Probably related to this: https://notepad-plus-plus.org/news/v869-about-taiwan/
Everyone is entitled to their opinions. My opinion is that open source documentation is like polite dinner conversation: It’s not the proper place to discuss politics. If an author wishes to use their open source project as a platform to discuss politics, that’s the author’s prerogative. But then, as perhaps in this instance, it could be to the detriment of the project itself.
Notepad++ hijacked by state-sponsored actors
361–370 of 560 posts
Re: Notepad++ hijacked by state-sponsored actors
#362Probably related to this: https://notepad-plus-plus.org/news/v869-about-taiwan/
Re: Notepad++ hijacked by state-sponsored actors
#363Earlier quoted context omitted.
The whole approach of virus scanning is reactive and incomplete. This is because, except for some uncertain guesswork using "heuristics", it depends upon vendor analysis of submitted malware infection samples after it's already happened to determine specific malware file/process signatures. This doesn't and cannot catch all possible malware that has ever happened, especially if it's new, not widespread, or evaded ana…
PSA?: How to establish trust?
Re: Notepad++ hijacked by state-sponsored actors
#364Earlier quoted context omitted.
You can totally say Texas should be independent. A lot of Texans have. You can’t be against the Ukraine war in Russia because Putin is an evil dictator
I'm writing this comment from Russia, St. Petersburg, and yes, you can be against the Ukraine war in Russia.
Re: Notepad++ hijacked by state-sponsored actors
#365Which versions where affected and how can people check if they have the infected version?
Re: Notepad++ hijacked by state-sponsored actors
#366Earlier quoted context omitted.
Yes, it is very much atypical. Most hacks happen because admins still haven’t applied a 2 years old patch. I hate updates, but it‘s statistically safer that running an old software version. Try exposing a windows XP to the internet and watch how long it takes before it‘s hacked.
Debatable. "I connected Windows XP to the Internet; it was fine" - https://news.ycombinator.com/item?id=40528117 One comment there points out that XP is old enough for infected attack vectors to have all died out. I dunno.
Re: Notepad++ hijacked by state-sponsored actors
#367Earlier quoted context omitted.
I don’t get it, why don’t you all—absolutely all of you reading—use Little Snitch? [1] It really doesn’t compute in my head why would any macOS user not use a network firewall like this, or similar, to block unwanted outgoing HTTP(s) requests. You can easily inspect the packet with tools like Wireshark or Burp Suite Professional (or Community) edition, or any other proxy tool, of which there are many in the macOS eco…
Now you have to worry about Little snitch not "snitching" on all your traffic.
Re: Notepad++ hijacked by state-sponsored actors
#368Earlier quoted context omitted.
Why woul building from source be safer? Are you veting every single line of third-party source code you compile and use?
You're sure not vetting any byte of an executable, so building from source is safer.
Re: Notepad++ hijacked by state-sponsored actors
#369XMLDSig is notoriously difficult to implement correctly and securely, I hope this doesn't backfire.
Re: Notepad++ hijacked by state-sponsored actors
#370> Traffic from certain targeted users was selectively redirected to attacker-controlled served malicious update manifests. I'd be curious to know if there was any pattern as to which users were targeted, but the post doesn't go into any further detail except to say it was likely a Chinese state-sponsored group.