2026-09-18 14:37 UTC
What's the current security industry thinking on public-facing password-protected FTP servers? Is there any new thought on that? Any "don't do that, replace it with this"? Last time I dealt with this, SFTP was the answer, or just not doing it that way? Anything new is news to me, and I'd love to hear it.
Replies (4)
-
@danielcornell@mastodon.social 2026-09-18 14:58
@Sempf@infosec.exchange These days I recommend that all data communications be done via random German wiki accounts
-
@Sempf@infosec.exchange 2026-09-18 15:08
Thank you all very much. I'm glad to see that nothing has changed. I guess I don't even know what to say. An FTP server, really? What is this, the 90s?
-
@nerdpr0f@infosec.exchange 2026-09-18 14:41
@Sempf@infosec.exchange Last I saw, SFTP was the recommendation. If there's a business reason why that can't be done (which I've seen once or twice), require file-level encryption.
-
@FritzAdalis@infosec.exchange 2026-09-18 15:47
@Sempf@infosec.exchange We did files.com, which allowed us to turn off the serv-u ftp server.