Live data from Hacker News

Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

blog.pupred.com

21–30 of 79 posts

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#21
post #12

I don't get it. The putty website has always been https://www.chiark.greenend.org.uk/~sgtatham/putty/ This has never changed. Just because someone likes to use short circuit routing in their head doesn't make putty.org the official site for putty. That is the same attitude as telling the Keepass folks that https://keepass.info/ is wrong... edit: Maybe also have a look at the putty FAQ, especially 9.3 https://www.chia…

Google (not saying it's a good search engine, but people use it) puts putty.org at the top of search results.

The results shows as:

  Download PuTTY - a free SSH and telnet client for Windows.
  PuTTY is an SSH and telnet client, developed originally by Simon Tatham for the Windows platform. PuTTY is open source software that is available with source...

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#22
post #12

I don't get it. The putty website has always been https://www.chiark.greenend.org.uk/~sgtatham/putty/ This has never changed. Just because someone likes to use short circuit routing in their head doesn't make putty.org the official site for putty. That is the same attitude as telling the Keepass folks that https://keepass.info/ is wrong... edit: Maybe also have a look at the putty FAQ, especially 9.3 https://www.chia…

Point of information.

From that doc:

A.9.3 Would you like me to register you a nicer domain name?

No, thank you. Even if you can find one (most of them seem to have been registered already, by people who didn't ask whether we actually wanted it before they applied), we're happy with the PuTTY web site being exactly where it is. It's not hard to find (just type ‘putty’ into google.com and we're the first link returned) ...

Searching for "putty ssh" on both DDG and Google now return putty.org as their top result.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#23
post #19

Earlier quoted context omitted.

So someone who has written something and made it available for the common good, and makes no money from it, should now go and buy every possible domain that people might use in a deceptive manner. This is a great example of what drives people away from providing anything for free.

It's a namespace problem. You can't just ban people from registering anything that might be confusing like that. If we followed your idea the internet wouldn't work. EDIT: They're not deceiving users though? The first section on the index page links directly to the real putty site. They're very clear about all of it. EDIT2: Nope. We really don't want DNS "moderators." All of us have seen what happens with forum moder…

You absolutely could, though.

Deceiving users? Warning, temporary ban, permanent ban!

Selling mushy stuff for plumbers and kids? No problem!

It takes a simple reporting system, couple moderators costing peanuts compared to what we pay for the names and a clear set of rules forbidding intentionally misleading users.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#24
> The domain, long associated by users with PuTTY [...] a domain name that clearly and historically signals the PuTTY project

This seems a bit misleading. The domain has never, as far as I know, belonged to the project, so it can only have been "long associated" in the minds of users mistakenly trying to guess the URL and "historically" navigating to the wrong website.

> “The PuTTY project never had this domain”

Right.

> Search engines treat domain names like putty.org as authoritative.

Do they? Domain names "like" putty.org in what sense? Which search engines, by what mechanism?

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#25
post #16

both sides are at fault here (the "journalist" and Bitvise - the PuTTY maintainers have nothing to do with this). the Bitvise owner shouldn't have responded so unprofessionally, and their views on open source software are strange - but they're correct that the domain was never "historically associated with PuTTY", it just uses its name. additionally, the usage of unformatted markdown in each "journalist" email makes…

LLM written, spurring up controversy, holding a private company accountable like they are the government. If they - PuTTY - is bothered enough, they are allowed to sue or request a takedown, and if legal grounds are not viable I don't think Google would mind ranking the correct website up after request. This "issue" has been present for years and this journalist picks up on it, presses on the guy as if he was in the Panama Papers or something and writes the article with newgen LLM no less. Disgraceful.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#26
post #12

I don't get it. The putty website has always been https://www.chiark.greenend.org.uk/~sgtatham/putty/ This has never changed. Just because someone likes to use short circuit routing in their head doesn't make putty.org the official site for putty. That is the same attitude as telling the Keepass folks that https://keepass.info/ is wrong... edit: Maybe also have a look at the putty FAQ, especially 9.3 https://www.chia…

Here's a framing of the problem. There's software called PuTTY, and non-technical or less technical people, or even technical people who are running on autopilot, might reasonably expect that it's hosted on putty.org. They just need to be more careful. Here's an analogy. Even capable programmers keep screwing up when using C and end up with memory leaks and security vulnerabilities. But that's no reason to stop using…

It is good analogy.

Similarly, telcos keep accepting and showing any cooked up caller ID over their SS7, and when someone gets scammed because they trusted the caller ID, the messaging I hear always actually is "people should just be more careful."

Same as banks requiring only card number to give someone money from the account. "you shoul be more careful with your card number."

It is sad to hear the level of victim blaming from the big industry.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#27
post #15

Earlier quoted context omitted.

It's a company who bought the domain of the exact name of the largest open source project that they directly compete with and then advertise themselves on it? This is at the very least unethical. You can't just use a competitors exact name to run a website that tries to snipe users looking for your competitor and call it a "fan site". The comments on this submission are pretty strange. What are the chances that a bun…

You can buy domain names with competitors names in them. People do this all the time. If you don't want people doing that you need to register the names yourself.

That's a good way to lose your domain name

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#29
post #12

I don't get it. The putty website has always been https://www.chiark.greenend.org.uk/~sgtatham/putty/ This has never changed. Just because someone likes to use short circuit routing in their head doesn't make putty.org the official site for putty. That is the same attitude as telling the Keepass folks that https://keepass.info/ is wrong... edit: Maybe also have a look at the putty FAQ, especially 9.3 https://www.chia…

Point of information. From that doc: A.9.3 Would you like me to register you a nicer domain name? No, thank you. Even if you can find one (most of them seem to have been registered already, by people who didn't ask whether we actually wanted it before they applied), we're happy with the PuTTY web site being exactly where it is. It's not hard to find (just type ‘putty’ into google.com and we're the first link returned…

It's not even on the screen for me when searching "putty"

1: putty.org

2: "People also ask, What is putty and why is it used?" then 4 other questions about the material putty taking up most of the page

3: Videos "How to use Putty to SSH on Windows"

----- Fold -----

4. Video "How to Use Putty?"

5: Video "How to SSH Without a Password with Putty"

6: https://www.chiark.greenend.org.uk/~sgtatham/putty/ the actual site

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#30
post #9

> “The difference is not one of profit, it is one of philosophy. You believe software can be managed by a committee. I believe software requires an owner, otherwise it is dead.” This justification is even worse than the domain squatting itself. Some of the most influential software in history (Linux, Git, GCC, and yes, PuTTY) thrived under community-driven development. The idea that software "dies" without a single c…

I see where you're coming from, but I think your examples actually prove the opposite point.

I've always seen Linux and Git not as projects run by a committee, but as projects guided by a single, trusted leader. Linus Torvalds is the owner of the kernel's vision. He has the final say. That isn't community consensus; it's benevolent dictatorship.

So while the putty.org situation is shady, I believe the core idea is right: great software needs a final arbiter with a clear vision, not just a crowd.

Post reply on HN