id summary reporter owner description type status priority component resolution keywords cc component_version os os_version 8237 Encrypt passwords ftpuserd "Just found out about this due to a recurrent series of website hacks which seem on investigation to be to this error. It's really lax. Even if FZ is not being used at the time, any virus or malware can scoop up the ftp addresses, usernames and passwords. I have been recommending FZ for years, but I am now putting out an advisory to stop using it as a matter of urgency. For those using it to manage a lot of sites, a single infection on a client machine could trigger weeks of server clean-up work. And I'm frankly shocked by the developer's response to tickets and forum posts on this over the years. It borders on negligence for such an otherwise excellent tool." Bug report closed critical FileZilla Client duplicate password encrypt security yerenkov.scott@… Windows All