Live data from Hacker News

Downloading PuTTY Safely Is Nearly Impossible (2014)

noncombatant.org

151–160 of 173 posts

Re: Downloading PuTTY Safely Is Nearly Impossible (2014)

#151
post #2

This is really just a rant about how poorly PuTTY is distributed. (and a vague implication that it is malware of some sort). I think it is a valid criticism, and I wish the person who wrote PuTTy (an SSH client for windows) would be more open/available/transparent but it is hard to force that on someone.

> but it is hard to force that on someone

Everyone who distributes exe files should include some form of authentication otherwise you are just sloppy. In all likelihood he doesn't check authenticity of software on his end so you can imagine other risks as well.

Re: Downloading PuTTY Safely Is Nearly Impossible (2014)

#152
post #148
post #9

Earlier quoted context omitted.

Ok, we changed the title. If anyone suggests a better title we can change it again.

It would be nice, when you do this, to know what the original title is, to know what the issue with the original title was.

We typically quote the original title when it was different from that of the article. Otherwise you can just assume the default, i.e. "Downloading Software Safely Is Nearly Impossible" in this case.

Re: Downloading PuTTY Safely Is Nearly Impossible (2014)

#153
post #80

Earlier quoted context omitted.

Many FOSS projects have Pro versions (Redhat Linux / Cent OS Linux) Best One Liner about commercial Open Source software : The only kind of profit strategy that is incompatible with Open Source is monopoly-based sales, also known as "royalties". [] http://opensource.org/faq#profit

But Moba isn't selling support. They're giving out crippleware and charging money for a professional version based on the core. How are the modifications that make the pro version not required to be open source?

Cripple software is not monopoly based system called "Royalties."

Re: Downloading PuTTY Safely Is Nearly Impossible (2014)

#154

Earlier quoted context omitted.

I understand what you are saying about "Putty seeks to perform a security-critical function." and therefore it should take these things into account (in a perfect world). I don't speak for all developers, obviously, but I'd wager a guess that most developers don't code (for OS at least) to "corner the market" or essentially become and run a mini-corporation (Twitter, Blog, Github, HTTPS, Code Signing, Website w/ Land…

Sounds like we're in agreement. But what can we do? I don't think it's realistic to expect anyone to issue code-signing certs for free. Any credible process for issuing the certs, it seems to me, would be too resource intensive for anyone but a charity to do for free. For projects like Putty it probably won't be a problem to raise money for the cert, if the dev wants to go that route. But I don't know what's to be do…

I think joshstrange has it right: the easiest way for everyone is to do it yourself and take the original developer out of the loop. There's no reason the person who writes the code and the person who handles the certified distribution need to be the same. Set up a site 'pdabbadabba's signed distribution of putty (and perhaps of whatever other open source programs you think merit such),' get the certificate yourself, offer downloads and ask users for money to cover the costs.

Re: Downloading PuTTY Safely Is Nearly Impossible (2014)

#155
post #108

Earlier quoted context omitted.

TIL: $73/year is "insanely expensive". Literally cheaper than sponsoring an African child or paying Sarah McLachlan to stop using commercials to make me cry.

Would you mind paying for a code signing and two wildcard certificates for me then, please? Yearly, of course. I would cover the costs out of my profits, but the $0.00/yr I am pulling in from my open source projects doesn't quite cover it, let alone the $200/yr for the VPS and domain registration.

What are you adding to his productivity? I'd pay it if you were as useful as putty.

Re: Downloading PuTTY Safely Is Nearly Impossible (2014)

#156

Earlier quoted context omitted.

The home page is clearly organized and readable, only having some text and links. What more do you want from a website that only exists to distribute one program? There's a link to the download page right on top. It's more than good enough. Do you need flashy CSS animations and a Konami Code to find a website cool enough for you? There's not a single thing wrong with PuTTY's UX either. The terminal area is just a ter…

Clearly Stockholm Syndrome has set in here. That page is awful. Period. What do I want from a website that exists to distribute one program? Some effort. Some class. Something more than the software equivalent of being wrapped in greasy newspaper. When you say "its UX because it's already optimal" you're basically saying "I do not value fit and finish, I am purely interested in functionality, I also make my own under…

You want a pretty web page for a terminal client? Are you not seeing the irony here?

Re: Downloading PuTTY Safely Is Nearly Impossible (2014)

#157

Earlier quoted context omitted.

The home page is clearly organized and readable, only having some text and links. What more do you want from a website that only exists to distribute one program? There's a link to the download page right on top. It's more than good enough. Do you need flashy CSS animations and a Konami Code to find a website cool enough for you? There's not a single thing wrong with PuTTY's UX either. The terminal area is just a ter…

Clearly Stockholm Syndrome has set in here. That page is awful. Period. What do I want from a website that exists to distribute one program? Some effort. Some class. Something more than the software equivalent of being wrapped in greasy newspaper. When you say "its UX because it's already optimal" you're basically saying "I do not value fit and finish, I am purely interested in functionality, I also make my own under…

You want a pretty web page for a terminal client? Are you not seeing the irony here?

Re: Downloading PuTTY Safely Is Nearly Impossible (2014)

#158

Earlier quoted context omitted.

Sounds like we're in agreement. But what can we do? I don't think it's realistic to expect anyone to issue code-signing certs for free. Any credible process for issuing the certs, it seems to me, would be too resource intensive for anyone but a charity to do for free. For projects like Putty it probably won't be a problem to raise money for the cert, if the dev wants to go that route. But I don't know what's to be do…

I think joshstrange has it right: the easiest way for everyone is to do it yourself and take the original developer out of the loop. There's no reason the person who writes the code and the person who handles the certified distribution need to be the same. Set up a site 'pdabbadabba's signed distribution of putty (and perhaps of whatever other open source programs you think merit such),' get the certificate yourself,…

A fair point, and I'm actually tempted to do just that. I wonder, though: why on earth would anyone trust code that I have signed? At least the developer has (maybe) built some level of trust. But what's the benefit of signing by some random third party?

Re: Downloading PuTTY Safely Is Nearly Impossible (2014)

#159
post #108

Earlier quoted context omitted.

Would you mind paying for a code signing and two wildcard certificates for me then, please? Yearly, of course. I would cover the costs out of my profits, but the $0.00/yr I am pulling in from my open source projects doesn't quite cover it, let alone the $200/yr for the VPS and domain registration.

What are you adding to his productivity? I'd pay it if you were as useful as putty.

Without relaxation, it's very hard to be productive (byuu develops Nintendo emulators).

Re: Downloading PuTTY Safely Is Nearly Impossible (2014)

#160

Earlier quoted context omitted.

I think joshstrange has it right: the easiest way for everyone is to do it yourself and take the original developer out of the loop. There's no reason the person who writes the code and the person who handles the certified distribution need to be the same. Set up a site 'pdabbadabba's signed distribution of putty (and perhaps of whatever other open source programs you think merit such),' get the certificate yourself,…

A fair point, and I'm actually tempted to do just that. I wonder, though: why on earth would anyone trust code that I have signed? At least the developer has (maybe) built some level of trust. But what's the benefit of signing by some random third party?

Trust is built by things like time and social proof. Whether you're the person who wrote the code doesn't really come into it. Look at how it works on Linux: most people install most software via package managers. Nobody expects the person who wrote the code to be the same as the person who has the knowledge and resources to package stuff for Debian or whatever. The Debian packagers have earned trust over time. You could do the same thing.
Post reply on HN