Linux Fu: Improving FTP

FTP isn’t exactly cutting-edge technology. These days, if you control both ends of a connection, you’re probably using scp, SFTP, rsync, or something even fancier. But FTP refuses to die, especially if you are perusing old public FTP servers or talking to retrocomputers. Every now and then, you still need an FTP client. Naturally, there are plenty of graphical clients. But some of us would rather stay at the command line. You could just type ftp, of course. It works, and if you haven’t used it lately, it is probably better than you remember. However, I’ve long been a fan of NcFTP. While some other FTP clients have caught up, it still has unique features that make FTP a lot more productive.

Not Your Father’s FTP

Before maligning the standard ftp command, though, we should point out that it probably isn’t the FTP client you remember from 30 years ago. For example, on openSUSE Tumbleweed, /usr/bin/ftp is really tnftp, a portable version of NetBSD’s enhanced FTP client. Debian uses it too; the ftp package in both Bookworm and Trixie leads you to tnftp. Since current Raspberry Pi OS is based on Debian Trixie, you’ll encounter tnftp there, too. That’s significant because tnftp has already fixed many of the irritations you might associate with old-fashioned FTP.

You get command-line editing, history, and filename completion, things that are also in ncftp. Both understand passive FTP and IPv6. The tnftp client can also retrieve HTTP, HTTPS, and file: URLs, so commands such as:

ftp https://example.com/something.tar.gz

aren’t necessarily typos, although ncftp lacks this ability. But ncftp does have some killer features.

Remember Me?

One of NcFTP’s nicest creature comforts is bookmarks. Connect to a machine, move to a useful directory, and save it:

ncftp /pub/micros> bookmark oldstuff

Then later you can simply type:

ncftp oldstuff

The bookmark can remember more than just the hostname, making frequently used FTP sites feel much more like named resources than anonymous servers you repeatedly have to navigate.

NcFTP also maintains a cache of remote directory listings. If you’ve ever used FTP over a slow link, you know how annoying it is to ask for the same directory listing over and over. NcFTP can often work from what it already knows instead. Neither feature sounds earth-shattering, but together they make an interactive FTP session considerably more pleasant.

Get All The Things

Another difference becomes obvious when you want an entire directory. NcFTP supports recursive transfers:

get -R foo

or:

put -R foo

That seems obvious if you’re accustomed to modern tools, but traditional FTP is fundamentally organized around transferring individual files. NcFTP does the tedious directory walking for you. It also handles resuming interrupted transfers more naturally, something particularly welcome when the file in question is a multi-gigabyte disk image rather than README.TXT. With tnftp, you have to explicitly ask to resume an interrupted file. NcFTP will detect it and, depending on configuration, either resume or, at least, offer to resume the transfer.

Go Away, I’m Busy

NcFTP also has a clever background-transfer system. Commands such as:

bgget giant-file.iso

Hand a transfer to NcFTP’s spooler rather than tying up your interactive session. There are corresponding facilities for uploads. That’s an interesting distinction from simply detaching a shell command. NcFTP knows that this is a transfer job and maintains a queue of FTP work that can be retried and processed independently.

Shell Games

But perhaps the biggest reason to know about NcFTP is that NcFTP isn’t just one program. The package includes commands such as ncftpget, ncftpput, and ncftpls. These perform FTP operations directly from the Unix shell without starting an interactive FTP command interpreter. For example:

ncftpget ftp.example.com /tmp /pub/widget.bin

or:

ncftpput ftp.example.com /incoming widget.bin

This is much nicer in a script than sending commands to ftp using, for example, a here document and automating login with .netrc. For example:

ftp <<EOF
open ftp.example.com
cd incoming
put widget.bin
quit
EOF

Sure, it works, but any time you send input to an interactive program it is, at best, messy. The ncftpput program expresses what you actually wanted to do in the first place: put this file there. That’s much more Unix-like.

Don’t Do This At Home

None of these conveniences change FTP’s fundamental problem: ordinary FTP is not secure. Usernames, passwords, and data can travel without encryption. If you’re designing a new system and control both ends, you usually have much better choices. But sometimes you don’t control both ends. If FTP is something you run into, ncftp is worth knowing about. Bookmarks, cached directories, recursive and background transfers, and especially the script-friendly companion commands turn an antique protocol into something that feels surprisingly at home on a modern Unix command line.

Of course, just as you can use FUSE to mount an ssh server, you can use ftpfs, to make a remote server look like part of your file system. You never know when FTP is going to crop up.

Hackaday Links Column Banner

Hackaday Links: August 16, 2026

We’re no strangers to unusual hardware failures around these parts, but even so, a swarm of jellyfish clogging up the works is a new one to us. That’s exactly what happened to the cooling system at the Gravelines nuclear power plant in France earlier this week, resulting in three reactors having to be shut down. This isn’t even an isolated incident, as POLITICO points out that the same thing actually happened last year around this same time.

So why are jellyfish staging an annual protest against nuclear power? A warming of the North Sea has extended breeding seasons and produced larger populations of the plankton that the jellyfish feed on. This is great for the gelatinous sea creatures, but not exactly ideal if you’re trying to pump the water they live in through a complex cooling system. The French installed filter screens and monitoring systems after this happened in 2025, but clearly they’re going to need to keep working on the problem.

From a new problem to a very old one, a BBC investigation has revealed that the UK’s National Health Service (NHS) Blood and Transplant department was inadvertently leaking private patient data by sending it in the clear over the pager network. Sniffing pager messages was fairly trivial decades ago, and is even easier these days thanks to the proliferation of cheap software-defined radios and open source decoding software. Given the fragility of the underlying communication network they use, the NHS announced they were going to stop using pagers by 2021, but clearly not everyone got the memo.

Continue reading “Hackaday Links: August 16, 2026”

Fully Characterized Systems

A friend from my old hackerspace was in grad school for electrical engineering. He had a professor who would ask, when something went wrong with a student project, “Have you fully characterized the system?” It’s a good, if lofty, goal, but it also became an inside joke around the hackerspace because YOLO was our MO about 95% of the time. Head crashes on the 3D printer – “not fully characterized”. Forgot to take out the trash last weekend? Was the system fully characterized?

It’s maybe also the difference between theory and practice: In theory, there’s no difference between theory and practice, and all systems can be fully characterized. But in practice, it’s hard to fully characterize a system that you don’t yet fully understand.

Case in point: we have nine small saplings growing in our front yard, and I have to water them. It’s boring moving the hose from tree to tree, so I thought I’d take a length of hose, stopper it at one end, and drill enough holes in it so that it could irrigate all of the trees at once. I kinda characterized the system: I figured out how much water flows per minute through our hose, and divided that up into a reasonable outflow in my mind, and drilled holes that ended up being way too large.

Why? Because a length of hose has a resistance to flow, and the water came pouring out of the first few holes, while the last few were dry. It wasn’t a constant pressure system like I thought it would be. I hadn’t even thought that the drag in the hose would matter, so there was no way I would have tried to measure it. But how would I characterize this resistance anyway? You could make a hose with too-large holes and measure the falloff. (Oops, that’s exactly what I did.)

In retrospect, professional drip irrigation systems always have holes that are tiny relative to the pipe diameter, which avoids this pressure-drop phenomenon, which means that they don’t have to worry about characterizing the hose resistance. So that’s what I ended up doing. I cut the hole size in half, and later widened up some of the downstream holes until it looked about right. Not even close to fully characterized, but it works.

So now, in addition to the engineer’s “have you fully characterized the system?”, I have the hacker’s “can you avoid characterizing parts of the system?” in my mind. And a holey chunk of hose in the trashcan.

Supercon News

Just briefly, in case you missed it: Tickets are on sale now for Supercon Ten, and we’ve extended the call for participation by another two weeks. If you’re a Hackaday fan, you owe it to yourself to join us at our annual gathering.

Hackaday Podcast Episode 382: Glueballs, Borg Cubes, And Supersonic Trebuchets

It’s still hot on both sides of the Atlantic, but Kristina has a new secret weapon for staying cool without making noise. Will Elliot and the others follow suit? Time will tell.

In Hackaday news, well, there’s a lot of it. For starters, Supercon Ten tickets went on sale Thursday morning, but chances are good that by the time you read this, the early bird offering will be all pecked out. But, never fear! More tickets will be released soon enough.

Don’t want to buy a ticket, but still want to go? Submit a talk proposal that gets accepted, and you’ll be welcomed in free of charge. Lucky for you, we just extended the deadline by two weeks to August 26th.

After exhausting the news, Elliot reached into the ol’ Mailbag and found a funny anecdote from [Vik Olliver]. (Funny in that it’ll make you go ‘hmm’.) A brief discussion about imperial vs. metric ensued, but then it was on to the hacks.

Check out the links below if you want to follow along, and as always, tell us what you think about this episode in the comments!

Download in lovely MP3.

Continue reading “Hackaday Podcast Episode 382: Glueballs, Borg Cubes, And Supersonic Trebuchets”

This Week In Security: BugTraq, AI Hacks, And Being Dumb On Planes

After a multi-year hiatus, the venerable BugTraq mailing list is back!

For decades, BugTraq was the place where vulnerabilities were disclosed, from the early days when nearly all vendors viewed all security research as a hostile force, through to the modern era of working with vendors to coordinate disclosing bugs. With the rise of bug bounty programs and other social changes, the mailing list slowly died: what started in 1993 ended in 2021 is returning. The new maintainer, Jonathan Brossard, says in his announcement “The mission is unchanged: full disclosure, researcher-first, no corporate filter.”

Don’t Be Dumb on Planes

In the unlikely event anyone here needs to be told: Don’t do dumb things on planes.

It seems that someone coming home from from the DEF CON hacker conference in Las Vegas decided to mess with the in-plane WiFi, and is likely now in the “find out” phase of doing something dumb. There hasn’t been any public followup beyond the original reports: a passenger on a Delta flight leaving Las Vegas brought up a fake WiFi hotspot named “Delta WiFi FAST” to trick other passengers into connecting, and attempted to disable the in-flight WiFi using a denial of service attack.

Continue reading “This Week In Security: BugTraq, AI Hacks, And Being Dumb On Planes”

Supercon Ten Tickets On Sale Now

Hackers, start your engines! We’re opening up ticket sales for our tenth, the 2026 Hackaday Supercon, to take place Nov 6-8 in Pasadena, CA. As always, because we haven’t announced the full slate of talks yet, we’d like to give the Hackaday True Believers out there a bonus: early bird tickets for $150 instead of the regular price of $296 (plus fees). If you know you want to attend (and you know that you want to attend) do not delay and order your tickets now!

As we mentioned before, there are a few exciting changes coming to this year’s Supercon. First off, we are moving to a larger venue on Saturday and Sunday: a few blocks south at the ArtCenter South Campus. We’re looking forward to two larger stages, more room for attendees, and more space to spread out and hack. No longer crammed into a cozy alley, we’ll sprawl out in a luxurious courtyard.

We have more tickets available than ever this year, which is great because Supercons past have all sold out. But we’re not expanding so much that we’ll lose the killer signal-to-noise ratio and friendly hacker atmosphere that makes Supercon our favorite con.

But do get your tickets soon! Whether you get in at the True Believer rate or not, Supercon is a bargain. Two and a half days of fully catered hacking and entertainment, plus the great talks, make it a bargain. Then we throw in sweet hackable badge over the top. But it’s truly the assembled crowd that makes it a priceless experience.

If you’re a Hackaday Supercon regular, we look forward to seeing you again soon! If you’ve always wanted to attend, but never pulled the trigger, the nice round number of Supercon Ten is a great excuse.

Of course, the best way to attend any convention is as a presenter, and our call for proposals just got extended for another two weeks. If you have something you’d like to say: let us know soon!

Procrastineers Rejoice! 2026 Supercon Call For Participation Extended

A few weeks ago, we put out the call for participation for this year’s 2026 Hackaday Supercon, taking place in Pasadena, CA this November. Today was going to be the deadline, but like you, we often let things pile up and put things off, so we’re extending another two weeks until August 26th.

Which is not to say that we haven’t heard from a ton of you! We’re psyched to see so many familiar Supercon regulars on the list, but we also love to see first-timers give talks. We try to make sure that new folks get their time to shine, so if you’ve never given a Supercon talk before, or if it’s been a few years, take this as your cue to present in front of the friendliest audience of like-minded hackers around.

This year is Hackaday’s tenth in-person Superconference, and to celebrate we’ve gotten a larger venue, so more folks can watch the talks live. We’ll be running two tracks as always, and you have your choice of a 20-minute or 40-minute slot. Presenters get in free, and we’ll get you an early-bird ticket rate the submission, so don’t delay and register for your slot today! Or at least before August 26th, because we won’t extend the deadline twice.

Oh, and if you’re interested in tickets, swing by Hackaday about this time tomorrow — we’ll have some news for you.