Live data from Hacker News

Notepad++ hijacked by state-sponsored actors

notepad-plus-plus.org

331–340 of 560 posts

Re: Notepad++ hijacked by state-sponsored actors

#331

So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer? Anyway, I hope the author can be a bit more specific about what actually has happened to those unlucky enough to have received these malicious updates. And perhaps a tool to e.g. do a checksum of all Notepad++ files, and compare them to the ones of a verified clean install of the u…

> So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer?

Is this surprising? My model is that keeping with the new versions is generally more dangerous than sticking with an old version, unless that old version has specific known and exploitable vulnerabilities.

Re: Notepad++ hijacked by state-sponsored actors

#332

I’m on version 8.8.8, which says a lot. This time I unfortunately have to move on from Notepad++. Vibes have been negative for a while but out of inertia (and because there weren't obvious alternatives) I never pulled the trigger. Now it's time. The trust is gone. Thanks NP++ for being free and useful for so many years. Can anyone suggest a solid alternative on Windows? I'm fine with Linux and macOS but I have to kee…

Sublime Text. It's art.

Re: Notepad++ hijacked by state-sponsored actors

#333

> With these changes and reinforcements, I believe the situation has been fully resolved. Fingers crossed. I get that this is a difficult situation for a small developer, but ending with this line did not fill me with confidence that the problem is actually resolved and make me trust their software on my system.

That's the most honest assessment you can expect from any small-scale developer. What do you expect them to say or do? Their adversary is presumably a national intelligence agency of a superpower . The odds may be better if you operate the way OpenSSH does: move slow, security first, architect everything to be very difficult to attack. But if you're building a text editor, it's not your mindset, and probably never wi…

and yet OpenSSH was almost the victim of a giant hack too (xz-utils)

Re: Notepad++ hijacked by state-sponsored actors

#334
post #270
post #228

Earlier quoted context omitted.

"of Notepad++ size" is basically one guy in his free time, no?

"But look at those downloads, they magically print money"

Notepad++ is Windows-based and could use the Windows store instead of the built in updater. Microsoft charges a one time fee. It would pass SmartScreen checks. His website has a bunch of ads integrated which I assume are there to help pay for hosting.

Mr. Ho already has hosting charges and he uses GitHub. For those who use GitHub, he could continue his GnuPG method for signing. Additionally, GitHub integrates with Sigstore. Windows wouldn’t trust his signature but at least there would be better traceability. Version 8.8.7 labeled “authenticity guaranteed” is a step in that direction.

The real “issue” here was his outside hosting platform for updates from my reading of the article.

Re: Notepad++ hijacked by state-sponsored actors

#336
post #331

So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer? Anyway, I hope the author can be a bit more specific about what actually has happened to those unlucky enough to have received these malicious updates. And perhaps a tool to e.g. do a checksum of all Notepad++ files, and compare them to the ones of a verified clean install of the u…

> So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer? Is this surprising? My model is that keeping with the new versions is generally more dangerous than sticking with an old version, unless that old version has specific known and exploitable vulnerabilities.

Yes, it is very much atypical. Most hacks happen because admins still haven’t applied a 2 years old patch. I hate updates, but it‘s statistically safer that running an old software version. Try exposing a windows XP to the internet and watch how long it takes before it‘s hacked.

Re: Notepad++ hijacked by state-sponsored actors

#337

I don't think "we" would have been impacted since this specifically targets the updates, but recently Microsoft pulled Notepad++ from the list of apps we can use on our production management laptops. Some people were annoyed and whining about this. That predated this announcement by a few weeks. Probably the right move by the security folks.

it was pulled because the binaries were self-signed for a short period, not because they knew something

who signed the binaries was irrelevant for this attack, because the issue was not checking any signature

Re: Notepad++ hijacked by state-sponsored actors

#338

Probably related to this: https://notepad-plus-plus.org/news/v869-about-taiwan/

Ah, so this has to do with mainland China going after those who think the Taiwanese do not belong to mainland China. Well, I see them as independent folks. Mainland China needs to stop thinking it can occupy land willy-nilly; unfortunately with USA, Russia and China thinking they can bully other countries that lack nukes, I think these smaller countries absolutely need nukes for defensive purpose. It is also annoying…

[deleted]

Re: Notepad++ hijacked by state-sponsored actors

#339

Earlier quoted context omitted.

Skirt too short, in other words? I'm going to place the blame on the party committing the crimes, not the person exercising free expression.

This is a zero sum take. There are no winners, only the people you deem using free expression correctly. Would a developer who names releases like "Ukrainians are nazi's" or "Taiwan is China" be met with this same sympathy? Or would you brush them off as a mouthpiece for those governments? I'm thinking it's the latter. Free expression is rarely anything other than socially acceptable expression.

What a bad take. Not every political statement is morally equivalent nor worthy of the same respect. Supporting self-determination of people is not the same as supporting oppression of people - for example.

So the free expression is considered by everyone according to their own ethical and moral values.

Re: Notepad++ hijacked by state-sponsored actors

#340
post #71

Earlier quoted context omitted.

Code signing certs are unfortunately expensive

$700+ at Sectigo for two years Something of Notepad++ size might think about it now

the issue was not the money, but that it was difficult to get a certificate without having some sort of legal entity
Post reply on HN