Live data from Hacker News

Notepad++ hijacked by state-sponsored actors

notepad-plus-plus.org

461–470 of 560 posts

Re: Notepad++ hijacked by state-sponsored actors

#461

So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer? Anyway, I hope the author can be a bit more specific about what actually has happened to those unlucky enough to have received these malicious updates. And perhaps a tool to e.g. do a checksum of all Notepad++ files, and compare them to the ones of a verified clean install of the u…

I disable auto update for everything that does not have direct contact with the Internet otherwise (mail app, browser, OS, router,...). Probability for some random app being exploited because updates were skipped is insignificant compared to the probability of a malicious update.

Updates are a direct connection from the Internet to your computer. You want to minimize that.

Just do a manual update from time to time.

Re: Notepad++ hijacked by state-sponsored actors

#462
post #406

Earlier quoted context omitted.

A petition and including your political opinions whenever you engage in your trade or profession is not the same. This is the entire point and objection with politicisation of everything.

> whenever you engage in your trade or profession is not the same Feels like this is overstating the facts. Afaik, twice did the author on N++ did include a small political message in a release. Is it really "whenever"? Blowing this out of proportions because some are so allergic to any political message that twice in 10 years is being pushy.. In the end, everything involving more than 2 humans is politics. You may w…

Only for the ideologue every interaction must be burdened by partisan politics.

Re: Notepad++ hijacked by state-sponsored actors

#463
post #331

Earlier quoted context omitted.

> So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer? Is this surprising? My model is that keeping with the new versions is generally more dangerous than sticking with an old version, unless that old version has specific known and exploitable vulnerabilities.

Yes, it is very much atypical. Most hacks happen because admins still haven’t applied a 2 years old patch. I hate updates, but it‘s statistically safer that running an old software version. Try exposing a windows XP to the internet and watch how long it takes before it‘s hacked.

It depends if the application itself touches the Internet or only when conducting updates.

The threat model for a server and for a personal computer are very different. On a consumer device, typically only the OS mail app and browser have direct contact with the outside world.

Re: Notepad++ hijacked by state-sponsored actors

#464
post #438

Earlier quoted context omitted.

Hysterics aside, this is a real effect and you’re a fool for ignoring it.

I know it's real. But it doesn't excuse giving away one's values just because something inconvenienced them. As an example, do I find some vegans annoying on the internet? Yes. Does it mean I will instead start supporting carnism, or push back on veganism? No, absolutely not. Because these are values I have, and no actions of others can change what I value.

The fundamental values don’t often change, but if you alienate people enough they will shift their activities to supporting a different cause they care about, or give up and tune out entirely. It’s self-defeating. You can’t win with radicals alone.

Re: Notepad++ hijacked by state-sponsored actors

#465
post #456

I guess my habit of running a firewall and not allowing programs to access the internet unless they actually need it is helpful for stuff like this. Absolutely no reason a text editor needs internet access. I only update stuff through winget, which fetches the installer from github in a lot of cases, and changing a package requires a PR to the winget repo AFAIK. Not foolproof of course though.

Checking for updates and pulling in plug-ins. Both are valid.

Re: Notepad++ hijacked by state-sponsored actors

#466

Earlier quoted context omitted.

This reminds me of college, when some of my professors were still sorting out their curriculum and would give us homework assignments with bugs in it. I complained many times that they were enabling my innate procrastination by proving over and over again that starting the homework early meant you would get screwed. Every time I'd wait until the people in the forum started sounding optimistic before even looking at t…

> let my friends try out software updates first before I do And who do they let try the software before they do? And so on... Where does it ended?

There is always a fresh group of people who haven't learned that lesson yet acting as the guinea pigs.

Re: Notepad++ hijacked by state-sponsored actors

#467

Earlier quoted context omitted.

Whether it's a waste is not entirely up to you. There are plenty of people on this forum who are completely naive and live in a bubble. The chance that a comment they see her could make a lightbulb go off is non-zero. But if I were a nihilist I might agree with you.

So write good comments, neutral in tone, avoid preaching, stick to the facts, gently emphasize how laws are being broken without an excess of righteuosness, see the people whose opinions you oppose and find common ground to pivot to your position, etc. When last we crossed you appeared to be lecturing people while incorrectly paraphrasing their actual position (aka strawmanning)( https://news.ycombinator.com/item?id=…

Why should you be the dictator of what tone is appropriate? Particularly when mass murder is involved. Get real.

Re: Notepad++ hijacked by state-sponsored actors

#468

Earlier quoted context omitted.

https://www.tomshardware.com/software/windows/idle-windows-x... But good we are talking about my point rather than than the example.

> YouTuber Eric Parker demonstrated in a recent video how dangerous it is to connect classic Windows operating systems The video referenced in that article explicitly connects directly to the internet, using a VPN to bypass any ISP and router protections and most importantly disables any protections WinXP itself has. So yeah, if you really go out of your way to disable all security protections, you may have a problem…

That’s still the example, not my point.

My point is, statistically, it is more secure to install updates as fast as possible.

We can take another example: search for “shitrix”, there’s thousands more CVEs out there to use as example.

Re: Notepad++ hijacked by state-sponsored actors

#469
post #456

I guess my habit of running a firewall and not allowing programs to access the internet unless they actually need it is helpful for stuff like this. Absolutely no reason a text editor needs internet access. I only update stuff through winget, which fetches the installer from github in a lot of cases, and changing a package requires a PR to the winget repo AFAIK. Not foolproof of course though.

Checking for updates and pulling in plug-ins. Both are valid.

A browser can download updates and plugins to be installed locally. I too do not want all my apps making internet connections. Sandboxes / namespaces can help a little.

Re: Notepad++ hijacked by state-sponsored actors

#470

> Traffic from certain targeted users was selectively redirected to attacker-controlled served malicious update manifests. I'd be curious to know if there was any pattern as to which users were targeted, but the post doesn't go into any further detail except to say it was likely a Chinese state-sponsored group.

My guess would be certain IPs associated with universities, corporations and government institutions.
Post reply on HN