Live data from Hacker News

Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

blog.pupred.com

41–50 of 79 posts

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#42
post #12

I don't get it. The putty website has always been https://www.chiark.greenend.org.uk/~sgtatham/putty/ This has never changed. Just because someone likes to use short circuit routing in their head doesn't make putty.org the official site for putty. That is the same attitude as telling the Keepass folks that https://keepass.info/ is wrong... edit: Maybe also have a look at the putty FAQ, especially 9.3 https://www.chia…

Except Google, DuckDuckGo, Bing all return putty.org as the top result. The "official" PuTTY website appears as either the 2nd or 3rd result.

putty.org has this on their page:

> On July 13, 2025, Bitvise was contacted by a political interrogator posing as a journalist.

They are doing a great job of making themselves look like assholes.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#43
post #17

Earlier quoted context omitted.

How does your example relate? keepass.info is the official Keepass website, owned by the Keepass developer.

As is https://www.chiark.greenend.org.uk/~sgtatham/putty/ to Putty. Still there were multiple requests to the Keepass project to change that domain to "a proper" domain like keepass.com

I, too, took your comment to mean that keepass.info is to KeePass as putty.org is to PuTTY.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#44

Earlier quoted context omitted.

So someone who has written something and made it available for the common good, and makes no money from it, should now go and buy every possible domain that people might use in a deceptive manner. This is a great example of what drives people away from providing anything for free.

Yes, all the ones actually worth owning are only a few dollars if you have a unique project name, you don't need "every possible domain" you just need one that looks legit. Unfortunately this is the world we live in where if you don't then someone else will and they'll abuse it so you have to act defensively. Either you put the time into the project and care about it in which case you should spend the few dollars a y…

there are to many top level domains that look legitimate:

    https://putty.app
    https://putty.at
    https://putty.click
    https://putty.cloud
    https://putty.codes
    https://putty.co.uk
    https://putty.com
    https://putty.computer
    https://putty.dev
    https://putty.digital
    https://putty.domains
    https://putty.engineer
    https://putty.host
    https://putty.hosting
    https://putty.info
    https://putty.io
    https://putty.media
    https://putty.net
    https://putty.network
    https://putty.online
    https://putty.org
    https://putty.software
    https://putty.solutions
    https://putty.tech
    https://putty.technology
    https://putty.website
i could not tell which one of these should be more legitimate than any other. registering even just a few of those is going to add up to a sizable yearly bill.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#45
post #28

Earlier quoted context omitted.

I use putty on linux. now what?

I hope you do, that would be pretty funny. Like using PowerShell as your shell on Linux.

I'll bite. What is your preferred way to use serial port console on linux? Kermit? I am really no fan of minicom...

Also, I'd take pterm over modern gpu electron nodejs turtle tower terminals. It has sane requirements and perfomance, behaves in a consistent, predictable manner and handles large scrollback very well.

Why bad?

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#46
post #12

I don't get it. The putty website has always been https://www.chiark.greenend.org.uk/~sgtatham/putty/ This has never changed. Just because someone likes to use short circuit routing in their head doesn't make putty.org the official site for putty. That is the same attitude as telling the Keepass folks that https://keepass.info/ is wrong... edit: Maybe also have a look at the putty FAQ, especially 9.3 https://www.chia…

Point of information. From that doc: A.9.3 Would you like me to register you a nicer domain name? No, thank you. Even if you can find one (most of them seem to have been registered already, by people who didn't ask whether we actually wanted it before they applied), we're happy with the PuTTY web site being exactly where it is. It's not hard to find (just type ‘putty’ into google.com and we're the first link returned…

Huh weird, usually top 3 results are "sponsored" links serving malware.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#47

Earlier quoted context omitted.

Point of information. From that doc: A.9.3 Would you like me to register you a nicer domain name? No, thank you. Even if you can find one (most of them seem to have been registered already, by people who didn't ask whether we actually wanted it before they applied), we're happy with the PuTTY web site being exactly where it is. It's not hard to find (just type ‘putty’ into google.com and we're the first link returned…

It's not even on the screen for me when searching "putty" 1: putty.org 2: "People also ask, What is putty and why is it used?" then 4 other questions about the material putty taking up most of the page 3: Videos "How to use Putty to SSH on Windows" ----- Fold ----- 4. Video "How to Use Putty?" 5: Video "How to SSH Without a Password with Putty" 6: https://www.chiark.greenend.org.uk/~sgtatham/putty/ the actual site

This is definitely something that should be raised to the putty team. But with how the rest of the text is worded, I doubt that will change their mind.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#48
post #12

I don't get it. The putty website has always been https://www.chiark.greenend.org.uk/~sgtatham/putty/ This has never changed. Just because someone likes to use short circuit routing in their head doesn't make putty.org the official site for putty. That is the same attitude as telling the Keepass folks that https://keepass.info/ is wrong... edit: Maybe also have a look at the putty FAQ, especially 9.3 https://www.chia…

Except Google, DuckDuckGo, Bing all return putty.org as the top result. The "official" PuTTY website appears as either the 2nd or 3rd result. putty.org has this on their page: > On July 13, 2025, Bitvise was contacted by a political interrogator posing as a journalist. They are doing a great job of making themselves look like assholes.

IMHO neither of the two showed exactly nice behavior. But I don't think that this is particularly relevant.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#49
post #43
post #17

Earlier quoted context omitted.

As is https://www.chiark.greenend.org.uk/~sgtatham/putty/ to Putty. Still there were multiple requests to the Keepass project to change that domain to "a proper" domain like keepass.com

I, too, took your comment to mean that keepass.info is to KeePass as putty.org is to PuTTY.

Well, classic sender receiver mismatch I guess :D

Is my intent more clear with that second try to explain? If not, I'm more then welcome to talk about a better way to phrase it :)

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#50
post #12

I don't get it. The putty website has always been https://www.chiark.greenend.org.uk/~sgtatham/putty/ This has never changed. Just because someone likes to use short circuit routing in their head doesn't make putty.org the official site for putty. That is the same attitude as telling the Keepass folks that https://keepass.info/ is wrong... edit: Maybe also have a look at the putty FAQ, especially 9.3 https://www.chia…

Here's a framing of the problem. There's software called PuTTY, and non-technical or less technical people, or even technical people who are running on autopilot, might reasonably expect that it's hosted on putty.org. They just need to be more careful. Here's an analogy. Even capable programmers keep screwing up when using C and end up with memory leaks and security vulnerabilities. But that's no reason to stop using…

I don't think the issue really stems from putty.org being there. It stems from a "trusted" third-party, the search engine, suggesting you the wrong place.

Therefore I think you are missing the point with your analogy.

Post reply on HN