Live data from Hacker News

PuTTY has a new website

putty.software

161–170 of 304 posts

Re: PuTTY has a new website

#161
post #146

Earlier quoted context omitted.

Unfortunately the person who owns putty.org started to use it to spread misinformation about vaccines and the pandemic, as you can see on the site today. This recently [1][2] got a lot of attention on the web and here on HN, along with a post on Mastodon from the author [3] I imagine trying to disincentivize this and provide another shorter more official looking link is the hope here. [1] https://www.theregister.com/…

[flagged]

Argument from authority is not particularly strong. The information on putty.org is considered misinformation by the vast majority of professionals in the field of infectious diseases.

Re: PuTTY has a new website

#162

Related recent context/controversy that maybe fueled some of this: putty.org is not run by the PuTTY developers https://news.ycombinator.com/item?id=44558328 Hijacking Trust? Bitvise Under Fire for Controlling Domain of FOSS Project PuTTY https://news.ycombinator.com/item?id=44579265

I think PupRed is a troll and stirred this up with the intent to provoke an escalation.

Re: PuTTY has a new website

#163
post #148

Earlier quoted context omitted.

Yes, your caveat at the end there is exactly why this method shouldn't be trusted, as it's indistinguishable from an attacker with access to embed a single link. So it doesn't confirm the account belongs to the author, it confirms the site has a specific link and nothing more.

A regular link won't do, since it requires the rel="me" attribute, which is intended for this purpose: https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/... Adding a tag or creating a page with certain content are already used even for more impactful verification, like getting issued a certificate for that domain. If an attacker does have broad access to edit the HTML of your website, I feel that's already…

So you have read that page and understand its purpose is to link social media profiles for informational purposes, but don't understand that it's not suitable for any kind of auth, let alone in a software supply chain?

Re: PuTTY has a new website

#166

Earlier quoted context omitted.

https://imgur.com/a/qA1fr71 Something wrong with my eyes? Doesn't cmd.exe look smoother in this screenshot?

I agree. In those screenshots cmd looks better. Not sure what's up.

It's the lack of subpixel anti-aliasing (aka ClearType). For some reason it's being erased from a lot of modern software. It's why Windows >= 8 UWP apps and GNOME look so blurry.

Re: PuTTY has a new website

#167
post #148

Earlier quoted context omitted.

A regular link won't do, since it requires the rel="me" attribute, which is intended for this purpose: https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/... Adding a tag or creating a page with certain content are already used even for more impactful verification, like getting issued a certificate for that domain. If an attacker does have broad access to edit the HTML of your website, I feel that's already…

So you have read that page and understand its purpose is to link social media profiles for informational purposes, but don't understand that it's not suitable for any kind of auth, let alone in a software supply chain?

By the XFN spec, it "demonstrates that the same person has control over [the pages]". The docs page I linked links to two further specs for using it for authentication in the way that Mastodon does.

Re: PuTTY has a new website

#168
post #140

Earlier quoted context omitted.

Unfortunately the person who owns putty.org started to use it to spread misinformation about vaccines and the pandemic, as you can see on the site today. This recently [1][2] got a lot of attention on the web and here on HN, along with a post on Mastodon from the author [3] I imagine trying to disincentivize this and provide another shorter more official looking link is the hope here. [1] https://www.theregister.com/…

This seems similar to the Notepad++ team using their platform to promote political viewpoints. The same thing happened with Facebook "pages", when they became a personal "soap box" by the owner of the page. It was downhill from there... You might as well turn the whole web into FB/Twitter/X/Insta promotional spam at that point.

[flagged]

Re: PuTTY has a new website

#170
post #142

Earlier quoted context omitted.

Average person aware of trust on social network / internet - because https://hachyderm.io/@simontatham has a validated link to the author's homepage. Others - they don't understand the trust anyway, so there prerequisite steps missing before the main question anyway.

It was bad enough that we had to tell developers to trust some rando website to download a tool that we'd use to potentially plug in sensitive production usernames + credentials. A link that looks like this: https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.ht... And now they've gone and made it worse by posting some new site and confirming the new link is real on their weird "hachyderm" social media post thi…

> on their weird "hachyderm" social media post thing

At this point tech people should understand what Mastodon is. For their own benefit. It's been years.

Post reply on HN