FTP vs FTPS vs SFTP for cameras: what actually changes?
Compare camera FTP, FTPS, and SFTP encryption, ports, passive data connections, certificates, SSH host keys, and model-specific support.
The short answer
Use SFTP when the exact camera supports it and field testing confirms the host-key flow. Use explicit FTPS when SFTP is unavailable but the body supports FTP over TLS. Treat unencrypted FTP as a narrow compatibility path. Don’t use it as the default for credentials or media crossing the public internet.2,4,6
Similar menu labels hide different transports.
FTP is the original file-transfer protocol, with separate control and data connections. FTPS adds TLS to FTP through the extensions RFC 4217 defines. SFTP is a different file-transfer protocol carried over SSH. It doesn’t share a specification with FTP.1,4,6
| Protocol | Typical control port | Encryption | Network behavior | Camera-side trust |
|---|---|---|---|---|
| FTP | 21 | None by default | Separate control and data connections; passive data ports matter | Username and password |
| Explicit FTPS | 21 | TLS negotiated with AUTH TLS | Keeps FTP’s separate data connection model | TLS certificate behavior varies by camera |
| SFTP | 22 | SSH transport | One SSH connection carries file operations | SSH authentication / host-key behavior varies by camera |
FTP-family ingest is a firewall problem as well as a login problem.
The FTP specification separates the control connection from the data connection that carries directory listings and files. In passive operation, the server supplies an address and port for the client to open. Build your gateway with a deliberate passive-port range, public address advertisement, firewall rules, and per-session isolation.1,3
FTPS protects FTP. It doesn’t replace FTP’s connection model. RFC 4217 defines AUTH TLS and protection levels for the data connection. Test the authentication step and the media channel separately to confirm both are protected.4
Encryption is only one part of a safe ingest endpoint.
The IETF’s FTP security guidance documents password guessing, credential capture, bounce attacks, and port theft among the protocol’s risks. TLS or SSH protects the transport layer. The service still needs unique credentials, rate limits, upload quotas, safe filenames, media validation, tenant-scoped storage, and revocation.2
Per-source credentials
Do not share one event-wide login across freelancers. A leaked password should revoke exactly one source and leave the rest of the production untouched.
Upload-only permissions
The camera should not list or read another source’s files. Treat path traversal and filename collisions as hostile input.
Short retention
Staging is a delivery buffer. Set lifecycle deletion and surface failed routes before media expires.
Audit the data channel
A successful FTPS login does not prove the transfer channel used the intended TLS protection level.4
Read the exact body and firmware guide.
Canon documents FTP, FTPS, and SFTP choices on the EOS R5 Mark II. Nikon documents FTP, FTPS, and SFTP server types on the Z6III. That evidence covers those exact models and their documented firmware. It says nothing about other bodies from either brand.7,8
Some camera menus also impose protocol-specific setup: passive mode, root certificates, SSH login choices, proxy settings, or a fixed sequence for entering the server and port. Select the protocol your official manual names, then reproduce it against the production endpoint before assignment day.7,8
Frequently asked questions
Are FTPS and SFTP the same thing?+
No. FTPS is FTP secured with TLS. SFTP is the SSH File Transfer Protocol carried over SSH. They use different negotiation, trust, and server implementations.4,6
Which ports do camera FTP, FTPS, and SFTP use?+
FTP and explicit FTPS use TCP port 21 by default. SFTP uses the SSH port, TCP 22, by default. FTP and FTPS also negotiate a separate data connection. Use the custom port your endpoint issues, when it provides one.1,4,5
Is plain FTP acceptable for a camera?+
Only as a constrained compatibility mode, and only when you understand the network and the risk. FTP does not protect credentials or content by default. The IETF documents several protocol-level security concerns for it. Prefer SFTP or FTPS when the body supports them.2
Sources
Sources were last reviewed on . Vendor interfaces and documentation can change; follow the linked source and re-test the exact production workflow.
- 01IETF / RFC EditorRFC 959 — File Transfer Protocol ↗
- 02IETF / RFC EditorRFC 2577 — FTP Security Considerations ↗
- 03IETF / RFC EditorRFC 2428 — FTP Extensions for IPv6 and NATs ↗
- 04IETF / RFC EditorRFC 4217 — Securing FTP with TLS ↗
- 05IETF / RFC EditorRFC 4253 — The Secure Shell (SSH) Transport Layer Protocol ↗
- 06IETF DatatrackerSSH File Transfer Protocol, draft-ietf-secsh-filexfer-13 ↗
- 07
- 08
