This all fascinating, but in the end: I have notepad++; what should I do?
Notepad++ hijacked by state-sponsored actors
51–60 of 560 posts
Re: Notepad++ hijacked by state-sponsored actors
#52Earlier quoted context omitted.
I can't help but feel there must some better venue for such messaging. When I see politics in software updates or documentation, nothing happens because I'm not looking to use the software for political activism. Maybe I tell my adblocker to remove the messaging, and carry on with my task. I can engage with politics in a social context, when political messaging isn't interrupting something else I'm doing; that's a be…
Similar comments also come up in the [now regular] "I don't want to see political articles on HN" threads, and I think the response is similar: Asking for "no politics" is itself a strong political view: One in support/service of whatever the current status quo is. Trying to set oneself apart from (or above) politics is itself political. If you're lucky enough to be one of the fortunate people on earth who are not un…
Re: Notepad++ hijacked by state-sponsored actors
#53Earlier quoted context omitted.
if you're going to give in and avoid applications because, like in this case they take a strong stance on Ukraine or Taiwan the hack has literally achieved its purpose. Either silence the author directly or destroy its userbase. Fuck'em and just donate ten bucks to notepad++ , I'd rather my pc breaks then reward this crap
I think I made it clear that I use (and pay for) their applications. I also think I made a sufficiently nuanced comment that doesn't suggest that I've "given in" to anything.
Re: Notepad++ hijacked by state-sponsored actors
#54Wow. I'd love to know more how the targeted systems were actually compromised.
https://www.heise.de/en/news/Notepad-updater-installed-malwa...
https://doublepulsar.com/small-numbers-of-notepad-users-repo...
The TLDR is that until version 8.8.7 of Notepad++, the developer used a self-signed certificate, which was available in the Github source code. The author enabled this by not following best practices.
The "good news" is that the attacks were very targeted and seemed to involve hands on keyboard attacks against folks in Asia.
Blaming the hosting company is kind of shady, as the author should own at least some level of the blame for this.
Re: Notepad++ hijacked by state-sponsored actors
#55i always worry about tools like this, maintained by small teams, that are so universal that even if only a small fraction of installs are somehow co-opted by malicious actors, you have a wide open attack surface on most tech companies. e.g. iTerm, Cyberduck, editors of all shades, various VSCode extensions, etc.
I don’t get it, why don’t you all—absolutely all of you reading—use Little Snitch? [1] It really doesn’t compute in my head why would any macOS user not use a network firewall like this, or similar, to block unwanted outgoing HTTP(s) requests. You can easily inspect the packet with tools like Wireshark or Burp Suite Professional (or Community) edition, or any other proxy tool, of which there are many in the macOS eco…
Re: Notepad++ hijacked by state-sponsored actors
#56i always worry about tools like this, maintained by small teams, that are so universal that even if only a small fraction of installs are somehow co-opted by malicious actors, you have a wide open attack surface on most tech companies. e.g. iTerm, Cyberduck, editors of all shades, various VSCode extensions, etc.
I don’t get it, why don’t you all—absolutely all of you reading—use Little Snitch? [1] It really doesn’t compute in my head why would any macOS user not use a network firewall like this, or similar, to block unwanted outgoing HTTP(s) requests. You can easily inspect the packet with tools like Wireshark or Burp Suite Professional (or Community) edition, or any other proxy tool, of which there are many in the macOS eco…
Re: Notepad++ hijacked by state-sponsored actors
#57i always worry about tools like this, maintained by small teams, that are so universal that even if only a small fraction of installs are somehow co-opted by malicious actors, you have a wide open attack surface on most tech companies. e.g. iTerm, Cyberduck, editors of all shades, various VSCode extensions, etc.
I don’t get it, why don’t you all—absolutely all of you reading—use Little Snitch? [1] It really doesn’t compute in my head why would any macOS user not use a network firewall like this, or similar, to block unwanted outgoing HTTP(s) requests. You can easily inspect the packet with tools like Wireshark or Burp Suite Professional (or Community) edition, or any other proxy tool, of which there are many in the macOS eco…
Re: Notepad++ hijacked by state-sponsored actors
#58Re: Notepad++ hijacked by state-sponsored actors
#59Earlier quoted context omitted.
The notepad++ author has publicly come out in favor of Taiwanese independence.
Taiwan is already independent. Surely the normal way to refer to it would be as coming out against assimilation with mainland China?
Re: Notepad++ hijacked by state-sponsored actors
#60Earlier quoted context omitted.
The notepad++ author has publicly come out in favor of Taiwanese independence.
Taiwan is already independent. Surely the normal way to refer to it would be as coming out against assimilation with mainland China?
That is a very controversial statement, and one that both Taipei and Beijing disagree with.