From owner-freebsd-current@freebsd.org Thu Sep 17 15:12:35 2020 Return-Path: Delivered-To: freebsd-current@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id E01FC3E3A25 for ; Thu, 17 Sep 2020 15:12:35 +0000 (UTC) (envelope-from brooks@spindle.one-eyed-alien.net) Received: from spindle.one-eyed-alien.net (spindle.one-eyed-alien.net [199.48.129.229]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 4BsgSM47yXz46kZ; Thu, 17 Sep 2020 15:12:35 +0000 (UTC) (envelope-from brooks@spindle.one-eyed-alien.net) Received: by spindle.one-eyed-alien.net (Postfix, from userid 3001) id 35ED73C0199; Thu, 17 Sep 2020 15:12:34 +0000 (UTC) Date: Thu, 17 Sep 2020 15:12:34 +0000 From: Brooks Davis To: Gleb Popov Cc: Cy Schubert , Ed Maste , FreeBSD Current Subject: Re: Deprecating ftpd in the FreeBSD base system? Message-ID: <20200917151234.GA92193@spindle.one-eyed-alien.net> References: <202009171404.08HE4fZj007939@slippy.cwsent.com> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="nFreZHaLTZJo0R7j" Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.9.4 (2018-02-28) X-Rspamd-Queue-Id: 4BsgSM47yXz46kZ X-Spamd-Bar: ---- X-Spamd-Result: default: False [-4.00 / 15.00]; REPLY(-4.00)[]; ASN(0.00)[asn:36236, ipnet:199.48.128.0/22, country:US] X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.33 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 17 Sep 2020 15:12:35 -0000 --nFreZHaLTZJo0R7j Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Thu, Sep 17, 2020 at 06:43:16PM +0400, Gleb Popov wrote: > On Thu, Sep 17, 2020 at 6:05 PM Cy Schubert > wrote: >=20 > > I've been advocating removing FTP (and HTTP) from libfetch as well. Peo= ple > > should be using HTTPS only. > > >=20 > Isn't this a bit too much? I often find myself in need to download > something starting with "http://" or "ftp://" and use fetch for this. Yes, let's remove access to instance metadata on several (hundred-?)million AWS instances. -- Brooks --nFreZHaLTZJo0R7j Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQEcBAEBAgAGBQJfY3zhAAoJEKzQXbSebgfAmacH/3LXIYMF1ZOrZKoXiZ8nVzMO qhCUr+1JA9L13UOPpTC2rqNWrFL07sGhIS//t6QEweTUBha9fdjSU8c2r3JywrDq eYn/swSTCeAErLz62DbmPOdbe62Jopw6aEvmQXlVsIjnfoCs9CNZcHME7U1ot/hD qM0b+OyUoK7rZc87vOoaoHKwwzyqsVcufGBo7XDc1G6QvtFi/7iaGoZv+FrN+1Bm JQ7JZWgRAAJ17onFp9U1pJZtES/F+bT92W4xSaBpR+gZhCLV1D2FtYXMX/w/xUB0 Nxw09BGEc8pQxfSefPrlNMHnC6HEua4pBKy+69/2+OWKx3jlpipyLeH9srkojjI= =/5Fc -----END PGP SIGNATURE----- --nFreZHaLTZJo0R7j--