Live data from Hacker News

Notepad++ hijacked by state-sponsored actors

notepad-plus-plus.org

421–430 of 560 posts

Re: Notepad++ hijacked by state-sponsored actors

#421

Earlier quoted context omitted.

Bro, it's political. Political isn't synonymous with "bad" or with "propaganda". Wars are waged on many fronts, and securing economic and hardware support takes messaging.

In fact, Carl von Clausewitz is known for saying "War is politics by other means" (among many other great quotes)

I'd say politics is war by other means. First we killed each other for resources. Then we decided killing sucked, and if your tribe doesn't kill my tribe, my tribe won't kill your tribe, but now we have to decide how many resources we each get. It's hard work to keep things like this and avoid reverting back to the default state.

Re: Notepad++ hijacked by state-sponsored actors

#422

Earlier quoted context omitted.

I can't help but feel there must some better venue for such messaging. When I see politics in software updates or documentation, nothing happens because I'm not looking to use the software for political activism. Maybe I tell my adblocker to remove the messaging, and carry on with my task. I can engage with politics in a social context, when political messaging isn't interrupting something else I'm doing; that's a be…

Similar comments also come up in the [now regular] "I don't want to see political articles on HN" threads, and I think the response is similar: Asking for "no politics" is itself a strong political view: One in support/service of whatever the current status quo is. Trying to set oneself apart from (or above) politics is itself political. If you're lucky enough to be one of the fortunate people on earth who are not un…

I disagree. I want to separate my technology from politics. I consume politics through other venues. I don’t want HN full of political articles. It doesn’t mean I support status quo. It means I don’t want this one website pushing politics, which it increasingly does.

HN discussions are usually very high quality and respectful disagreement therein, which is unique online nowadays.

I’ve come here to escape Reddit, which is all politics all the time. If this place turns as political as Reddit, I’m out.

Re: Notepad++ hijacked by state-sponsored actors

#424
post #331

So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer? Anyway, I hope the author can be a bit more specific about what actually has happened to those unlucky enough to have received these malicious updates. And perhaps a tool to e.g. do a checksum of all Notepad++ files, and compare them to the ones of a verified clean install of the u…

> So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer? Is this surprising? My model is that keeping with the new versions is generally more dangerous than sticking with an old version, unless that old version has specific known and exploitable vulnerabilities.

Steve from Security Now podcast has been specifically using Notepad++ as an example of not being able to leave good enough alone for years now. Can't wait to hear him claim his told you so next week.

Love notepad++ and will continue to use it.

Re: Notepad++ hijacked by state-sponsored actors

#425

Earlier quoted context omitted.

There is more detail linked below: https://www.heise.de/en/news/Notepad-updater-installed-malwa... https://doublepulsar.com/small-numbers-of-notepad-users-repo... The TLDR is that until version 8.8.7 of Notepad++, the developer used a self-signed certificate, which was available in the Github source code. The author enabled this by not following best practices. The "good news" is that the attacks were very targeted a…

out of curiosity, why is a self signed cert bad for this case? Can't the updater check the validity of the cert just as well regardless? Or did the attackers get access to the signing key as well?

It would still have been less than ideal, but he might have gotten away with it if the private key wasnt stored within the public Github repo.

Re: Notepad++ hijacked by state-sponsored actors

#426

Earlier quoted context omitted.

Hum... We keep pretending the Solar Winds scandal never happened?

that wasnt really microsoft massive though.

It didn't happen by Microsoft fault. It reached all of Microsoft... and every other company that sells software or computers to the US government.

Re: Notepad++ hijacked by state-sponsored actors

#427

Earlier quoted context omitted.

This is a zero sum take. There are no winners, only the people you deem using free expression correctly. Would a developer who names releases like "Ukrainians are nazi's" or "Taiwan is China" be met with this same sympathy? Or would you brush them off as a mouthpiece for those governments? I'm thinking it's the latter. Free expression is rarely anything other than socially acceptable expression.

What a bad take. Not every political statement is morally equivalent nor worthy of the same respect. Supporting self-determination of people is not the same as supporting oppression of people - for example. So the free expression is considered by everyone according to their own ethical and moral values.

I'm not sure you realize but you're agreeing with my statement. So it's a bit odd that you call it a bad take.

Re: Notepad++ hijacked by state-sponsored actors

#428
post #40

Earlier quoted context omitted.

The notepad++ author has publicly come out in favor of Taiwanese independence.

Taiwan is already independent. Surely the normal way to refer to it would be as coming out against assimilation with mainland China?

[dead]

Re: Notepad++ hijacked by state-sponsored actors

#429

Earlier quoted context omitted.

Yeah, Notepad++ is known for political messaging in their updates. Taiwan, Ukraine, etc.

I can't help but feel there must some better venue for such messaging. When I see politics in software updates or documentation, nothing happens because I'm not looking to use the software for political activism. Maybe I tell my adblocker to remove the messaging, and carry on with my task. I can engage with politics in a social context, when political messaging isn't interrupting something else I'm doing; that's a be…

> When I see politics in software updates or documentation, nothing happens

I find this take deeply ironic.

And here due to alleged political take of some software (Notepad++), __state sponsored software__ was used to attack users of said software. Something actually happened!

You don't want to see politics in any software, but may be (or already are) a victim of political software attack (from state sponsored tracking, to sanctions, to political psy-ops through software distributing (social) media).

> Maybe I tell my adblocker to remove the messaging, and carry on with my task. > > I can engage with politics in a social context, when political messaging isn't interrupting something else I'm doing; that's a better place for activism, IMHO.

You are clearly annoyed by ads, like many of us - maybe you should get public attention to change policy about ads? How they are annoying? How there are unskippable Ads in TV services that I pay money for? How there are big enterprises using their monopoly/oligopoly powers to make you stop being able to adblock ever again? Or do you only block ads you deem "political"?

_______

States (and not only them) will use software and even open source software (open source IMHO is also a political take/view) to get to you if it's ever needed. Though congrats you just got extra social credits in __both__: China's and Palantir's databases!

Re: Notepad++ hijacked by state-sponsored actors

#430

So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer? Anyway, I hope the author can be a bit more specific about what actually has happened to those unlucky enough to have received these malicious updates. And perhaps a tool to e.g. do a checksum of all Notepad++ files, and compare them to the ones of a verified clean install of the u…

This reminds me of college, when some of my professors were still sorting out their curriculum and would give us homework assignments with bugs in it. I complained many times that they were enabling my innate procrastination by proving over and over again that starting the homework early meant you would get screwed. Every time I'd wait until the people in the forum started sounding optimistic before even looking at t…

> let my friends try out software updates first before I do

And who do they let try the software before they do? And so on... Where does it ended?

Post reply on HN