Live data from Hacker News

Notepad++ supply chain attack breakdown

securelist.com

201–205 of 205 posts

Re: Notepad++ supply chain attack breakdown

#201
post #99
post #66

Earlier quoted context omitted.

The containers are literally the "bolting on". You need to give the illusion of the software is running under a full OS but you can actually mount the system directories as read-only.

and you still need to mount volumes and add all sorts of holes in the sandbox for applications to work correctly and/or be useful try to run gimp inside a container for example, you’ll have to give access to your ~/Pictures or whatever for it to be useful Compared to some photo editing applications on android/iOS which can work without having filesystem access by getting the file through the OS file picker

What we need is a model similar to Google+ circles if anyone can remember that.

Basically a thing that I could assign 1) apps and 2) content to. Apps can access all content in all circles they are assigned to. Circles can overlap arbitrarily so you can do things like having apps A,B,C share access to documents X,Y but only A,B have access to Z etc.

Re: Notepad++ supply chain attack breakdown

#203

Earlier quoted context omitted.

I'm sure that will contribute to the illusion of security, but in reality the system is thoroughly backdoored on every level from the CPU on up, and everyone knows it. There is no such thing as computer security, in general, at this point in history.

I'm sure you're right; however, there is still a distinction between the state using my device against me and unaffiliated or foreign states using my device against me or more likely simply to generate cash for themselves. It's still worth solving one of these problems.

A distinction without a difference. One mafia is as bad as another. One screws you in the short term, the other screws you in the long term, and much worse.

The problem in both cases is the massive attack surface at every level of the system. Most of these proposals about "security" are just rearranging deckchairs on the Titanic.

If you can't keep a nation state out (and you're referring to your own state, right?) then you can't keep a lone wolf hacker out either, because in either case that's who's doing the work.

Re: Notepad++ supply chain attack breakdown

#204
post #180

This is the nudge I needed to stop using VSCodium completely. (No offense to its devs, mind you, who seem to much better have their act together.)

Why?

VSCode is the most popular IDE right now, making it and its telemetry-free derivative (and their overlapping extension ecosystem) too juicy of a target for a supply chain attack. Over 75% of devs use VSCode, according to the SO survey. And there's also the potential of Codium itself being targeted, despite it currently having a small userbase by comparison, which could easily change as MSFT does to VSCode what it did to Windows. Also, I predict MSFT is going to make it progressively more difficult for the Codium devs to completely strip anti-privacy "features" from VSCode upstream.

Re: Notepad++ supply chain attack breakdown

#205
post #204

Earlier quoted context omitted.

Why?

VSCode is the most popular IDE right now, making it and its telemetry-free derivative (and their overlapping extension ecosystem) too juicy of a target for a supply chain attack. Over 75% of devs use VSCode, according to the SO survey. And there's also the potential of Codium itself being targeted, despite it currently having a small userbase by comparison, which could easily change as MSFT does to VSCode what it did…

Definitely all true!

If you don’t need it, I wouldn’t use it.

Thanks.

Post reply on HN