Notably Notepad++ was recently shipping unsigned/self-signed updates, apparently overlapping with the time of this incident, see releases 8.8.2-8.8.6: https://notepad-plus-plus.org/news/
So they just conveniently decided not to sign their releases right around the time they were supposedly "hacked"? Something doesn't seem right here.
Notepad++ hijacked by state-sponsored actors
71–80 of 560 posts
Re: Notepad++ hijacked by state-sponsored actors
#72Earlier quoted context omitted.
Yeah, Notepad++ is known for political messaging in their updates. Taiwan, Ukraine, etc.
I can't help but feel there must some better venue for such messaging. When I see politics in software updates or documentation, nothing happens because I'm not looking to use the software for political activism. Maybe I tell my adblocker to remove the messaging, and carry on with my task. I can engage with politics in a social context, when political messaging isn't interrupting something else I'm doing; that's a be…
Re: Notepad++ hijacked by state-sponsored actors
#73Re: Notepad++ hijacked by state-sponsored actors
#74Earlier quoted context omitted.
I don’t get it, why don’t you all—absolutely all of you reading—use Little Snitch? [1] It really doesn’t compute in my head why would any macOS user not use a network firewall like this, or similar, to block unwanted outgoing HTTP(s) requests. You can easily inspect the packet with tools like Wireshark or Burp Suite Professional (or Community) edition, or any other proxy tool, of which there are many in the macOS eco…
It’s a false sense of security, more or less. If an application wants to talk to a C2 they don’t have to make a connection at all, just proxy a connection through something already allowed, or tunnel through DNS. Those juicy cryptocurrency keys? Pop Safari with them in the URL and they’re sent to the malicious actor instantly. If you’re owned Little Snitch does nothing at all for you except give you the impression th…
Source. I work for a company for longer than the internet has been alive.
Re: Notepad++ hijacked by state-sponsored actors
#75Earlier quoted context omitted.
It wouldn't protect against this attack though. The Notepad++ update servers were hijacked. Presumably you would allow Notepad++ updates through Little Snitch so you would be equally as vulnerable.
No, why would you allow automatic updates? It makes no sense. You should audit every update as if each payload could contain malware. It’s a paranoid way to live, but that’s what it takes. We also need better computer science education in high schools, teaching students how to inspect network packets, verify SSL certificates, and evaluate whether a binary blob might contain malicious code. People have gotten complace…
Re: Notepad++ hijacked by state-sponsored actors
#76Earlier quoted context omitted.
Similar comments also come up in the [now regular] "I don't want to see political articles on HN" threads, and I think the response is similar: Asking for "no politics" is itself a strong political view: One in support/service of whatever the current status quo is. Trying to set oneself apart from (or above) politics is itself political. If you're lucky enough to be one of the fortunate people on earth who are not un…
I don't care for the current status quo at all. The current administration has wrecked this country and completely compromised its position in the global economy potentially forever. But there is a time and a place for those arguments and activism, as well as the same for other parts of the world suffering from similar or worse issues. Like, I wouldn't be receptive to hearing about Ukraine every time I go to the groc…
I considered the majority of the population to be affected by repeated messaging, messages in the background, or in other words availability bias. So the messaging be having the desired effect on society in general but not on some subset who filter it out completely.
Re: Notepad++ hijacked by state-sponsored actors
#77Earlier quoted context omitted.
The notepad++ author has publicly come out in favor of Taiwanese independence.
Taiwan is already independent. Surely the normal way to refer to it would be as coming out against assimilation with mainland China?
The Taiwanese government has never formally declared itself independent from the mainland. Such a declaration would likely cause the PRC to invade.
Re: Notepad++ hijacked by state-sponsored actors
#78Earlier quoted context omitted.
It’s a false sense of security, more or less. If an application wants to talk to a C2 they don’t have to make a connection at all, just proxy a connection through something already allowed, or tunnel through DNS. Those juicy cryptocurrency keys? Pop Safari with them in the URL and they’re sent to the malicious actor instantly. If you’re owned Little Snitch does nothing at all for you except give you the impression th…
I find it difficult to believe that there is levels of cooperation between different companies that would allow this to work. Source. I work for a company for longer than the internet has been alive.
Re: Notepad++ hijacked by state-sponsored actors
#79[flagged]
Re: Notepad++ hijacked by state-sponsored actors
#80Earlier quoted context omitted.
I don’t get it, why don’t you all—absolutely all of you reading—use Little Snitch? [1] It really doesn’t compute in my head why would any macOS user not use a network firewall like this, or similar, to block unwanted outgoing HTTP(s) requests. You can easily inspect the packet with tools like Wireshark or Burp Suite Professional (or Community) edition, or any other proxy tool, of which there are many in the macOS eco…
It’s a false sense of security, more or less. If an application wants to talk to a C2 they don’t have to make a connection at all, just proxy a connection through something already allowed, or tunnel through DNS. Those juicy cryptocurrency keys? Pop Safari with them in the URL and they’re sent to the malicious actor instantly. If you’re owned Little Snitch does nothing at all for you except give you the impression th…