |