Live data from Hacker News

Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

blog.pupred.com

11–20 of 79 posts

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#12
I don't get it. The putty website has always been https://www.chiark.greenend.org.uk/~sgtatham/putty/

This has never changed.

Just because someone likes to use short circuit routing in their head doesn't make putty.org the official site for putty.

That is the same attitude as telling the Keepass folks that https://keepass.info/ is wrong...

edit:

Maybe also have a look at the putty FAQ, especially 9.3

https://www.chiark.greenend.org.uk/~sgtatham/putty/faq.html#...

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#13
post #12

I don't get it. The putty website has always been https://www.chiark.greenend.org.uk/~sgtatham/putty/ This has never changed. Just because someone likes to use short circuit routing in their head doesn't make putty.org the official site for putty. That is the same attitude as telling the Keepass folks that https://keepass.info/ is wrong... edit: Maybe also have a look at the putty FAQ, especially 9.3 https://www.chia…

How does your example relate? keepass.info is the official Keepass website, owned by the Keepass developer.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#14
post #11

I don't think Bitvise is even doing anything wrong here? There's nothing wrong with running what is essentially a fan site and promoting your own things on it.

It's a company who bought the domain of the exact name of the largest open source project that they directly compete with and then advertise themselves on it? This is at the very least unethical. You can't just use a competitors exact name to run a website that tries to snipe users looking for your competitor and call it a "fan site".

The comments on this submission are pretty strange. What are the chances that a bunch of non-sockpuppet HN type of people are in support of this kind of garbage? Generally with sort of abysmal behaviour like the email communication in the article, there's people going to bat against actually defensible actions purely in the name of civility on HN. These bitvise people seem bad from both angles and yet the of early comments are either ignoring the issue and redirecting (e.g. "who even uses putty") or outright defending their shitty behaviour?

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#15
post #11

I don't think Bitvise is even doing anything wrong here? There's nothing wrong with running what is essentially a fan site and promoting your own things on it.

It's a company who bought the domain of the exact name of the largest open source project that they directly compete with and then advertise themselves on it? This is at the very least unethical. You can't just use a competitors exact name to run a website that tries to snipe users looking for your competitor and call it a "fan site". The comments on this submission are pretty strange. What are the chances that a bun…

You can buy domain names with competitors names in them. People do this all the time. If you don't want people doing that you need to register the names yourself.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#16
both sides are at fault here (the "journalist" and Bitvise - the PuTTY maintainers have nothing to do with this).

the Bitvise owner shouldn't have responded so unprofessionally, and their views on open source software are strange - but they're correct that the domain was never "historically associated with PuTTY", it just uses its name.

additionally, the usage of unformatted markdown in each "journalist" email makes me think this story was at least partially assisted by an LLM (https://putty.org/20250713-MiraiF-Emails.txt)

in short this is a nothing story

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#17
post #12

I don't get it. The putty website has always been https://www.chiark.greenend.org.uk/~sgtatham/putty/ This has never changed. Just because someone likes to use short circuit routing in their head doesn't make putty.org the official site for putty. That is the same attitude as telling the Keepass folks that https://keepass.info/ is wrong... edit: Maybe also have a look at the putty FAQ, especially 9.3 https://www.chia…

How does your example relate? keepass.info is the official Keepass website, owned by the Keepass developer.

As is https://www.chiark.greenend.org.uk/~sgtatham/putty/ to Putty.

Still there were multiple requests to the Keepass project to change that domain to "a proper" domain like keepass.com

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#18
post #15

Earlier quoted context omitted.

It's a company who bought the domain of the exact name of the largest open source project that they directly compete with and then advertise themselves on it? This is at the very least unethical. You can't just use a competitors exact name to run a website that tries to snipe users looking for your competitor and call it a "fan site". The comments on this submission are pretty strange. What are the chances that a bun…

You can buy domain names with competitors names in them. People do this all the time. If you don't want people doing that you need to register the names yourself.

So someone who has written something and made it available for the common good, and makes no money from it, should now go and buy every possible domain that people might use in a deceptive manner.

This is a great example of what drives people away from providing anything for free.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#19
post #15

Earlier quoted context omitted.

You can buy domain names with competitors names in them. People do this all the time. If you don't want people doing that you need to register the names yourself.

So someone who has written something and made it available for the common good, and makes no money from it, should now go and buy every possible domain that people might use in a deceptive manner. This is a great example of what drives people away from providing anything for free.

It's a namespace problem. You can't just ban people from registering anything that might be confusing like that. If we followed your idea the internet wouldn't work.

EDIT: They're not deceiving users though? The first section on the index page links directly to the real putty site. They're very clear about all of it.

EDIT2: Nope. We really don't want DNS "moderators." All of us have seen what happens with forum moderators. Like I said if that were done the internet would not work. It's not about the cost it's about being unable to clearly define what should be banned.

If you want to see a great example of how moderation like that both stops legitimate use and fails to stop malware go look at smartphone app stores. The result is borderline unusable garbage.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#20
post #12

I don't get it. The putty website has always been https://www.chiark.greenend.org.uk/~sgtatham/putty/ This has never changed. Just because someone likes to use short circuit routing in their head doesn't make putty.org the official site for putty. That is the same attitude as telling the Keepass folks that https://keepass.info/ is wrong... edit: Maybe also have a look at the putty FAQ, especially 9.3 https://www.chia…

Here's a framing of the problem.

There's software called PuTTY, and non-technical or less technical people, or even technical people who are running on autopilot, might reasonably expect that it's hosted on putty.org.

They just need to be more careful.

Here's an analogy.

Even capable programmers keep screwing up when using C and end up with memory leaks and security vulnerabilities. But that's no reason to stop using it ... people should just be more careful.

No analogy is perfect, every example has problems and loopholes, but this seems a reasonable one. Just as people should use programming languages that make it harder to make mistakes, so companies should not behave in deceptive manners, and when they do, they should be called out on it.

Post reply on HN