Ghost FTP 0.30.12
Release date: 6 October 2026
Ghost FTP 0.30.12 is a privacy and security hardening release across Windows, Linux, Android and macOS.
Windows / Linux
- Hardens encrypted backup export and restore with explicit encrypted-file and decompressed-size limits.
- Requires newly exported encrypted backups to use a non-trivial password, caps pathological password input before Argon2 work, and preserves compatibility when opening older backups.
- Rejects crafted backup credential records that target keychain namespaces outside Ghost FTP.
- Zeroes derived backup keys and decrypted/compressed plaintext buffers after use, overwrites serialized credential/config copies in memory immediately after encryption input is built, and wipes backup passwords/API keys/Bearer headers at the Rust command boundary after use.
- Stops credential-bearing MCP child-process stderr from being reflected into the UI, preventing third-party CLI argument echoes from leaking Bearer tokens through diagnostics.
- Guarantees cleanup of temporary SQLite backup snapshots on success and failure paths.
- Writes restored staging files with private owner-only permissions on Unix platforms.
- Adds release-blocking contract checks and Rust tests for the new backup security boundaries.
Android
- Enables secure-window protection so sensitive Ghost FTP screens are excluded from screenshots and non-secure display capture.
- Rejects obscured touches on password and action controls to reduce tapjacking risk.
- Stops retaining persistent Storage Access Framework document permissions for uploads and settings restore.
- Cleans up legacy persisted document permissions left by older builds.
- Retains no-backup, no-cleartext, non-persisted-password and strict SFTP host-key / FTPS hostname-validation protections.
macOS
- Stores remembered passwords as non-synchronizing, device-only Keychain items accessible only while the device is unlocked.
- Bounds restored profile backups to 256 KiB and 512 profiles.
- Rejects restored profile fields containing control characters or oversized identity/host values.
- Applies owner-only POSIX permissions to exported profile backup files.
- Adds unit and production-contract coverage for the new privacy boundaries.
Protocol security status
- Windows/Linux retain strict TLS certificate/hostname validation and strict SSH host-key verification.
- Android retains explicit FTPS hostname verification and pinned SHA-256 SFTP host-key verification.
- macOS plain FTP remains functional; FTPS and SFTP file operations remain blocked until their certificate/hostname and SSH host-key verification engines are complete.
- macOS remains an ad-hoc-signed development Preview until Developer ID signing and notarization are available.
Release metadata
- Version: 0.30.12
- Previous canonical release: 0.30.11
- Build: 2026.10.06.4
- Android versionCode: 301201
- Channel: stable