Live data from Hacker News

Windows Notepad App Remote Code Execution Vulnerability

cve.org

491–500 of 538 posts

Re: Windows Notepad App Remote Code Execution Vulnerability

#491
post #442

Earlier quoted context omitted.

Calculator asks you to rate it in the app store... You're the preinstalled calculator!! You don't have to compete with other apps!!

The desperation for feedback is grating. You have a monopoly position, you know I cannot switch from this, why waste my time with this dialogue? Not like you take user opinions seriously anyway.

Just an act of asking for the opinion matters.

(Maybe not for all, but definitely for some)

https://en.wikipedia.org/wiki/Hawthorne_effect

Re: Windows Notepad App Remote Code Execution Vulnerability

#492

Earlier quoted context omitted.

Just... no... not notepad.. Notepad should be the single-simplest of text editors, always has been, always should be... it should be "safe" much like "task manager" it should be as simple and bulletproof as any application in Windows are... these are essential tools that should never, ever, ever break. MS has WordPad... f ck around with that to make it support markdown or whatever else beyond rtf you want it to suppo…

WordPad was discontinued.

Only three years ago, too. That kinda surprised me.

Re: Windows Notepad App Remote Code Execution Vulnerability

#493
post #230

Earlier quoted context omitted.

Something felt off about your comments, so I checked your account. You signed up almost six years ago, and in all that time made zero submissions and your only comments are these two on this thread? I’ve been seeing this more and more on HN. What exactly is going on here?

Looks like they logged in the first time in years to make a post https://news.ycombinator.com/item?id=46975123 And decided to jump in on some threads just as well.

That post also looks suspiciously like AI slop

Re: Windows Notepad App Remote Code Execution Vulnerability

#494
post #18

Earlier quoted context omitted.

clicking links should not be a security issue and yes the CVE is totally deserved: that's remote code execution.

How is the code execution remote?

It's remote from the attacker point of view. It allows to remote execute the code the attacker provided.

It'd be the same to upload a file to a web server that gets to be run by the said web server, except this time it's done with "notepad.exe"

Re: Windows Notepad App Remote Code Execution Vulnerability

#495
post #395

Earlier quoted context omitted.

Yet 99% of the planet doesn't do "the bare minimum", bro. We have supposedly all the smartest minds in the world working in tech and they haven't been able to create a simple, cheap, reliable cross platform solution for user data protection, backup and restore. It's easier to blame users instead.

The iPad and iPhone say “Hi!” - at least until the EU and other companies get done ruining them.

Yeah, yeah. It's not purely about installing apps. It's primarily about sandboxing them.

I always thought Americans were "nanny state this, nanny state that". Doesn't this also apply to huge state sized corporations mandating a cut of every app sold and forcing everyone to only install apps from them?

Re: Windows Notepad App Remote Code Execution Vulnerability

#496
post #395

Earlier quoted context omitted.

Yet 99% of the planet doesn't do "the bare minimum", bro. We have supposedly all the smartest minds in the world working in tech and they haven't been able to create a simple, cheap, reliable cross platform solution for user data protection, backup and restore. It's easier to blame users instead.

> It's easier to blame users instead. Yes, because the users are in fact the problem. The options are either to trust the user to make decisions (and technically illiterate users will screw things up for themselves), or lock down the system so that the user isn't allowed to do anything the corporate overlord doesn't let them. There is no middle ground.

There is one where desktops are slowly being remade, which Windows and MacOS are failing at. Have application repositories, but open ones like Debian or Linux in general, so that application developers can publish and don't ask for a cut of every sale. Sandbox all new desktop applications over the years and publish long roadmaps until everything is sandboxed, say, in 2035.

Provide more education and guidance for users and more corporate controls.

If they would have really started to do this in 2005, we would have been there by now. Instead we get more UI toolkits and more UI refreshes and AI everywhere.

Re: Windows Notepad App Remote Code Execution Vulnerability

#497
post #454

Earlier quoted context omitted.

I’d wish to use Linux. But some things just don’t run there (properly). Like Assetto Corsa EVO or SimHub.

When was the last time you tried it? Assetto Corsa EVO has a Gold rating on ProtonDB[1] and apparently SimHub also works fine, according to the SimHub forums[2]. [1] https://www.protondb.com/app/3058630 [2] https://www.simhubdash.com/community-2/simhub-support/guide-...

Yes, I know that they might work just fine on Linux.

But… ACC EVO is alpha at the moment. It barely runs without bugs on Windows. It’s just less hassle on Windows.

Re: Windows Notepad App Remote Code Execution Vulnerability

#498
post #277

Earlier quoted context omitted.

As funny as the "Bush hid the facts" bug may be, there is a world of difference between an embarassing mistake by a function that guesses the text encoding wrong, and a goddamn remote code execution with an 8.8 score > and we have other battles we fight. Except no, we don't. notepad.exe was DONE SOFTWARE. It was feature complete. It didn't have to change. This is not a battle that needed fighting, this was hitting a…

> Except no, we don't. notepad.exe was DONE SOFTWARE While 8.8 score is embarrassing, by no measure notepad was done software. It couldn't load a large text file for one, its search was barely functional, had funky issues with encoding, etc. Notepad++ is closer to what should be expected from an OS basic text editor

> t couldn't load a large text file for one, its search was barely functional, had funky issues with encoding, etc.

It was working according to the spec. Which is very unusual in the SW world.

Re: Windows Notepad App Remote Code Execution Vulnerability

#499
post #197

Earlier quoted context omitted.

The very fact that UTF-8 itself discouraged from using the BOM is just so alien to me. I understand they want it to be the last encoding and therefore not in need of a explicit indicator, but as it currently IS NOT the only encoding that is used, it makes is just so difficult to understand if I'm reading any of the weird ASCII derivatives or actual Unicode. It's maddening and it's frustrating. The US doesn't have any…

> The US doesn't have any of these issues I think you mean “the US chooses to completely ignore these issues and gets away with it because they defined the basic standard that is used, ASCII, way-back-when, and didn't foresee it becoming an international thing so didn't think about anyone else” :)

> because they defined the basic standard that is used, ASCII

I thought it was EBCDIC /s

Re: Windows Notepad App Remote Code Execution Vulnerability

#500

Earlier quoted context omitted.

That is completely valid for personal threat models, I rely on LUKS/BitLocker for my daily driver too. The specific gap this fills is 'Defense in Depth' + compliance. OS-level encryption (like FDE) is transparent once you log in. If you walk away from an unlocked machine, FDE does nothing. App-level encryption, however, ensures the specific sensitive notes remain encrypted on disk even while the OS is running and the…

> If you walk away from an unlocked machine ...then I might as well ask what happens when I walk away from the encrypting edior while a file is still open. User Error can happen with any encryption or security schema. Pointing out a trueism is not an argument. > It's also portable So is encrypting files using a specialized tool. I don't need my editor to do this. The entire point of my criticism, and indeed the entir…

> software that should focus on a narrow task, tries to do way too much, leading to problems.

"Problems ? No problems. Profit."

Regards (insert your favourite 3 letter agency or exploit sellers here)

Post reply on HN