Live data from Hacker News

Notepad++ hijacked by state-sponsored actors

notepad-plus-plus.org

371–380 of 560 posts

Re: Notepad++ hijacked by state-sponsored actors

#371

Earlier quoted context omitted.

Debatable. "I connected Windows XP to the Internet; it was fine" - https://news.ycombinator.com/item?id=40528117 One comment there points out that XP is old enough for infected attack vectors to have all died out. I dunno.

https://www.tomshardware.com/software/windows/idle-windows-x... But good we are talking about my point rather than than the example.

> YouTuber Eric Parker demonstrated in a recent video how dangerous it is to connect classic Windows operating systems

The video referenced in that article explicitly connects directly to the internet, using a VPN to bypass any ISP and router protections and most importantly disables any protections WinXP itself has.

So yeah, if you really go out of your way to disable all security protections, you may have a problem.

Re: Notepad++ hijacked by state-sponsored actors

#372
post #4

i always worry about tools like this, maintained by small teams, that are so universal that even if only a small fraction of installs are somehow co-opted by malicious actors, you have a wide open attack surface on most tech companies. e.g. iTerm, Cyberduck, editors of all shades, various VSCode extensions, etc.

I don’t get it, why don’t you all—absolutely all of you reading—use Little Snitch? [1] It really doesn’t compute in my head why would any macOS user not use a network firewall like this, or similar, to block unwanted outgoing HTTP(s) requests. You can easily inspect the packet with tools like Wireshark or Burp Suite Professional (or Community) edition, or any other proxy tool, of which there are many in the macOS eco…

I used to love Zone Alarm's ability to notify me on an application's first attempt to connect to the internet, and allow me to approve or deny it. I really wish there was still such an interface today.

Having said that, I absolutely despised the implementation that stole keyboard focus; if it popped up when I was typing it frequently disappeared before I head a chance to read it and I had to go into settings to try and find what had changed. Nothing should ever steal keyboard focus unless it's urgent, and then it should website that you can't accidentally manipulate it with a keyboard (see UAC prompt where it opens in the background if the calling program is in the background, and where once you activate it, you have to hold alt+y/n or tab to a button before it accepts the input; just hitting the y/n key alone won't do anything).

Re: Notepad++ hijacked by state-sponsored actors

#373
post #168

Earlier quoted context omitted.

Probably the real motive.

“ The incident began from June 2025. Multiple independaent security researchers have assessed that the threat acotor is likely a Chinese state-sponsored group, which would explain the highly selective targeting obseved during the campaign.” How do they know it was a Chinese group or even a state sponsored one?

When you want to spread jingoist paranoia you can just make stuff up and claim any critique is from said actors.

Re: Notepad++ hijacked by state-sponsored actors

#374
post #225

Earlier quoted context omitted.

I partially agree, but as a non-US user of the English speaking internet, the issue is with specifically US politics and social issues being everywhere . It drowns out all attempts at discourse for anything else, and Americans, including people here, seem uniquely incapable of nuance in their thinking when it comes to politics. So, while I fully agree with your stance that banning political discourse is support for t…

> the issue is with specifically US politics and social issues being everywhere. It drowns out all attempts at discourse for anything else Unfortunately, US politics also drives tech issues elsewhere like the EU. For example, local data control is a big thing that some of us have been screaming about forever but nobody paid attention to--until US politics made it a hot button issue. And, to be honest, if the EU would…

>And, to be honest, if the EU would get off its ass and at least try to foster some alternatives, even those of us in the US would benefit.

What exactly do you want the EU, the Brussels based institution, to do here? Because AWS didn't come into existence because Uncle sam came in and twisted Bezo's hand telling him to invent a hyperscaler that will conquer the world.

EU's lack of comparable domestic alternatives is a consequence of the failure of its entrepreneurship and free market in the SW private sector, and nothing that EU institution can do about it to magically fix this since the solution is not MORE regulatory interference form government bureaucrats who don't know how the internet works.

You might be able to force innovation if the governments can throw money at the problem if the VC sector is lacking, but they can't force economies of scale and mass adoption without a China style great firewall, in which case you'd then have even bigger issues.

Re: Notepad++ hijacked by state-sponsored actors

#375

Earlier quoted context omitted.

Skirt too short, in other words? I'm going to place the blame on the party committing the crimes, not the person exercising free expression.

This is a zero sum take. There are no winners, only the people you deem using free expression correctly. Would a developer who names releases like "Ukrainians are nazi's" or "Taiwan is China" be met with this same sympathy? Or would you brush them off as a mouthpiece for those governments? I'm thinking it's the latter. Free expression is rarely anything other than socially acceptable expression.

[deleted]

Re: Notepad++ hijacked by state-sponsored actors

#376
post #306

Earlier quoted context omitted.

You're sure not vetting any byte of an executable, so building from source is safer.

Binaries or source, it's pretty much the same unless you thoroughly vet the entire source code. Malicious code isn't advertised and commented and found by looking at a couple of functions. It's carefully hidden and obfuscated.

That's

However much the code is hidden and obfuscated, some parts of the source code are going to be looked upon.

For a binary, none, ever, except in the extremely rare case that someone disassembles and analyzes one version of it.

The fact that open-source doesn't coincide with security doesn't mean that it isn't beneficial to security.

Re: Notepad++ hijacked by state-sponsored actors

#377
post #215

Earlier quoted context omitted.

By analyzing payloads / C2 address, etc...

Yeah because a state level actor would be completely incapable of false attribution.

With enough effort, anything can be obfuscated. But effort costs money and also state level actors have limited funds and time and want to go home to their families ar some point and if the purpose was to get a message across (don't mess with china, otherwise face the consequences) there is no need to really hide the origin.

Re: Notepad++ hijacked by state-sponsored actors

#378
post #234

Earlier quoted context omitted.

This reminds me of college, when some of my professors were still sorting out their curriculum and would give us homework assignments with bugs in it. I complained many times that they were enabling my innate procrastination by proving over and over again that starting the homework early meant you would get screwed. Every time I'd wait until the people in the forum started sounding optimistic before even looking at t…

Ah, I remember those days. One that wasn't an error exactly was an assignment that had a word limit of 2000 words or something. I'd written maybe 3000 words and spent quite some time cutting it down, getting it to just under the limit. Then someone else who also wrote too many words asked the professor if that was okay and they sent out an update to everyone saying it's fine to ignore the word limit.

You were working within the system of academia, the other student in the system of the real world.

Re: Notepad++ hijacked by state-sponsored actors

#379

Earlier quoted context omitted.

From the Heise article: > Until version 8.8.7 of Notepad++, the developer used a self-signed certificate, which is available in the Github source code. This made it possible to create manipulated updates and push them onto victims, as binaries signed this way cause a warning „Unknown Publisher“ It also mentions "installing a root certificate". I suspect that it means that users who installed the root cert could check…

Notepad++ has way too many updates for a text editor. I purposely decline most of the nags to update for precisely this reason. It is too juicy of a target and was bound to get compromised.

Well, some people use it as a IDE, so there are more feature they need. But I am not sure if a less frequent update routine would be safer.

Re: Notepad++ hijacked by state-sponsored actors

#380

Earlier quoted context omitted.

I'm writing this comment from Russia, St. Petersburg, and yes, you can be against the Ukraine war in Russia.

Always hiliarious when westerners think they know how life works in Russia, China, etc because they heard from it on TV.

Of course it’s all propaganda, comrade, you can openly protest against the ~~war~~ SMO. Don’t forget your Z insignia, though.
Post reply on HN