Hacker News new | ask | show | jobs
by pharrington 314 days ago
The man himself also posted about it on his social media https://hachyderm.io/@simontatham/115025974777386803
2 comments

Cool, but hachyderm.io also is not a trusted/recognizable domain for me. Trust issues all the way down!
It's definitionally the correct domain for Simon Tatham's social media. What are you expecting here?
How would the average person know that?
Average person aware of trust on social network / internet - because https://hachyderm.io/@simontatham has a validated link to the author's homepage.

Others - they don't understand the trust anyway, so there prerequisite steps missing before the main question anyway.

It was bad enough that we had to tell developers to trust some rando website to download a tool that we'd use to potentially plug in sensitive production usernames + credentials.

A link that looks like this:

https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.ht...

And now they've gone and made it worse by posting some new site and confirming the new link is real on their weird "hachyderm" social media post thing. Yeah, talk about a grey-beard get-off-my-lawn developer screaming at the wind and wanting to make it worse for themselves and their "brand".

> on their weird "hachyderm" social media post thing

At this point tech people should understand what Mastodon is. For their own benefit. It's been years.

[flagged]
hachyderm.io says it has a validated link to his homepage, but if you don't already trust hachyderm.io that means nothing.
It means a lot - you need to check the other side's meta to confirm yourself. https://fedi.tips/how-do-i-verify-my-account/
If you check the source of the website that it links to [1], on line 168, we have this

<p>I'm on Mastodon as <a rel="me" href="https://hachyderm.io/@simontatham">@simontatham@hachyderm.io</a>.</p>

If you trust that website, then you can be sure that this Mastodon account is the right one.

1. https://www.chiark.greenend.org.uk/~sgtatham/

I just checked his home page: https://www.chiark.greenend.org.uk/~sgtatham/
So… what would be a trusted domain, for you, then?
Exactly. Which nicely confirms all this by saying:

Latest news

2025-08-14 New website, putty.software

We have a new domain name for the PuTTY website!

...

What if someone hacked his site and inserted that news item? Better to visit the guy in person and verify.
What if someone planted the idea of adding a new website for the project while he was asleep?
Which is what the original response linked to. :P
As much as I like fedi, it does make it hard to understand which user on which instance is the correct one.
Luckily, fediverse has an account-to-website verification feature, see https://joinmastodon.org/verification . Mr. Tatham's account on hachyderm.io uses it, so we can be reasonably certain that it's the correct account for him.