Earlier quoted context omitted.
This seems similar to the Notepad++ team using their platform to promote political viewpoints. The same thing happened with Facebook "pages", when they became a personal "soap box" by the owner of the page. It was downhill from there... You might as well turn the whole web into FB/Twitter/X/Insta promotional spam at that point.
It's one thing to say "stand with Ukraine", and an entirely different thing to spread vaccine misinformation...
PuTTY has a new website
281–290 of 304 posts
Re: PuTTY has a new website
#282Earlier quoted context omitted.
You are wrong. It means that whoever owns the website marked as verified also owns the social account. See https://joinmastodon.org/verification for a quick overview of how it works.
No, it means a certain link exists on the website. On Hacker News of all sites, I would think we should all know that's not sufficient evidence of identity for an update regarding the source of critical software like a terminal.
Re: PuTTY has a new website
#283Earlier quoted context omitted.
Yes, your caveat at the end there is exactly why this method shouldn't be trusted, as it's indistinguishable from an attacker with access to embed a single link. So it doesn't confirm the account belongs to the author, it confirms the site has a specific link and nothing more.
A regular link won't do, since it requires the rel="me" attribute, which is intended for this purpose: https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/... Adding a tag or creating a page with certain content are already used even for more impactful verification, like getting issued a certificate for that domain. If an attacker does have broad access to edit the HTML of your website, I feel that's already…
Re: PuTTY has a new website
#284Ever since Windows gained Terminal and OpenSSH, my usage of Putty has almost entirely ceased except for serial for embedded systems work. Then I realised Putty ships with a CLI version which I now use in Terminal for accessing serial.
I always used mingw and similar projects. IMO, putty was always annoying (but very useful) software. The "ecosystem" seems better now though.
Re: PuTTY has a new website
#285Earlier quoted context omitted.
I agree. In those screenshots cmd looks better. Not sure what's up.
It's the lack of subpixel anti-aliasing (aka ClearType). For some reason it's being erased from a lot of modern software. It's why Windows >= 8 UWP apps and GNOME look so blurry.
Re: PuTTY has a new website
#286Re: PuTTY has a new website
#287Earlier quoted context omitted.
That looks like an open and shut ICANN trademark case to me. https://web.archive.org/web/20250728091154/https://www.putty...
Do they have a trademark? It costs $325 per year plus roughly $650 for the initial application (even if rejected). Is he paying that?
Re: PuTTY has a new website
#288It's incredible to me that this tool is still needed. Using putty as my daily driver was definitely part of my coming-of-age story as a windows sysadmin way back when.
It’s not needed on modern Windows strictly speaking, but many users still prefer it.
Re: PuTTY has a new website
#289Somehow, these new long TLDs just feel spammy and "fake" and I usually ignore them when they show up in search results. Unfortunately the .com, .net and .org are already taken.
Even a .com/org/net with something like getputty or similar as the domain name would feel less sketchy than putty.sofware.
putty.net is also up for sale but probably will be an unreasonable price and paying the troll toll would suck.
Re: PuTTY has a new website
#290Somehow, these new long TLDs just feel spammy and "fake" and I usually ignore them when they show up in search results. Unfortunately the .com, .net and .org are already taken.
Certificate by Let's Encrypt, issued to "putty.software" no other info. Sometimes I feel like we are training users to disregard safety mechanisms for phishing. Using putty was never the pinnacle of professionalism and open source auditing anyway, it's just a binary you download on windows before you hear the gospel of linux and ssh.
That's how domain validated certificates that are used on most website today work.
And yes, it's bonkers that we need to rely on authorities like Let's Encrypt for this instead of just delegating trust via the same hierarchy as DNS.