Others - they don't understand the trust anyway, so there prerequisite steps missing before the main question anyway.
[...] <a rel="me" href="https://hachyderm.io/@simontatham"> [...]It means that whoever owns the website marked as verified also owns the social account. See https://joinmastodon.org/verification for a quick overview of how it works.
But the link validation confirms that if you believed that the original download site belongs to the author, then you would have almost the same guarantee about the social account. (+/- the chances of the putty website being hacked)
So it doesn't confirm the account belongs to the author, it confirms the site has a specific link and nothing more.
Adding a <meta> tag or creating a page with certain content are already used even for more impactful verification, like getting issued a certificate for that domain.
If an attacker does have broad access to edit the HTML of your website, I feel that's already the issue and Mastodon verifying that "this person controls this website" isn't even really wrong.
No sane sober person would use it to authenticate messages about changing URLs in a software supply chain.
This is in addition to the original site linking to the new one with a news post. Does that also mean nothing because an attacker could add a news post to the page?
How is this any different than your email address being compromised? How is this different than having your laptop compromised and somebody downloading your .ssh folder?
The issue here isn't "is this reliable identification" - because it IS reliable. Your concern is "how likely is this to be compromised vs other things" and that's a fair concern - but there are plenty of very secure web sites out there. This isn't saying "I am john doe and this is my identity", this is saying with some confidence "this person on mastadon is the same person as the person who wrote this web site copy" and that's a totally fine piece of identification for the right context.
Looks like it's as complicated as a parts inventory system developed in house for a half a million employee company...
<p>I'm on Mastodon as <a rel="me" href="https://hachyderm.io/@simontatham">@simontatham@hachyderm.io</a>.</p>
If you trust that website, then you can be sure that this Mastodon account is the right one.
A link that looks like this:
https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.ht...
And now they've gone and made it worse by posting some new site and confirming the new link is real on their weird "hachyderm" social media post thing. Yeah, talk about a grey-beard get-off-my-lawn developer screaming at the wind and wanting to make it worse for themselves and their "brand".
At this point tech people should understand what Mastodon is. For their own benefit. It's been years.
Latest news
2025-08-14 New website, putty.software
We have a new domain name for the PuTTY website!
...