Live data from Hacker News

Downloading PuTTY Safely Is Nearly Impossible (2014)

noncombatant.org

1–10 of 173 posts

Re: Downloading PuTTY Safely Is Nearly Impossible (2014)

#2
This is really just a rant about how poorly PuTTY is distributed. (and a vague implication that it is malware of some sort).

I think it is a valid criticism, and I wish the person who wrote PuTTy (an SSH client for windows) would be more open/available/transparent but it is hard to force that on someone.

Re: Downloading PuTTY Safely Is Nearly Impossible (2014)

#5
Title should be "Downloading Putty Safely Is Nearly Impossible"

Don't most people install stuff in Windows through Ninite when possible these days? I know it has at least one SSH client. And in my experience, the vast majority of good software is at the top of any search query.

Re: Downloading PuTTY Safely Is Nearly Impossible (2014)

#6
None of which would have mattered if Putty.exe was codesigned. Unfortunately it is not.

Code signing certificates are insanely expensive. The cheapest one I could find from a CA was $73/year (3 year minimum). I could go on a long rant now about how much CAs are in collusion and how they're making everyone more insecure though their pricing, but that would be redundant as I think "everyone knows that" by now.

Let's Encrypt are welcome (when they arrive), but they still don't offer Code Signing, Wildcard Certificates, and so on. The whole certificate/CA industry needs change, Let's Encrypt doesn't go nearly far enough. I blame Microsoft, Mozilla, and Apple primarily as they decide who gets to be a CA, and could allow non-profits and other disruptive startups into the space if they wished.

Re: Downloading PuTTY Safely Is Nearly Impossible (2014)

#7
post #2

This is really just a rant about how poorly PuTTY is distributed. (and a vague implication that it is malware of some sort). I think it is a valid criticism, and I wish the person who wrote PuTTy (an SSH client for windows) would be more open/available/transparent but it is hard to force that on someone.

This is not just a rant. As of two days ago, there is a hostile version of PuTTY in the wild.[1][2] It's on some mirror sites distributing open source software. It steals login credentials. Right now, it's essential to be able to tell the good one from the bad ones, and it's not easy.

[1] http://www.symantec.com/connect/blogs/check-your-sources-tro... [2] http://blogs.cisco.com/security/trojanized-putty-software

Re: Downloading PuTTY Safely Is Nearly Impossible (2014)

#9
post #5

Title should be "Downloading Putty Safely Is Nearly Impossible" Don't most people install stuff in Windows through Ninite when possible these days? I know it has at least one SSH client. And in my experience, the vast majority of good software is at the top of any search query.

Ok, we changed the title. If anyone suggests a better title we can change it again.
Post reply on HN