Live data from Hacker News

Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

blog.pupred.com

61–70 of 79 posts

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#61

Earlier quoted context omitted.

Point of information. From that doc: A.9.3 Would you like me to register you a nicer domain name? No, thank you. Even if you can find one (most of them seem to have been registered already, by people who didn't ask whether we actually wanted it before they applied), we're happy with the PuTTY web site being exactly where it is. It's not hard to find (just type ‘putty’ into google.com and we're the first link returned…

How do we report disappointing search results to Google? (Does anyone know please?)

They don’t care if results are disappointing for you, they just want you to click more ads

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#62
post #56
post #49

Earlier quoted context omitted.

Well, classic sender receiver mismatch I guess :D Is my intent more clear with that second try to explain? If not, I'm more then welcome to talk about a better way to phrase it :)

I was confused as well and panicked that I'd been installing KeePass from a fake site all these years. But keepass.info is indeed the official site. Suggest: That is the same attitude as critics telling the Keepass maintainer to migrate the (official) keepass.info domain to a .com...

For some reason there's no .official tld, there's .app, .codes, .dev, .download, .kosher

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#63
Has the putty.org website changed in the few hours since this was posted? I see nothing there about any kind of software at all. It appears to be about someone called Mike Yeadon, and scandals in the pharmaceutical industry. That's not what anyone else here is describing.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#64

Earlier quoted context omitted.

Here's a framing of the problem. There's software called PuTTY, and non-technical or less technical people, or even technical people who are running on autopilot, might reasonably expect that it's hosted on putty.org. They just need to be more careful. Here's an analogy. Even capable programmers keep screwing up when using C and end up with memory leaks and security vulnerabilities. But that's no reason to stop using…

Nontechnical people afraid of a scary console window use putty?

Yes. Unfortunately.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#65

Has the putty.org website changed in the few hours since this was posted? I see nothing there about any kind of software at all. It appears to be about someone called Mike Yeadon, and scandals in the pharmaceutical industry. That's not what anyone else here is describing.

well, if you read about the exchange beween the author and owners ... add "schwurbeln" (german) to the list of whats weird about the domain.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#66
post #45

Earlier quoted context omitted.

I hope you do, that would be pretty funny. Like using PowerShell as your shell on Linux.

I'll bite. What is your preferred way to use serial port console on linux? Kermit? I am really no fan of minicom... Also, I'd take pterm over modern gpu electron nodejs turtle tower terminals. It has sane requirements and perfomance, behaves in a consistent, predictable manner and handles large scrollback very well. Why bad?

I don't need to use a serial com that often, but when I do I use picocom. I'm already on Linux and wanting to do cli things so I want to use my normal terminal emulator. The readme doesn't really cover all it does as well as the man page.

https://gitlab.com/wsakernel/picocom

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#67
post #45

Earlier quoted context omitted.

I'll bite. What is your preferred way to use serial port console on linux? Kermit? I am really no fan of minicom... Also, I'd take pterm over modern gpu electron nodejs turtle tower terminals. It has sane requirements and perfomance, behaves in a consistent, predictable manner and handles large scrollback very well. Why bad?

No one said bad. Putty is awesome, it's just always funny when the best program on Linux is a Windows program running in Wine. I didn't consider serial ports, only SSH, in that case I actually do struggle to suggest something better. As for terminals, I don't know, I just run Xterm.

xterm is actually great, if you know to invoke and use the exotic control UI. That software is ancient.

Using putty's plink/pscp/pftp commandline tools are refreshingly straightforward and also have merit, at least as a way of not dealing with OpenSSH maintainer tantrums (each release inventing wonderful ways to break your setup or confuse you for no good reason).

It is all around small solid piece of software (like his puzzle collection), that is a magnet for all sorts of crooks that try to distribute their "spiked" versions, or try to charge for it...

I am amazed it has not gone the way of libtomcrypt yet.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#68

Has the putty.org website changed in the few hours since this was posted? I see nothing there about any kind of software at all. It appears to be about someone called Mike Yeadon, and scandals in the pharmaceutical industry. That's not what anyone else here is describing.

On the wayback machine it does appear that putty.org recently changed. If you go to www.putty.org you can see the page everyone is talking about still present.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#69
post #9

> “The difference is not one of profit, it is one of philosophy. You believe software can be managed by a committee. I believe software requires an owner, otherwise it is dead.” This justification is even worse than the domain squatting itself. Some of the most influential software in history (Linux, Git, GCC, and yes, PuTTY) thrived under community-driven development. The idea that software "dies" without a single c…

I see where you're coming from, but I think your examples actually prove the opposite point. I've always seen Linux and Git not as projects run by a committee, but as projects guided by a single, trusted leader. Linus Torvalds is the owner of the kernel's vision. He has the final say. That isn't community consensus; it's benevolent dictatorship. So while the putty.org situation is shady, I believe the core idea is ri…

The thing is that this was his "answer" to what was really the quite reasonable question of "do you think this is ethical?" To start talking about this sort of thing is completely disconnected from the actual question.

Of course you can have discussion about these aspects of the open source ecosystem; this is a long-running discussion where many people have discussed and disagreed in good faith. I don't entirely agree with your take personally, but I also don't entirely disagree and can see where you're coming from, and it's of course an interesting thing to discus.

However, in this context, as an "answer" to that question, it's hard to see it as anything other than just self-serving post-hoc rationalisation for being a selfish wanker. This is classic nihilism where the abuse of everything and everyone is justified as long as you can get away with it. Everything that moves the needle and you can get away with is morally justified because it moves the needle and you can get away with it.

Re: Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY

#70
post #56

Earlier quoted context omitted.

I was confused as well and panicked that I'd been installing KeePass from a fake site all these years. But keepass.info is indeed the official site. Suggest: That is the same attitude as critics telling the Keepass maintainer to migrate the (official) keepass.info domain to a .com...

For some reason there's no .official tld, there's .app, .codes, .dev, .download, .kosher

It's a nice idea in principle, but one problem with that is that for many names, there are multiple "official" meanings. Apple Inc. and Apple Records is a well-known example. This is why Wikipedia has (sometimes lengthy) disambiguation pages.
Post reply on HN