Live data from Hacker News

Notepad++ hijacked by state-sponsored actors

notepad-plus-plus.org

51–60 of 560 posts

Re: Notepad++ hijacked by state-sponsored actors

#52

Earlier quoted context omitted.

I can't help but feel there must some better venue for such messaging. When I see politics in software updates or documentation, nothing happens because I'm not looking to use the software for political activism. Maybe I tell my adblocker to remove the messaging, and carry on with my task. I can engage with politics in a social context, when political messaging isn't interrupting something else I'm doing; that's a be…

Similar comments also come up in the [now regular] "I don't want to see political articles on HN" threads, and I think the response is similar: Asking for "no politics" is itself a strong political view: One in support/service of whatever the current status quo is. Trying to set oneself apart from (or above) politics is itself political. If you're lucky enough to be one of the fortunate people on earth who are not un…

I don't care for the current status quo at all. The current administration has wrecked this country and completely compromised its position in the global economy potentially forever. But there is a time and a place for those arguments and activism, as well as the same for other parts of the world suffering from similar or worse issues. Like, I wouldn't be receptive to hearing about Ukraine every time I go to the grocery store. When I want to hear about it I go to the YouTube channels documenting it! They're very interesting, but I need to be in a space to receive it. Similarly there are places where I'm not specifically looking for it but where I'd be receptive because it's not immediately irrelevant to something I'm doing. Otherwise it is just noise. This is absolutely no statement about the status quo, but just how my brain works. It's also not a statement against activism in general, just about my personal opinion of it in certain places.

Re: Notepad++ hijacked by state-sponsored actors

#53

Earlier quoted context omitted.

if you're going to give in and avoid applications because, like in this case they take a strong stance on Ukraine or Taiwan the hack has literally achieved its purpose. Either silence the author directly or destroy its userbase. Fuck'em and just donate ten bucks to notepad++ , I'd rather my pc breaks then reward this crap

I think I made it clear that I use (and pay for) their applications. I also think I made a sufficiently nuanced comment that doesn't suggest that I've "given in" to anything.

I can see where they got that idea from. You saying you won't provide permissions at the end ends up sounding a lot more like you won't use the app than I imagine you intended. (Although, subscribing to an app and then not using it would be silly.)

Re: Notepad++ hijacked by state-sponsored actors

#54

Wow. I'd love to know more how the targeted systems were actually compromised.

There is more detail linked below:

https://www.heise.de/en/news/Notepad-updater-installed-malwa...

https://doublepulsar.com/small-numbers-of-notepad-users-repo...

The TLDR is that until version 8.8.7 of Notepad++, the developer used a self-signed certificate, which was available in the Github source code. The author enabled this by not following best practices.

The "good news" is that the attacks were very targeted and seemed to involve hands on keyboard attacks against folks in Asia.

Blaming the hosting company is kind of shady, as the author should own at least some level of the blame for this.

Re: Notepad++ hijacked by state-sponsored actors

#55
post #4

i always worry about tools like this, maintained by small teams, that are so universal that even if only a small fraction of installs are somehow co-opted by malicious actors, you have a wide open attack surface on most tech companies. e.g. iTerm, Cyberduck, editors of all shades, various VSCode extensions, etc.

I don’t get it, why don’t you all—absolutely all of you reading—use Little Snitch? [1] It really doesn’t compute in my head why would any macOS user not use a network firewall like this, or similar, to block unwanted outgoing HTTP(s) requests. You can easily inspect the packet with tools like Wireshark or Burp Suite Professional (or Community) edition, or any other proxy tool, of which there are many in the macOS eco…

Isn't Little Snitch exactly the sort of application they're worried about?

Re: Notepad++ hijacked by state-sponsored actors

#56
post #4

i always worry about tools like this, maintained by small teams, that are so universal that even if only a small fraction of installs are somehow co-opted by malicious actors, you have a wide open attack surface on most tech companies. e.g. iTerm, Cyberduck, editors of all shades, various VSCode extensions, etc.

I don’t get it, why don’t you all—absolutely all of you reading—use Little Snitch? [1] It really doesn’t compute in my head why would any macOS user not use a network firewall like this, or similar, to block unwanted outgoing HTTP(s) requests. You can easily inspect the packet with tools like Wireshark or Burp Suite Professional (or Community) edition, or any other proxy tool, of which there are many in the macOS eco…

It’s a false sense of security, more or less. If an application wants to talk to a C2 they don’t have to make a connection at all, just proxy a connection through something already allowed, or tunnel through DNS. Those juicy cryptocurrency keys? Pop Safari with them in the URL and they’re sent to the malicious actor instantly. If you’re owned Little Snitch does nothing at all for you except give you the impression that you’re not.

Re: Notepad++ hijacked by state-sponsored actors

#57
post #4

i always worry about tools like this, maintained by small teams, that are so universal that even if only a small fraction of installs are somehow co-opted by malicious actors, you have a wide open attack surface on most tech companies. e.g. iTerm, Cyberduck, editors of all shades, various VSCode extensions, etc.

I don’t get it, why don’t you all—absolutely all of you reading—use Little Snitch? [1] It really doesn’t compute in my head why would any macOS user not use a network firewall like this, or similar, to block unwanted outgoing HTTP(s) requests. You can easily inspect the packet with tools like Wireshark or Burp Suite Professional (or Community) edition, or any other proxy tool, of which there are many in the macOS eco…

It wouldn't protect against this attack though. The Notepad++ update servers were hijacked. Presumably you would allow Notepad++ updates through Little Snitch so you would be equally as vulnerable.

Re: Notepad++ hijacked by state-sponsored actors

#58

Earlier quoted context omitted.

Sorry, what does this have to do with notepad++?

Sorry, I meant to reply to this comment: https://news.ycombinator.com/item?id=46851664 Please refer to it for context.

You should repost under the intended post

Re: Notepad++ hijacked by state-sponsored actors

#59
post #40

Earlier quoted context omitted.

The notepad++ author has publicly come out in favor of Taiwanese independence.

Taiwan is already independent. Surely the normal way to refer to it would be as coming out against assimilation with mainland China?

Before Trump set his sights on Greenland, Denmark also considered Kosovo to be independent.

Re: Notepad++ hijacked by state-sponsored actors

#60
post #40

Earlier quoted context omitted.

The notepad++ author has publicly come out in favor of Taiwanese independence.

Taiwan is already independent. Surely the normal way to refer to it would be as coming out against assimilation with mainland China?

>Taiwan is already independent.

That is a very controversial statement, and one that both Taipei and Beijing disagree with.

Post reply on HN