Live data from Hacker News

Putty maintainer on his attitude towards security and open source

andrewducker.dreamwidth.org

51–60 of 140 posts

Re: Putty maintainer on his attitude towards security and open source

#51
It would be cool if someone would donate to him a domain. Downloading PuTTY involves relying on greenend.org.uk (which isn't obviously connected with PuTTY). You can check your download using the hashes provided on the site; but if the download has been messed with, then the hash is untrustworthy too.

https://noncombatant.org/2014/03/03/downloading-software-saf...

Re: Putty maintainer on his attitude towards security and open source

#52

Earlier quoted context omitted.

For me putty is still preferred way to ssh with Windows. Nowadays windows is shipping openssh.exe, so I can run it from cmd and it kinda works for quick simple actions, but clipboard works weirdly, basically I have to use right-click/paste to reliably paste data, shift+insert works in some apps and does not work in others. Putty just works like it worked 10 years ago, it's good old reliable tool.

Anybody have a solution to get hostname completion in Powershell? ssh [letter][tab] gets me a list with my Zsh config. I looked briefly one time and couldn't find what I was looking for. I have a fairly large SSH config file, and needing to open it to copy and paste hostnames from the file is the main reason I just use WSL.

I don't have a solution but if you want to invest the time, you should have a look at https://docs.microsoft.com/en-us/powershell/module/microsoft...

Re: Putty maintainer on his attitude towards security and open source

#53
The discussion around open source in the last few days lends weight in my view to the notion that most engineers are apolitical by nature. Unfortunately larger political entities (that is, BigCorp) have no reservations taking advantage of this.

Re: Putty maintainer on his attitude towards security and open source

#54
post #43

Earlier quoted context omitted.

Have you ever tried mobaxterm? I was a putty person as well until I was put on to moba.

This software limits the user with a maximum of allowed sessions.

The _demo_ limits the user with a maximum of allowed sessions. The unrestricted software has a modest licensing fee. Entirely reasonable considering the target audience.

Re: Putty maintainer on his attitude towards security and open source

#55
post #30

> And part of that is making all the necessary security tools available free of charge, because the more money they cost, the more companies will take a cost-benefit decision not to bother with them, neglecting the externalised cost of those knock-on effects of their insecurity on everyone else. Boy if that doesn't ring true. Kudos to PuTTY's author for making it so easy and low cost to do the right thing that those…

The same logic applies to other concerns like accessibility, which is one reason why I'm making one of my contributions in that area [1] available as permissively licensed open source. It helps that my current funding source for that project also wants it to be open source.

[1]: https://github.com/AccessKit/accesskit

Re: Putty maintainer on his attitude towards security and open source

#56
post #43

Earlier quoted context omitted.

Have you ever tried mobaxterm? I was a putty person as well until I was put on to moba.

This software limits the user with a maximum of allowed sessions.

Oh I didn’t know that. I don’t use that feature. Fair point though.

Re: Putty maintainer on his attitude towards security and open source

#57
post #41

Earlier quoted context omitted.

I do think there is a real problem whereby very important code that a lot of people and systems depend on is looked after part time (or not at all) and nobody thinks about it until it has a severe bug. But that's almost orthogonal to the issue of whether the original developer should be paid because their code turns out to be useful to lots of people.

I think it’s a problem, but don’t think funding is a good solution. If funding was good, then commercial products would serve the purpose. I think a better approach is to encourage more smart developers contributing time. And if companies find an individual or a percent of a person’s time on a project that’s actually funding. But it’s very different from trying to replicate direct funds.

> If funding was good, then commercial products would serve the purpose.

Not sure that's a solid affirmation, especially given how there are many open source projects receiving funding that often outcompete their commercial counterparts. In particular I would point out the major open source backing foundations such as the CNCF and Linux Foundation who help to fund their own projects. Would you say that these two organizations and their projects are not serving their purpose or are being outcompeted by commercial offerings?

Re: Putty maintainer on his attitude towards security and open source

#58
post #36

These days, there seems to be (at least) two kinds of open source software developers: 0. Those who release their code under an open source license, in the hope that it will be useful to others in some way. 1. Those who do the same as above, with the additional hope that they will be paid for in some ill-defined way. And when they are not, take to twitter and blogs to proclaim, "somebody should really do something ab…

2. those that start out as 0, but become 1 when it turns out their software they hoped would be useful winds up /costing them/ in some ill-defined way.

Re: Putty maintainer on his attitude towards security and open source

#59
post #27

I once used PuTTY as the base for an internal SSH tool. We needed to provide data entry teams with access to a green screen but didn’t want to expose any more servers than what they were authorised to use and a simple interface because a lot of the data entry guys were technologically illiterate. After spending hours looking for solutions that were purpose built for this kind of thing I gave up took PuTTYs source and…

For me putty is still preferred way to ssh with Windows. Nowadays windows is shipping openssh.exe, so I can run it from cmd and it kinda works for quick simple actions, but clipboard works weirdly, basically I have to use right-click/paste to reliably paste data, shift+insert works in some apps and does not work in others. Putty just works like it worked 10 years ago, it's good old reliable tool.

I wonder whether Wallix contributes to Putty development. That's one company I know that relies on Putty to survive.

Re: Putty maintainer on his attitude towards security and open source

#60
post #20

Earlier quoted context omitted.

Tatham, rather than Ducker - the former wrote a comment on the latter's link blog.

Indeed, Simon drops by occasionally and leaves a comment if he fancies. This one was so good I thought it was worth sharing more widely.

It's pretty darn weird realising that Simon is actually a person who knows somebody I've met IRL, rather than a mysterious benevolent entity responsible for manifesting the PuTTY suite fully-formed upon the internet ;)
Post reply on HN