Live data from Hacker News

Notepad++ hijacked by state-sponsored actors

notepad-plus-plus.org

71–80 of 560 posts

Re: Notepad++ hijacked by state-sponsored actors

#71
post #41

Notably Notepad++ was recently shipping unsigned/self-signed updates, apparently overlapping with the time of this incident, see releases 8.8.2-8.8.6: https://notepad-plus-plus.org/news/

So they just conveniently decided not to sign their releases right around the time they were supposedly "hacked"? Something doesn't seem right here.

Code signing certs are unfortunately expensive

Re: Notepad++ hijacked by state-sponsored actors

#72

Earlier quoted context omitted.

Yeah, Notepad++ is known for political messaging in their updates. Taiwan, Ukraine, etc.

I can't help but feel there must some better venue for such messaging. When I see politics in software updates or documentation, nothing happens because I'm not looking to use the software for political activism. Maybe I tell my adblocker to remove the messaging, and carry on with my task. I can engage with politics in a social context, when political messaging isn't interrupting something else I'm doing; that's a be…

There's generally a better venue for a lot of messaging, but I don't get a vote in it.

Re: Notepad++ hijacked by state-sponsored actors

#74
post #56

Earlier quoted context omitted.

I don’t get it, why don’t you all—absolutely all of you reading—use Little Snitch? [1] It really doesn’t compute in my head why would any macOS user not use a network firewall like this, or similar, to block unwanted outgoing HTTP(s) requests. You can easily inspect the packet with tools like Wireshark or Burp Suite Professional (or Community) edition, or any other proxy tool, of which there are many in the macOS eco…

It’s a false sense of security, more or less. If an application wants to talk to a C2 they don’t have to make a connection at all, just proxy a connection through something already allowed, or tunnel through DNS. Those juicy cryptocurrency keys? Pop Safari with them in the URL and they’re sent to the malicious actor instantly. If you’re owned Little Snitch does nothing at all for you except give you the impression th…

I find it difficult to believe that there is levels of cooperation between different companies that would allow this to work.

Source. I work for a company for longer than the internet has been alive.

Re: Notepad++ hijacked by state-sponsored actors

#75

Earlier quoted context omitted.

It wouldn't protect against this attack though. The Notepad++ update servers were hijacked. Presumably you would allow Notepad++ updates through Little Snitch so you would be equally as vulnerable.

No, why would you allow automatic updates? It makes no sense. You should audit every update as if each payload could contain malware. It’s a paranoid way to live, but that’s what it takes. We also need better computer science education in high schools, teaching students how to inspect network packets, verify SSL certificates, and evaluate whether a binary blob might contain malicious code. People have gotten complace…

Do you go by the smell of the executable or just general vibes? Nobody has never reviewed even a tiny fraction of the software they run, closed source or open source.

Re: Notepad++ hijacked by state-sponsored actors

#76

Earlier quoted context omitted.

Similar comments also come up in the [now regular] "I don't want to see political articles on HN" threads, and I think the response is similar: Asking for "no politics" is itself a strong political view: One in support/service of whatever the current status quo is. Trying to set oneself apart from (or above) politics is itself political. If you're lucky enough to be one of the fortunate people on earth who are not un…

I don't care for the current status quo at all. The current administration has wrecked this country and completely compromised its position in the global economy potentially forever. But there is a time and a place for those arguments and activism, as well as the same for other parts of the world suffering from similar or worse issues. Like, I wouldn't be receptive to hearing about Ukraine every time I go to the groc…

> Otherwise it is just noise. This is absolutely no statement about the status quo, but just how my brain works. It's also not a statement against activism in general, just about my personal opinion of it in certain places.

I considered the majority of the population to be affected by repeated messaging, messages in the background, or in other words availability bias. So the messaging be having the desired effect on society in general but not on some subset who filter it out completely.

Re: Notepad++ hijacked by state-sponsored actors

#77
post #40

Earlier quoted context omitted.

The notepad++ author has publicly come out in favor of Taiwanese independence.

Taiwan is already independent. Surely the normal way to refer to it would be as coming out against assimilation with mainland China?

The official position of Taiwan (Republic of China) and the People's Republic of China is that they're rival governments of the same China.

The Taiwanese government has never formally declared itself independent from the mainland. Such a declaration would likely cause the PRC to invade.

https://en.wikipedia.org/wiki/1992_Consensus

Re: Notepad++ hijacked by state-sponsored actors

#78
post #56

Earlier quoted context omitted.

It’s a false sense of security, more or less. If an application wants to talk to a C2 they don’t have to make a connection at all, just proxy a connection through something already allowed, or tunnel through DNS. Those juicy cryptocurrency keys? Pop Safari with them in the URL and they’re sent to the malicious actor instantly. If you’re owned Little Snitch does nothing at all for you except give you the impression th…

I find it difficult to believe that there is levels of cooperation between different companies that would allow this to work. Source. I work for a company for longer than the internet has been alive.

My example is “living off the land”, safari already has access to everything, open it and use it to communicate. Needs no permissions, bypasses little snitch entirely.

Re: Notepad++ hijacked by state-sponsored actors

#80
post #56

Earlier quoted context omitted.

I don’t get it, why don’t you all—absolutely all of you reading—use Little Snitch? [1] It really doesn’t compute in my head why would any macOS user not use a network firewall like this, or similar, to block unwanted outgoing HTTP(s) requests. You can easily inspect the packet with tools like Wireshark or Burp Suite Professional (or Community) edition, or any other proxy tool, of which there are many in the macOS eco…

It’s a false sense of security, more or less. If an application wants to talk to a C2 they don’t have to make a connection at all, just proxy a connection through something already allowed, or tunnel through DNS. Those juicy cryptocurrency keys? Pop Safari with them in the URL and they’re sent to the malicious actor instantly. If you’re owned Little Snitch does nothing at all for you except give you the impression th…

[deleted]
Post reply on HN