Live data from Hacker News

Notepad++ hijacked by state-sponsored actors

notepad-plus-plus.org

301–310 of 560 posts

Re: Notepad++ hijacked by state-sponsored actors

#301

Earlier quoted context omitted.

I live in a society that feeds me and rewards me for work and does a whole host of other things for me. I am grateful for all of it. Many other people are not so well served by society. This is all true. None of that has anything to do with politics. Politics is a game. It is played with one single objective: to make sure that the people with no political power remain fighting among themselves instead of fighting tho…

I'm taking you're from the US from the "either team" comment. That is a really elementary understanding of politics. Politics, again, is a word describing how humans behave in groups. Where are roads built? That's a political decision made by groups of humans reaching consensus. What is the budget for the local security force? That's a political decision made by groups of humans reaching consensus. How much money is…

You know what's even more important than politics? Water. That doesn't mean I need to read a prologue about water in every HN article reminding me that I require water to survive.

You seem very angry at a stranger on the internet. I think a break from thinking about everything through the lens of politics might be good for you.

Re: Notepad++ hijacked by state-sponsored actors

#302
post #194

Earlier quoted context omitted.

It is baffling to me, as well. You know how you get a remote-code-execution vulnerability? You give a bunch of software permission to fetch code remotely and execute it.

Like… browser? Or anything with script loading capabilities like script engine in games. Executing remote script is almost unavoidable nowadays. And there isn't really a way to confirm if it is configured in a secure way. You either trust the developer or not.

First, it wasn't even the developer who compromised people, here; second, scripts in most cases are orders of magnitude less dangerous than a windows executable.

And, in many cases you can get some protection from a developer going rogue (or not writing perfect code), it's not an all or nothing.

Re: Notepad++ hijacked by state-sponsored actors

#303

Earlier quoted context omitted.

I can't help but feel there must some better venue for such messaging. When I see politics in software updates or documentation, nothing happens because I'm not looking to use the software for political activism. Maybe I tell my adblocker to remove the messaging, and carry on with my task. I can engage with politics in a social context, when political messaging isn't interrupting something else I'm doing; that's a be…

Similar comments also come up in the [now regular] "I don't want to see political articles on HN" threads, and I think the response is similar: Asking for "no politics" is itself a strong political view: One in support/service of whatever the current status quo is. Trying to set oneself apart from (or above) politics is itself political. If you're lucky enough to be one of the fortunate people on earth who are not un…

> Asking for "no politics" is itself a strong political view

If this is true, I'd like to know what a weak political view is instead!

Re: Notepad++ hijacked by state-sponsored actors

#304

Earlier quoted context omitted.

Someone tried to kill you?! People actually killed your friends? Not sure if schizophrenia or actual story ... I desperately need to hear more of this story.

[flagged]

I don't think they're being malicious. It is definitely a normal reaction to respond with incredulity at something incredible.

As in, someone was actually killed because their friend forked an open source project? There is clearly more to the story, it's not like if I forked Audacity tomorrow people would be after me immediately.

The explanation, if any, involves the whole thing being very public and 4chan harassment, etc.

Re: Notepad++ hijacked by state-sponsored actors

#305

Earlier quoted context omitted.

I'm taking you're from the US from the "either team" comment. That is a really elementary understanding of politics. Politics, again, is a word describing how humans behave in groups. Where are roads built? That's a political decision made by groups of humans reaching consensus. What is the budget for the local security force? That's a political decision made by groups of humans reaching consensus. How much money is…

You know what's even more important than politics? Water. That doesn't mean I need to read a prologue about water in every HN article reminding me that I require water to survive. You seem very angry at a stranger on the internet. I think a break from thinking about everything through the lens of politics might be good for you.

> You know what's even more important than politics? Water.

Access to water is political. If you get water from the city, the building of infrastructure delivering water to your residence is political. Whether or not that water is polluted is political. If you get your water from a well on your own property, your ownership of that land is political. None of that is achieved without group consensus, and group consensus can take all of it away from you. You are able to ignore that fact because all of those political consensuses are currently going in your favor, but the same is not true for everyone, and when it isn't true for them, they can be predicted to make noise about not having access to water for obvious reasons. They will make noise about it everywhere they can because it will be more important than anything else to them, given that it will determine whether they live or die and they need to galvanize communal support in order to reverse their fortunes.

> You seem very angry at a stranger on the internet. I think a break from thinking about everything through the lens of politics might be good for you.

My previous comment was written entirely neutrally, so I'm not sure how you came to that conclusion. Incidentally, I happen to live in a prosperous and stable society that I have confidence will remain secure for decades to come, so I have the privilege to ignore politics at my leisure. I am grateful for that opportunity, but I also understand how much of a privilege it is that politics are going well and not actively creating problems for me, so when other people complain about political processes creating problems for them, like the threatened invasion of their country, I listen without complaining.

I took HN as a place for rational discussion, so I made an effort to communicate to you why politics are so important to many, but in the end it seems this discussion is fruitless. If there is any emotion I feel, it is that of disappointment for wasting my time trying to discuss things logically and rather than being met with any kind of reasoned rebuttal, I get a childish dismissal the likes of which I could've gotten on Reddit, which I stopped using for that very reason a decade ago.

Re: Notepad++ hijacked by state-sponsored actors

#306

Earlier quoted context omitted.

Yup, the only way to combat this as a smalltime dev would be to turn off auto updates and make people build from source.

Why woul building from source be safer? Are you veting every single line of third-party source code you compile and use?

You're sure not vetting any byte of an executable, so building from source is safer.

Re: Notepad++ hijacked by state-sponsored actors

#307
post #4

i always worry about tools like this, maintained by small teams, that are so universal that even if only a small fraction of installs are somehow co-opted by malicious actors, you have a wide open attack surface on most tech companies. e.g. iTerm, Cyberduck, editors of all shades, various VSCode extensions, etc.

I don’t get it, why don’t you all—absolutely all of you reading—use Little Snitch? [1] It really doesn’t compute in my head why would any macOS user not use a network firewall like this, or similar, to block unwanted outgoing HTTP(s) requests. You can easily inspect the packet with tools like Wireshark or Burp Suite Professional (or Community) edition, or any other proxy tool, of which there are many in the macOS eco…

Now you have to worry about Little snitch not "snitching" on all your traffic.

Re: Notepad++ hijacked by state-sponsored actors

#308
post #278

Earlier quoted context omitted.

No it's not and if you do believe that, you are taking an overly reductionist viewpoint. 99% countries, as they say, "acknowledge China's viewpoint".

~120 countries fully endorse One China Policy. ~60 acknowledge. ~10 recognize ROC.

https://interactives.lowyinstitute.org/features/one-china-co...

Re: Notepad++ hijacked by state-sponsored actors

#309
post #56

Earlier quoted context omitted.

I don’t get it, why don’t you all—absolutely all of you reading—use Little Snitch? [1] It really doesn’t compute in my head why would any macOS user not use a network firewall like this, or similar, to block unwanted outgoing HTTP(s) requests. You can easily inspect the packet with tools like Wireshark or Burp Suite Professional (or Community) edition, or any other proxy tool, of which there are many in the macOS eco…

It’s a false sense of security, more or less. If an application wants to talk to a C2 they don’t have to make a connection at all, just proxy a connection through something already allowed, or tunnel through DNS. Those juicy cryptocurrency keys? Pop Safari with them in the URL and they’re sent to the malicious actor instantly. If you’re owned Little Snitch does nothing at all for you except give you the impression th…

That's at the very least harder and less likely; security is not all or nothing.

Re: Notepad++ hijacked by state-sponsored actors

#310
post #174

Earlier quoted context omitted.

I don’t get it, why don’t you all—absolutely all of you reading—use Little Snitch? [1] It really doesn’t compute in my head why would any macOS user not use a network firewall like this, or similar, to block unwanted outgoing HTTP(s) requests. You can easily inspect the packet with tools like Wireshark or Burp Suite Professional (or Community) edition, or any other proxy tool, of which there are many in the macOS eco…

If an application wants to talk to AWS, how am I supposed to know if it's legit or not?

If it began doing it after an update, you know that it's better to check if it's supposed to do it
Post reply on HN