Simon Tatham: The Student Project That Became PuTTY
Simon Tatham describes himself as "a software engineer and free-software author in Cambridge, UK," and that's about as much as he'll tell you.
But if you've ever opened a black terminal window on a Windows PC and typed a Linux server's address into it, you've probably used his work. PuTTY, the free SSH client he started as a student in 1996, has been the way Windows talks to Unix for more than a quarter of a century.
It's also why North Korean hackers once built a booby-trapped copy of it, and why, in 2024, Tatham had to tell the world that one of his own bugs could hand over your private key.
Simon Tatham at a Glance
- In the summer of 1996, a student annoyed by the terminal emulation in Windows 95's telnet and DOS Kermit, Tatham wrote his own Windows telnet client from scratch and called it STel, for "Simon's Telnet."
- That same year he and Julian Hall wrote NASM, the Netwide Assembler, a free x86 assembler that's still maintained today.
- In 1998 STel gained SSH support and a new name, PuTTY; the first public release, a single putty.exe, went out in January 1999.
- In late 2000 his employer, the chip designer Arm, wanted to run its version control over SSH, so Tatham got a few weeks of work time to add SSH-2, Plink, Pageant and PuTTYgen.
- He ported PuTTY to Linux in 2002, and has since written 49 free puzzle games, a documentation system and a famous essay on how to report bugs, all from the same Cambridge website.
- In September 2022, Mandiant reported that a suspected North Korean group had used a trojanized PuTTY to plant a backdoor at a media company, with a fake Amazon job offer as bait.
- In April 2024 researchers at Ruhr University Bochum found that PuTTY's P-521 signatures leaked private keys after about 60 uses; Tatham shipped the fix in version 0.81 and told users to revoke the affected keys.
- PuTTY added post-quantum key exchange in 2025 and reached version 0.85 in August 2026, with Tatham still listed as its "benevolent dictator."
The Life of Simon Tatham
Simon's Telnet
In the summer of 1996, Tatham was a student with a problem a lot of people had: the telnet client that came with Windows 95 was bad at pretending to be a real terminal, and the DOS version of Kermit wasn't much better.
His first plan, "as a student who hadn't learned pessimism yet," was to take the Unix telnet and xterm code, glue them back to back and port the lot to Windows. He quickly decided it'd be faster to write a new one from scratch.
The result was STel, short for Simon's Telnet, and it got an unusually tough early test. Tatham's father worked at DEC, whose software leaned on obscure corners of the VT100 escape-sequence system, so STel had to handle them all.
From STel to PuTTY
Two years later, people were, as Tatham puts it, getting the memo about network security, and telnet's habit of sending passwords in the clear was becoming indefensible. In the summer of 1998 he added SSH-1 support, and STel became PuTTY.
The first public release went out in January 1999 as a single putty.exe you could download and run, with barely any documentation. Within months a volunteer had added PSCP for copying files, the first of many contributions from strangers who liked the program and wanted it to do one more thing.
What PuTTY stands for, Tatham has never said. "It's the name of a popular SSH and Telnet client," the project FAQ explains. "Any other meaning is in the eye of the beholder."
It's pronounced exactly like the stuff you fill holes with.
A Few Weeks of Arm's Time
By late 2000 Tatham was working at Arm, the Cambridge chip designer, and Arm wanted to run its version control system over SSH. Tatham talked his manager into letting him spend a few weeks of work time on the features it needed, which, he guessed, "worked out cheaper than a lot of ssh.com licences."
That burst produced SSH-2 support and three companions that Windows admins still use daily: Plink for scripted connections, Pageant to hold keys and PuTTYgen to make them. Contributors added X11 forwarding and port forwarding the following year.
In late 2002 Tatham took a full month off work and ported PuTTY to Linux, where its terminal emulator lives on as pterm. Serial-port support arrived in 2007, which is why network engineers still reach for PuTTY to console into a switch.
PuTTY has stayed free in both senses, "in the 'no cost' sense as well as the 'freedom' sense," and it's stayed small: a handful of volunteers with no company behind them, and Tatham listed as "project originator, main developer and benevolent dictator." Most of what it does, he's said, came either from his own need for a feature or from someone else doing the work and sending a patch.
Puzzles, Assemblers and Bug Reports
PuTTY is only the most famous thing on Tatham's website. In 1996 he and Julian Hall wrote NASM, the Netwide Assembler, which became one of the standard x86 assemblers and is still maintained three decades later.
He also wrote Halibut, the documentation system that builds PuTTY's manual, a hex editor called Tweak, a disk-usage tool called agedu, an X11 protocol tracer called xtruss, a calculator called spigot and even a music font called Gonville.
Then there are the games. Simon Tatham's Portable Puzzle Collection, begun in 2004, holds 49 one-player puzzles, from Mines to Untangle, all under the MIT licence, because he believed "there should be more small desktop toys available" and was tired of games that only existed on one operating system. They run on Windows, Unix and in the browser, and volunteers have ported them to Android and iPhone.
His essays travel even further than his code. "How to Report Bugs Effectively" has been mirrored and linked by open-source projects everywhere, and his essay on writing coroutines in C is a classic of the "wait, you can do that?" genre.
A Trojan Horse Named PuTTY
Being the default SSH client on so many Windows desktops has a downside: attackers know people will run it.
In September 2022, Mandiant described a campaign by a suspected North Korean group it called UNC4034. Posing as an Amazon recruiter, the attackers approached an employee of a media company, moved the conversation to WhatsApp and sent over a file named amazon_assessment.iso.
Inside was a PuTTY built from the real 0.77 source code with malicious code injected, plus a readme with fake SSH credentials to try. Running it installed a backdoor Mandiant called AIRDRY.V2. The giveaway: the fake lacked a valid digital signature.
The Bug in the Nonce
Tatham's own worst day came in April 2024. Two researchers at Ruhr University Bochum, Fabian Bäumer and Marcus Brinkmann, found that PuTTY's signatures made with 521-bit ECDSA keys were subtly biased.
The cause was almost elegant. PuTTY generated the per-signature random number by hashing with SHA-512 and reducing the result modulo the curve order, which works for smaller curves. But P-521's order is 521 bits long, so the reduction did nothing, and the top nine bits of every nonce were always zero.
Nine known bits per signature is enough. With about 60 signatures, an attacker could recover the private key and log into every server it unlocked. The flaw, CVE-2024-31497, had existed since version 0.68 and had been inherited by FileZilla, WinSCP, TortoiseGit and TortoiseSVN.
Tatham shipped version 0.81 on April 15, 2024, with blunt advice: anyone who'd used a P-521 key in PuTTY should revoke it everywhere and generate a new one. Ed25519 keys, and every other key size, were fine.
PuTTY Today
PuTTY keeps moving. Version 0.83, in February 2025, added ML-KEM post-quantum key exchange, so that an SSH session recorded today can't be unscrambled by a quantum computer later. Version 0.84 in May 2026 fixed a remotely triggerable double-free in RSA key exchange, and 0.85 in August 2026 closed a batch of Pageant and cipher-mode bugs.
The project also moved house, at least on paper: a new domain, putty.software, now points at the old chiark site, and after 0.85 the putty-announce mailing list was retired in favor of an RSS feed.
Tatham himself is still in Cambridge, still writing C, and still answering bug reports that, one hopes, follow his instructions.
Simon Tatham: Still Scratching His Own Itch
Most of the people on this site got famous by breaking something. Tatham got there by fixing something that annoyed him, then fixing the next thing, for thirty years.
PuTTY has no marketing department and no company, and it's outlived plenty of commercial rivals, because a student who hadn't learned pessimism yet wrote a terminal emulator that actually worked.
Somewhere right now, a sysadmin is pasting a server address into a small gray dialog box and clicking Open. Tatham wrote that box.
QUOTE:
"Amateurs hack systems, professionals hack people."