"None of which would have mattered if Putty.exe was codesigned. Unfortunately it is not."You mean Autenticode on Windows? I once had an Authenticode code signing cert that I used to sign Windows executables. Mostly, I signed hobby projects with it.
I wrote a proof of concept keystroke logger for Windows, then Authenticode signed it and made it available along with source code for others to experiment with and review.
Several years later, some customers of Zemena and Comodo complained that the keystroke detection/security software (that they had paid money for) did not detect my keystroke logging software.
This caused a big fuss. Even though my software had been available for years, was code signed, came with full source code and was clearly labeled for educational purposes only, the security companies sent takedown notices to my ISP, placed my domain on DNS blacklists and 'fixed' the issue by declaring any exe signed by my Authenticode cert as malicious. Their customers were then happy and felt safer as it was now 'detected'.
The real issue was that the security software trusted any code that was Authenticode signed and let it run no matter what. There was a check-box somewhere to disable that, but long story short, I would not say that Authenitcode code signing is a big security benefit today. It may help some, but not much. Maybe in the future.
I still have the Keystroke logger source code: https://github.com/w8rbt/keycap
Someone with an Authenticode cert should compile it and then sign it and see if it still gets by the security vendors.