Live data from Hacker News

Notepad++ hijacked by state-sponsored actors

notepad-plus-plus.org

191–200 of 560 posts

Re: Notepad++ hijacked by state-sponsored actors

#191
post #119

Earlier quoted context omitted.

>Software like most Sciences, Engineering, and Trade are much longer game for humanity than politics de jour. Not really, software, like sciences and engineering must survive politics first. If humans start tossing around nukes like angry apes then those that survive may be scratching simple arithmetic with a charcoal stick on a cave wall.

This take is completely blind to how sciences has worked throughout history of humanity and specifically post major world wars. Additionally, it is based on a false notion that political banners in software helps in pursuing anyone let alone change political outcomes.

Science has absolutely engaged in the politics du jour, including in major world wars. See, for example, the Szilárd petition[1]. (If you need a post-WWII example, those same scientists continued petitioning after the war on the dangers of nukes, too.)

Further, political banners in software have absolute helped, and have changed political outcomes. As an example of that, SOPA, and later PIPA, were defeated by websites such as Wikipedia (which are software) putting banners aimed at informing the public of those bills.

[1]: https://en.wikipedia.org/wiki/Szil%C3%A1rd_petition

Re: Notepad++ hijacked by state-sponsored actors

#192

Earlier quoted context omitted.

It wouldn't protect against this attack though. The Notepad++ update servers were hijacked. Presumably you would allow Notepad++ updates through Little Snitch so you would be equally as vulnerable.

No, why would you allow automatic updates? It makes no sense. You should audit every update as if each payload could contain malware. It’s a paranoid way to live, but that’s what it takes. We also need better computer science education in high schools, teaching students how to inspect network packets, verify SSL certificates, and evaluate whether a binary blob might contain malicious code. People have gotten complace…

Tell me about your auditing workflow and procedures.

Re: Notepad++ hijacked by state-sponsored actors

#193

So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer? Anyway, I hope the author can be a bit more specific about what actually has happened to those unlucky enough to have received these malicious updates. And perhaps a tool to e.g. do a checksum of all Notepad++ files, and compare them to the ones of a verified clean install of the u…

This reminds me of college, when some of my professors were still sorting out their curriculum and would give us homework assignments with bugs in it.

I complained many times that they were enabling my innate procrastination by proving over and over again that starting the homework early meant you would get screwed. Every time I'd wait until the people in the forum started sounding optimistic before even looking at the problem statement.

I still think I'd like to have a web of trust system where I let my friends try out software updates first before I do, and my relatives let me try them out before they do.

Re: Notepad++ hijacked by state-sponsored actors

#194
post #182

Vindicated once again for turning off any update checks the moment I install any new piece of software. Even if this sort of (obviously rare) attack is not a concern, it baffles me how few otherwise-intelligent people fail to see the way these updaters provide the network (which itself is always listening, see Room 641A and friends) with a fingerprint of your specific computer and a way to track its physical location…

It is baffling to me, as well. You know how you get a remote-code-execution vulnerability? You give a bunch of software permission to fetch code remotely and execute it.

Re: Notepad++ hijacked by state-sponsored actors

#195

Earlier quoted context omitted.

I partially agree, but as a non-US user of the English speaking internet, the issue is with specifically US politics and social issues being everywhere . It drowns out all attempts at discourse for anything else, and Americans, including people here, seem uniquely incapable of nuance in their thinking when it comes to politics. So, while I fully agree with your stance that banning political discourse is support for t…

I am an American and I make a very conscious effort to appreciate social and political nuances. And I go out of my way to point out nuances to others who, in my opinion, oversimplify their statements. It could be argued that the expression of stereotyping Americans as lacking nuance, itself lacks nuance. I believe really most people are similar in that we have our biases, differences in context and experiences. We ca…

I would say it's statistics, rather than stereotyping. I'm glad you're capable of nuance though, maybe you can teach that to some of your compatriots?

Re: Notepad++ hijacked by state-sponsored actors

#196

Earlier quoted context omitted.

It intrinsically does. Whatever stance changes nothing or prefers to change nothing is a vote for the status quo, by definition.

> Whatever stance changes nothing .. is a vote for the status quo, by definition. As problematic as the assertion "by definition" is aside, it should be noted that endlessly commenting about politics on internet forums effectively changes nothing. I've been kettled by mounted officers and hit by high pressure hoses on cold evenings, something that also rarely effects change .. but that's a least a fun night out with…

Whether it's a waste is not entirely up to you. There are plenty of people on this forum who are completely naive and live in a bubble. The chance that a comment they see her could make a lightbulb go off is non-zero.

But if I were a nihilist I might agree with you.

Re: Notepad++ hijacked by state-sponsored actors

#197
post #180

Can someone help clarify this for me? Is it correct to say that users would only get the compromised version if they downloaded from the website? Notepad++ has auto-update feature, is there any indication that updates from the AutoUpdate were compromised?

No, it's specifically the updates that were targetted. I'm unsure about the downloads but those too are presumably at risk.

> The attackers specifically targeted Notepad++ domain with the goal of exploiting insufficient update verification controls that existed in older versions of Notepad++.

Re: Notepad++ hijacked by state-sponsored actors

#198

Earlier quoted context omitted.

> I can't help but feel there must some better venue for such messaging. I would argue that this has been an effective avenue for messaging/protest. You’re responding to it on this very board - that means you’re thinking about it. Another angle: would such free protest be allowed if the developers of Notepad++ were based in China or Russia? I seriously doubt it.

Based on arrest of protesters in UK, US, and recent laws passed in Australia; it is fair to say that Notepad++’s freedom to protest would depend on who and what they are protesting.

I would have been interested in debating the content of your reply if your account had not been created 1 hour ago.

So what about protesting the Russian invasion of Ukraine seems objectionable to you?

> it is fair to say that Notepad++’s freedom to protest would depend on who and what they are protesting.

What? In the US, UK, and Australia, the right to protest (i.e. of speech) does not depend on what’s being protested in the way you’re implying.

Re: Notepad++ hijacked by state-sponsored actors

#199

Earlier quoted context omitted.

Choosing not to engage politically is not a neutral action. Life is politics. The world is full of people that are trying to control your life in a thousand different ways. Choosing to not engage in support or opposition to that control doesn't mean you aren't participating, it means your default position is letting them do what they want.

Is choosing to set certain parts of one’s life apart from politics equivalent to “choosing not to engage politically?” If so then shouldn’t every action that you take be imbued with politics, including the choice of how long you brush your teeth and when, where, and how you sleep? Or are certain things exempt from the rule, but not posting on HN? If that’s the case, why does posting on HN require political engagement…

I think this is a good example you provide about the store clerk at the grocery store, and I think you can expand this even further. Sometimes when I go to a store and am checking out they will ask me to donate to some random charity. Whether or not I care about the cause they are asking for money for doesn't matter at all in that moment. It annoys me and I don't want it to be asked in that interactions as that's not what I'm there for and not what I care to be put on the spot to think about.

I view these kinds of weird virtue signaling political statements on things like software to be the same. They do absolutely nothing and are just visual noise for nothing. Actually, this is a good example of where it can go wrong as it likely made the software the target of Chinese state-sponsored actors. So not only does it serve no useful purpose, it also can make you a target and piss people off.

Re: Notepad++ hijacked by state-sponsored actors

#200

Earlier quoted context omitted.

yes, that's my question: am I compromised? What should I do?

Standard answer to a potentially compromised machine is to start with a factory reset machine and add the software and data you need to do your work/use the machine. Do not take executables from the compromised machine and use them any where since they too could be compromised. There are more steps you can take to ensure greater safety. The above is the minimum a I do for myself and what the minimum IT department and…

[deleted]
Post reply on HN