First I thought CVE-2012-3587 was incompetence... but then seeing CVE-2012-0954 after it, I couldn't help think something more was at bay as something connected to a nation state. It does not surprise me in the least to see nation state attackers exploiting N++. Because I've also on very sensitive enterprise PAM systems in F500/research/academia, and about 10% of the time it felt like I'd see Notepad++ on internet-connected systems used for security tooling because vanilla notepad is indeed garbage. It does not surprise me at all this has been used as an attack vector.
Notepad++ hijacked by state-sponsored actors
511–520 of 560 posts
Re: Notepad++ hijacked by state-sponsored actors
#512I guess my habit of running a firewall and not allowing programs to access the internet unless they actually need it is helpful for stuff like this. Absolutely no reason a text editor needs internet access. I only update stuff through winget, which fetches the installer from github in a lot of cases, and changing a package requires a PR to the winget repo AFAIK. Not foolproof of course though.
Checking for updates and pulling in plug-ins. Both are valid.
Re: Notepad++ hijacked by state-sponsored actors
#513Earlier quoted context omitted.
> So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer? Is this surprising? My model is that keeping with the new versions is generally more dangerous than sticking with an old version, unless that old version has specific known and exploitable vulnerabilities.
Yes, it is very much atypical. Most hacks happen because admins still haven’t applied a 2 years old patch. I hate updates, but it‘s statistically safer that running an old software version. Try exposing a windows XP to the internet and watch how long it takes before it‘s hacked.
Re: Notepad++ hijacked by state-sponsored actors
#514Earlier quoted context omitted.
Yes, it is very much atypical. Most hacks happen because admins still haven’t applied a 2 years old patch. I hate updates, but it‘s statistically safer that running an old software version. Try exposing a windows XP to the internet and watch how long it takes before it‘s hacked.
You assume that the old software version has critical vulnerabilities. If it does not, then yes, updating is more of a risk since the new versions are unknowns.
Re: Notepad++ hijacked by state-sponsored actors
#515Earlier quoted context omitted.
What a bad take. Not every political statement is morally equivalent nor worthy of the same respect. Supporting self-determination of people is not the same as supporting oppression of people - for example. So the free expression is considered by everyone according to their own ethical and moral values.
I'm not sure you realize but you're agreeing with my statement. So it's a bit odd that you call it a bad take.
Re: Notepad++ hijacked by state-sponsored actors
#516That's sad. China should be more helpful with regards to open source. Notepad++ is a great editor. I don't use it on Linux, because I have an older editor I am very used to, but on Windows I like notepad++ a lot (though lately I have been using geany on Windows, mostly for convenience - I think notepad++ is better but I sort of like the github-based development of geany; either way notepad++ is really excellent as we…
> That's sad. China should be more helpful with regards to open source. They should also be more helpful with not plundering the oceans, even including the territorial waters of far-flung nations, of fish.
Re: Notepad++ hijacked by state-sponsored actors
#517Earlier quoted context omitted.
Zing! The state of the world is such that I have started running everything inside VMs. Baseline OS install + virtual machine management and that is it. Which is still not immune, but makes me feel a lot better than core OS utilities are probably getting better vetting than nifty-utility-123 on which I depend.
Qubes OS?
Re: Notepad++ hijacked by state-sponsored actors
#518> With these changes and reinforcements, I believe the situation has been fully resolved. Fingers crossed. I get that this is a difficult situation for a small developer, but ending with this line did not fill me with confidence that the problem is actually resolved and make me trust their software on my system.
Re: Notepad++ hijacked by state-sponsored actors
#519I guess my habit of running a firewall and not allowing programs to access the internet unless they actually need it is helpful for stuff like this. Absolutely no reason a text editor needs internet access. I only update stuff through winget, which fetches the installer from github in a lot of cases, and changing a package requires a PR to the winget repo AFAIK. Not foolproof of course though.
LittleSnitch is great for MacOS; it is easily configured to alert you every time your machine makes ip/domain connections, which can then be accepted, denied, or rules made
https://www.binisoft.org/wfc.php
It has some areas where improvement is needed, but the fundamentals work and the user interface design is decent.
I am surprised it's not more popular for Windows users. All of the alternatives I've tried have critical issues which made me dismiss them as unserious.
Re: Notepad++ hijacked by state-sponsored actors
#520Earlier quoted context omitted.
A huge chunk of activism is pointless and annoying. Especially when every cause is lumped together into Activism (TM) and the Omnicause. I don’t agree with them and I don’t think they should be in my software, or dealing with anything they don’t understand (for instance crime, homeless people, geopolitics, or really anything outside of overpriced vegan coffee shops). All they really do is end up getting Fox News peop…
> A huge chunk of activism is pointless and annoying. Activism can be annoying, but it's never pointless (not even when it fails to be effective). > All they really do is end up getting Fox News people to vote for fascists like Trump out of spite It wouldn't be worthwhile for activists to resign themselves to inaction out of fear of offending the "Fox news people". "Fox news people" are already more likely than not t…