6 ms·
Cool, but hachyderm.io also is not a trusted/recognizable domain for me. Trust issues all the way down!
by throaway920181 1y ago
Cool, but hachyderm.io also is not a trusted/recognizable domain for me. Trust issues all the way down!
- andrewflnr 1y agoIt's definitionally the correct domain for Simon Tatham's social media. What are you expecting here?
- closewith 1y agoHow would the average person know that?
- viraptor 1y agoAverage person aware of trust on social network / internet - because https://hachyderm.io/@simontatham https://hachyderm.io/@simontatham has a validated link to the author's homepage. Others - they don't understand the trust anyway, so there prerequisite steps missing before the main question anyway.
- jstanley 1y agohachyderm.io says it has a validated link to his homepage, but if you don't already trust hachyderm.io that means nothing.
- viraptor 1y agoIt means a lot - you need to check the other side's meta to confirm yourself. https://fedi.tips/how-do-i-verify-my-account/ https://fedi.tips/how-do-i-verify-my-account/
- mjmas 1y agoFor example, at https://www.chiark.greenend.org.uk/~sgtatham/ https://www.chiark.greenend.org.uk/~sgtatham/ : (the rel=me is the important part) [...] <a rel="me" href="https://hachyderm.io/@simontatham"> [...]
- closewith 1y agoNo, it really means nothing. Identity on the internet is not a solved problem.
- pferde 1y agoYou are wrong. It means that whoever owns the website marked as verified also owns the social account. See https://joinmastodon.org/verification https://joinmastodon.org/verification for a quick overview of how it works.
- closewith 1y agoNo, it means a certain link exists on the website. On Hacker News of all sites, I would think we should all know that's not sufficient evidence of identity for an update regarding the source of critical software like a terminal.
- viraptor 1y agoNobody claimed it validates the identity in any way. It validates that the person at the other website confirms it's their social account and the social account matches the other direction. The real identity is not involved here in any way and never was. You're disagreeing with someone nobody here raises. But the link validation confirms that if you believed that the original download site belongs to the author, then you would have almost the same guarantee about the social account. (+/- the chances of the putty website being hacked)
- closewith 1y agoYes, your caveat at the end there is exactly why this method shouldn't be trusted, as it's indistinguishable from an attacker with access to embed a single link. So it doesn't confirm the account belongs to the author, it confirms the site has a specific link and nothing more.
- Ukv 1y ago
- nottorp 1y agoAnd that's why the fediverse thing is so niche :) Looks like it's as complicated as a parts inventory system developed in house for a half a million employee company...
- viraptor 1y agoThere's a link on one side and a meta tag on the other. It's as simple as you can make the validation between two sites. It's not even fediverse-specific really - there were other services doing something similar before.
- bentinata 1y agoIt's because freedom and correctness is hard. Yeah, most people prefer convenience and would rather someone be the source of authority to do it for them, but people on fediverse are not those kind of people.
- aembleton 1y agoIf you check the source of the website that it links to [1], on line 168, we have this <p>I'm on Mastodon as <a rel="me" href="https://hachyderm.io/@simontatham">@simontatham@hachyderm.io</a>.</p> If you trust that website, then you can be sure that this Mastodon account is the right one. 1. https://www.chiark.greenend.org.uk/~sgtatham/ https://www.chiark.greenend.org.uk/~sgtatham/
- kelnos 1y agoSure, but by the time you've verified that, you could also have just visited the PuTTY website (the old/current one) to verify that putty.software is legit.
- zo1 1y agoIt was bad enough that we had to tell developers to trust some rando website to download a tool that we'd use to potentially plug in sensitive production usernames + credentials. A link that looks like this: https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.ht... And now they've gone and made it worse by posting some new site and confirming the new link is real on their weird "hachyderm" social media post thing. Yeah, talk about a grey-beard get-off-my-lawn developer screaming at the wind and wanting to make it worse for themselves and their "brand".
- andrewflnr 1y agoI just checked his home page: https://www.chiark.greenend.org.uk/~sgtatham/ https://www.chiark.greenend.org.uk/~sgtatham/
- jachee 1y agoSo… what would be a trusted domain, for you, then?
- zaphirplane 1y agohttps://www.chiark.greenend.org.uk/~sgtatham/putty/ https://www.chiark.greenend.org.uk/~sgtatham/putty/
- zugi 1y agoExactly. Which nicely confirms all this by saying: Latest news 2025-08-14 New website, putty.software We have a new domain name for the PuTTY website! ...
- cyphar 1y agoWhich is what the original response linked to. :P
- roman_soldier 1y agoWhat if someone hacked his site and inserted that news item? Better to visit the guy in person and verify.
- rzzzt 1y agoWhat if someone planted the idea of adding a new website for the project while he was asleep?