Live data from Hacker News

Notepad++ hijacked by state-sponsored actors

notepad-plus-plus.org

61–70 of 560 posts

Re: Notepad++ hijacked by state-sponsored actors

#61
post #16

This all fascinating, but in the end: I have notepad++; what should I do?

Gedit is an underrated alternative imo.

I don't know why that comment is being interpreted as a request for alternatives. They are clearly asking if their machine is compromised.

Re: Notepad++ hijacked by state-sponsored actors

#64

Earlier quoted context omitted.

I can't help but feel there must some better venue for such messaging. When I see politics in software updates or documentation, nothing happens because I'm not looking to use the software for political activism. Maybe I tell my adblocker to remove the messaging, and carry on with my task. I can engage with politics in a social context, when political messaging isn't interrupting something else I'm doing; that's a be…

Similar comments also come up in the [now regular] "I don't want to see political articles on HN" threads, and I think the response is similar: Asking for "no politics" is itself a strong political view: One in support/service of whatever the current status quo is. Trying to set oneself apart from (or above) politics is itself political. If you're lucky enough to be one of the fortunate people on earth who are not un…

i dont see how saying "no politics" is similar to asking "why is there political messaging literally everywhere" , do you see how conflating the two is the exact behaviour that the original commenter was trying to discuss ?

Re: Notepad++ hijacked by state-sponsored actors

#65

Wow. I'd love to know more how the targeted systems were actually compromised.

There is more detail linked below: https://www.heise.de/en/news/Notepad-updater-installed-malwa... https://doublepulsar.com/small-numbers-of-notepad-users-repo... The TLDR is that until version 8.8.7 of Notepad++, the developer used a self-signed certificate, which was available in the Github source code. The author enabled this by not following best practices. The "good news" is that the attacks were very targeted a…

out of curiosity, why is a self signed cert bad for this case? Can't the updater check the validity of the cert just as well regardless? Or did the attackers get access to the signing key as well?

Re: Notepad++ hijacked by state-sponsored actors

#66

Earlier quoted context omitted.

It's not a matter of "immune" - larger organizations generally have more resources to allocate to things like this. That doesn't mean they get it right 100% of the time, but they are at least able to try, while small teams or volunteer projects often simply don't have the hours to spend on things like this.

[flagged]

Hum... We keep pretending the Solar Winds scandal never happened?

Re: Notepad++ hijacked by state-sponsored actors

#67

Earlier quoted context omitted.

I can't help but feel there must some better venue for such messaging. When I see politics in software updates or documentation, nothing happens because I'm not looking to use the software for political activism. Maybe I tell my adblocker to remove the messaging, and carry on with my task. I can engage with politics in a social context, when political messaging isn't interrupting something else I'm doing; that's a be…

Similar comments also come up in the [now regular] "I don't want to see political articles on HN" threads, and I think the response is similar: Asking for "no politics" is itself a strong political view: One in support/service of whatever the current status quo is. Trying to set oneself apart from (or above) politics is itself political. If you're lucky enough to be one of the fortunate people on earth who are not un…

Sometimes when the politics deeply affects you, you just need a little break from it.

Re: Notepad++ hijacked by state-sponsored actors

#68

Earlier quoted context omitted.

I don’t get it, why don’t you all—absolutely all of you reading—use Little Snitch? [1] It really doesn’t compute in my head why would any macOS user not use a network firewall like this, or similar, to block unwanted outgoing HTTP(s) requests. You can easily inspect the packet with tools like Wireshark or Burp Suite Professional (or Community) edition, or any other proxy tool, of which there are many in the macOS eco…

It wouldn't protect against this attack though. The Notepad++ update servers were hijacked. Presumably you would allow Notepad++ updates through Little Snitch so you would be equally as vulnerable.

No, why would you allow automatic updates? It makes no sense. You should audit every update as if each payload could contain malware. It’s a paranoid way to live, but that’s what it takes.

We also need better computer science education in high schools, teaching students how to inspect network packets, verify SSL certificates, and evaluate whether a binary blob might contain malicious code.

People have gotten complacent about the internet, which is why they still get hacked, when it should be the other way around. With everything we’ve learned over the years, why are breaches more common than ever? I don’t understand why people are so careless about online security today, compared to decades ago when we were taught not to share personal information and not to trust anything on the internet.

Re: Notepad++ hijacked by state-sponsored actors

#69

Earlier quoted context omitted.

Similar comments also come up in the [now regular] "I don't want to see political articles on HN" threads, and I think the response is similar: Asking for "no politics" is itself a strong political view: One in support/service of whatever the current status quo is. Trying to set oneself apart from (or above) politics is itself political. If you're lucky enough to be one of the fortunate people on earth who are not un…

I don't care for the current status quo at all. The current administration has wrecked this country and completely compromised its position in the global economy potentially forever. But there is a time and a place for those arguments and activism, as well as the same for other parts of the world suffering from similar or worse issues. Like, I wouldn't be receptive to hearing about Ukraine every time I go to the groc…

I want to start by saying it's good that you are at least taking the time to look for this information! Stay healthily informed.

I see this as a bad analogy though: you wouldn't hear about it every time you go to the grocery store. Or, at the very least, you wouldn't stop and listen for the fifth time. You already know, and that's the point: the intention of most activism in technology (at least that I see) is to make you initially aware of it so you start to seek the information out and learn more elsewhere. (...And to give themselves good PR. We love rainbow capitalism /s)

Instagram and Twitter both get your attention during election season because they want you to be informed about how to vote. To me, that's a similar thing.

Re: Notepad++ hijacked by state-sponsored actors

#70
> Traffic from certain targeted users was selectively redirected to attacker-controlled served malicious update manifests.

I'd be curious to know if there was any pattern as to which users were targeted, but the post doesn't go into any further detail except to say it was likely a Chinese state-sponsored group.

Post reply on HN