[...] <a rel="me" href="https://hachyderm.io/@simontatham"> [...]Looks like it's as complicated as a parts inventory system developed in house for a half a million employee company...
It means that whoever owns the website marked as verified also owns the social account. See https://joinmastodon.org/verification for a quick overview of how it works.
But the link validation confirms that if you believed that the original download site belongs to the author, then you would have almost the same guarantee about the social account. (+/- the chances of the putty website being hacked)