Live data from Hacker News

Notepad++ hijacked by state-sponsored actors

notepad-plus-plus.org

521–530 of 560 posts

Re: Notepad++ hijacked by state-sponsored actors

#521
post #438

Earlier quoted context omitted.

I know it's real. But it doesn't excuse giving away one's values just because something inconvenienced them. As an example, do I find some vegans annoying on the internet? Yes. Does it mean I will instead start supporting carnism, or push back on veganism? No, absolutely not. Because these are values I have, and no actions of others can change what I value.

The fundamental values don’t often change, but if you alienate people enough they will shift their activities to supporting a different cause they care about, or give up and tune out entirely. It’s self-defeating. You can’t win with radicals alone.

> You can’t win with radicals alone.

I'm not saying you can, I'm saying if any radicalism is met with knee-jerk rejection of the cause, then you never really held these values.

Most social progress has been made because of radicalism not in spite of.

Re: Notepad++ hijacked by state-sponsored actors

#522
post #406

Earlier quoted context omitted.

> whenever you engage in your trade or profession is not the same Feels like this is overstating the facts. Afaik, twice did the author on N++ did include a small political message in a release. Is it really "whenever"? Blowing this out of proportions because some are so allergic to any political message that twice in 10 years is being pushy.. In the end, everything involving more than 2 humans is politics. You may w…

Only for the ideologue every interaction must be burdened by partisan politics.

Are you really burdened because the N++ author put a small text inside their software, pertaining to current events?

Re: Notepad++ hijacked by state-sponsored actors

#523
post #479

Earlier quoted context omitted.

LittleSnitch is great for MacOS; it is easily configured to alert you every time your machine makes ip/domain connections, which can then be accepted, denied, or rules made

> LittleSnitch is great for MacOS; it is easily configured to alert you every time your machine makes ip/domain connections, which can then be accepted, denied, or rules made For an open-source alternative, consider checking out - Lulu [0]. It's not as feature rich nor has impressive UI like the former but gets the main work done. [0] https://github.com/objective-see/LuLu

It's not open source, but I can also recommend Vallum[0] as a cheaper alternative to LittleSnitch.

[0] https://www.vallumfirewall.com/

Re: Notepad++ hijacked by state-sponsored actors

#524

I'm extremely wary about any application pushing politics. I subscribe to MacPaw, who makes excellent apps like Setapp, Gemini, and CleanMyMac, all of which I use. At some point, CleanMyMac started putting the Ukranian flag on the app icon and flagging utilities by any Russian developer as untrustworthy (because they are russian), and recommended that I uninstall them. I am not pro russia/anti-ukraine independence by…

> anti-ukraine independence What the fuck is that supposed to mean, lol. Ukraine isn’t done secessionist state. > Seeing them engage in software maccarythism makes me very, very hesitant to provide them. So are they wrong when flagging software or not? You haven’t provided any details.

They flag AdGuard for Safari as suspicious. It's one of the most popular mac apps, if adguard is truly suspicious then it should be bigger news.

Re: Notepad++ hijacked by state-sponsored actors

#525
post #456

I guess my habit of running a firewall and not allowing programs to access the internet unless they actually need it is helpful for stuff like this. Absolutely no reason a text editor needs internet access. I only update stuff through winget, which fetches the installer from github in a lot of cases, and changing a package requires a PR to the winget repo AFAIK. Not foolproof of course though.

Checking for updates and pulling in plug-ins. Both are valid.

> Checking for updates

Why ? CADT ?

Re: Notepad++ hijacked by state-sponsored actors

#526

Earlier quoted context omitted.

Can you name some aspects of society that are non–political? I can't think of many. Maybe the frequency spectrum of sunlight?

please tell me about the intricate politics of a phone booth. just because you can make everything political doesn't mean it is inherently political or doesn't make you look like a terminal online annoying loser when you try to compensate for your vapid personality outside of ideological dogma.

Phone booths are made by the phone company to increase the money they make, that's political. Phone booths are made with more or less shielding implying a greater or lesser danger to their occupant, that's politics. The ones at the airport have glass dividers while the ones at the lonely gas station at night are fully enclosed with thick glass. Different ones have different amounts of graffiti and different likelihood of being vandalised at any given time. You will find this correlates with demographics. Phone booths have disappeared as we all got portable phones in our pockets, but those phones also track us and some people might prefer the relative privacy of an impersonal phone booth, but can't because they no longer exist.

Re: Notepad++ hijacked by state-sponsored actors

#527

Earlier quoted context omitted.

I wouldn't say that avoiding political discussion yourself because you can't handle it is a vote for the status quo, but telling others not to talk about politics is definitely a vote for the status quo.

Doesn't that depend entirely on the context? Telling the grocery store not to carry dairy products is an anti-dairy stance. Objecting to dairy products in the vegetable section is not anti-dairy it's pro-keeping-things-organized. Debating whether or not dairy ought to be allowed in the vegetable section is also not anti-dairy, at least in the general case.

Unlike milk, politics pervades everything. It's not like keeping milk cartons out of the vegetable section, it's like keeping the letter "p" out of the vegetable section.

Re: Notepad++ hijacked by state-sponsored actors

#528
post #499

Earlier quoted context omitted.

The EU is trying but these things have to happen bottom–up. The EU Council or EU Parliament isn't a software development shop. They allocate funds to groups like NLNET who allocate them to a selection of the projects they get proposals for. NLNET can only allocate funds to something an individual or small group proposes. If you want to propose something, please go ahead. Capitalists can also start software businesses…

> NLNET can only allocate funds to something an individual or small group proposes. If you want to propose something, please go ahead. Well, gee, let's look at the sponsorship page for KiCad: https://www.kicad.org/sponsors/sponsors/ I see a couple EU companies, but no EU governments. It takes a paltry $15K to be a Platinum sponsor. I picked KiCad because PCB design is critical military infrastructure, the alternative…

There is an EU initiative to bring in chip manufacturing but it's not related to open source. For sovereignty purposes, airgapped software or locally made software is as good as open source and it's usually higher quality.

There are already alternatives to KiCad for PCBs. And I repeat myself: NLNET can only rule on the proposals it receives. Have you proposed to spend a year improving the KiCad UX?

Re: Notepad++ hijacked by state-sponsored actors

#529
post #456

I guess my habit of running a firewall and not allowing programs to access the internet unless they actually need it is helpful for stuff like this. Absolutely no reason a text editor needs internet access. I only update stuff through winget, which fetches the installer from github in a lot of cases, and changing a package requires a PR to the winget repo AFAIK. Not foolproof of course though.

Which firewall software do you use? I should probably start using firewalls in my computers as well...

It doesn't matter really because nowadays all of them are just a front-ends to Windows Firewall.

Also legitimate software (i.e. firewall/AV) cannot use "oldschool" tricks like system service descriptor table hooks to obtain godlike privileges these days, while malware sometimes can do this by exploiting vulnerabilities, so in such cases it may be an unequal fight.

Re: Notepad++ hijacked by state-sponsored actors

#530
post #493
post #480

Earlier quoted context omitted.

I've been using Fort: https://github.com/tnodir/fort It's the best one I found after trying a few, because it's pretty easy to use, and lets me disable notification popups which is a part that always frustrates me about other options.

Why am I hearing about that specific FW in year 2026, this seems really good, at least the features written if it really supports rules based on parent processes, wildcards, SvcHost granularity without gotchas. Been wrangling with Windows FW for ages, trying to get some badly behaved programs to update like Discord, Teams and others that change install paths or updater executable names or hiddenly use msedgewebview2.…

> A "Core Isolation: Memory Integrity" feature of Windows 10+ prevents creating such memory area (leading to BSOD).

> We tried to attestation sign the driver via new EV certificate by MS to fix the driver's limitation, but failed (see #108).

> So for now users have to disable the "Core Isolation: Memory Integrity" feature

Disabling HVCI doesn't sound like a good idea honestly. I mean they abuse kernel memory protection to bypass EV Certificate restrictions leaving the system in a state where another driver can mess with FW's internal structures using the same trick.

Post reply on HN