EMZETT.
Login

TFTP

In short: Trivial File Transfer Protocol — a greatly simplified variant of FTP without authentication and without encryption, based on UDP.

In more detail: Because of its minimal range of functions (no login, no directory listing), it’s mainly intended for automated scenarios in the local network, e.g. loading firmware/boot images onto network devices or for PXE boot. Practically never used on the open internet, since it’s insecure.

In Depth

TFTP was deliberately kept as minimal as possible — the complete command set comprises only five operations: read a file, write a file, send a data block, send an acknowledgement, report an error. There’s no directory browsing, no permission management, no authentication — anyone who knows the address can read or write files, as long as the server allows it. This radical simplicity makes TFTP extremely easy to implement in minimal firmware, which is the real reason it survives.

Typical place of use: PXE boot (Preboot Execution Environment), in which a computer that hasn’t yet loaded its own operating system at start-up loads its boot image over the network via TFTP from a central server — used, for example, when rolling out new operating system images in company networks or when booting network devices (routers, switches) that obtain their firmware/configuration centrally. Because TFTP runs over UDP (no connection setup, no automatic delivery guarantee), the application itself has to ensure reliability through simple acknowledgements per data block.

See also: FTP, UDP