Live data from Hacker News

Notepad++ hijacked by state-sponsored actors

notepad-plus-plus.org

511–520 of 560 posts

Re: Notepad++ hijacked by state-sponsored actors

#511
Long ago, Canonical did some shady stuff with the now-deprecated apt-key "net-update" signing validation for updating of GnuPG keys over the network, an exclusive Ubuntu "feature" Debian didn't even adopt that in theory allowed the same thing.

First I thought CVE-2012-3587 was incompetence... but then seeing CVE-2012-0954 after it, I couldn't help think something more was at bay as something connected to a nation state. It does not surprise me in the least to see nation state attackers exploiting N++. Because I've also on very sensitive enterprise PAM systems in F500/research/academia, and about 10% of the time it felt like I'd see Notepad++ on internet-connected systems used for security tooling because vanilla notepad is indeed garbage. It does not surprise me at all this has been used as an attack vector.

Re: Notepad++ hijacked by state-sponsored actors

#512
post #456

I guess my habit of running a firewall and not allowing programs to access the internet unless they actually need it is helpful for stuff like this. Absolutely no reason a text editor needs internet access. I only update stuff through winget, which fetches the installer from github in a lot of cases, and changing a package requires a PR to the winget repo AFAIK. Not foolproof of course though.

Checking for updates and pulling in plug-ins. Both are valid.

As for updates - my OS has a built-in package management system, which is responsible for installing and updating packages. Why should notepad++ bypass that and do its own independent update process?

Re: Notepad++ hijacked by state-sponsored actors

#513
post #331

Earlier quoted context omitted.

> So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer? Is this surprising? My model is that keeping with the new versions is generally more dangerous than sticking with an old version, unless that old version has specific known and exploitable vulnerabilities.

Yes, it is very much atypical. Most hacks happen because admins still haven’t applied a 2 years old patch. I hate updates, but it‘s statistically safer that running an old software version. Try exposing a windows XP to the internet and watch how long it takes before it‘s hacked.

You assume that the old software version has critical vulnerabilities. If it does not, then yes, updating is more of a risk since the new versions are unknowns.

Re: Notepad++ hijacked by state-sponsored actors

#514

Earlier quoted context omitted.

Yes, it is very much atypical. Most hacks happen because admins still haven’t applied a 2 years old patch. I hate updates, but it‘s statistically safer that running an old software version. Try exposing a windows XP to the internet and watch how long it takes before it‘s hacked.

You assume that the old software version has critical vulnerabilities. If it does not, then yes, updating is more of a risk since the new versions are unknowns.

My assumption is statistical. All software has critical vulnerabilities, not just the old ones. It’s just that these vulnerabilities are known, in the case of the old ones, which significantly increases the risk.

Re: Notepad++ hijacked by state-sponsored actors

#515

Earlier quoted context omitted.

What a bad take. Not every political statement is morally equivalent nor worthy of the same respect. Supporting self-determination of people is not the same as supporting oppression of people - for example. So the free expression is considered by everyone according to their own ethical and moral values.

I'm not sure you realize but you're agreeing with my statement. So it's a bit odd that you call it a bad take.

Then the 2 of you probably just disagree on what constitutes socially acceptable free expression.

Re: Notepad++ hijacked by state-sponsored actors

#516
post #508

That's sad. China should be more helpful with regards to open source. Notepad++ is a great editor. I don't use it on Linux, because I have an older editor I am very used to, but on Windows I like notepad++ a lot (though lately I have been using geany on Windows, mostly for convenience - I think notepad++ is better but I sort of like the github-based development of geany; either way notepad++ is really excellent as we…

> That's sad. China should be more helpful with regards to open source. They should also be more helpful with not plundering the oceans, even including the territorial waters of far-flung nations, of fish.

Why the downvotes? I guess I should hope the CCP doesn't hijack this account the way they did Notepad++.

Re: Notepad++ hijacked by state-sponsored actors

#517

Earlier quoted context omitted.

Zing! The state of the world is such that I have started running everything inside VMs. Baseline OS install + virtual machine management and that is it. Which is still not immune, but makes me feel a lot better than core OS utilities are probably getting better vetting than nifty-utility-123 on which I depend.

Qubes OS?

No, poor man's Qubes with manually assembled VMs. I keep meaning to take the plunge, but have been too lazy to rebuild my system.

Re: Notepad++ hijacked by state-sponsored actors

#518

> With these changes and reinforcements, I believe the situation has been fully resolved. Fingers crossed. I get that this is a difficult situation for a small developer, but ending with this line did not fill me with confidence that the problem is actually resolved and make me trust their software on my system.

Same here. I think I will probably look at some alternative to Notepad++.

Re: Notepad++ hijacked by state-sponsored actors

#519
post #456

I guess my habit of running a firewall and not allowing programs to access the internet unless they actually need it is helpful for stuff like this. Absolutely no reason a text editor needs internet access. I only update stuff through winget, which fetches the installer from github in a lot of cases, and changing a package requires a PR to the winget repo AFAIK. Not foolproof of course though.

LittleSnitch is great for MacOS; it is easily configured to alert you every time your machine makes ip/domain connections, which can then be accepted, denied, or rules made

Binisoft WFC for Windows is a free outbound firewall. It was acquired by MalwareBytes awhile back, but they have not interfered with development so far.

https://www.binisoft.org/wfc.php

It has some areas where improvement is needed, but the fundamentals work and the user interface design is decent.

I am surprised it's not more popular for Windows users. All of the alternatives I've tried have critical issues which made me dismiss them as unserious.

Re: Notepad++ hijacked by state-sponsored actors

#520

Earlier quoted context omitted.

A huge chunk of activism is pointless and annoying. Especially when every cause is lumped together into Activism (TM) and the Omnicause. I don’t agree with them and I don’t think they should be in my software, or dealing with anything they don’t understand (for instance crime, homeless people, geopolitics, or really anything outside of overpriced vegan coffee shops). All they really do is end up getting Fox News peop…

> A huge chunk of activism is pointless and annoying. Activism can be annoying, but it's never pointless (not even when it fails to be effective). > All they really do is end up getting Fox News people to vote for fascists like Trump out of spite It wouldn't be worthwhile for activists to resign themselves to inaction out of fear of offending the "Fox news people". "Fox news people" are already more likely than not t…

I don't think this is really true if you look at the results of the last election. Activism just on the transgender issue alone looks to have swung a lot of votes.
Post reply on HN