5 ms·
Notably Notepad++ was recently shipping unsigned/self-signed updates, apparently overlapping with the time of this incident, see releases 8.8.2-8.8.6: https://n
by tech234a 8mo ago
Notably Notepad++ was recently shipping unsigned/self-signed updates, apparently overlapping with the time of this incident, see releases 8.8.2-8.8.6: https://notepad-plus-plus.org/news/ https://notepad-plus-plus.org/news/
- bakugo 8mo agoSo they just conveniently decided not to sign their releases right around the time they were supposedly "hacked"? Something doesn't seem right here.
- adzm 8mo agoCode signing certs are unfortunately expensive
- firesteelrain 8mo ago$700+ at Sectigo for two years Something of Notepad++ size might think about it now
- abeyer 8mo ago"of Notepad++ size" is basically one guy in his free time, no?
- eviks 8mo ago"But look at those downloads, they magically print money"
- firesteelrain 8mo agoNotepad++ is Windows-based and could use the Windows store instead of the built in updater. Microsoft charges a one time fee. It would pass SmartScreen checks. His website has a bunch of ads integrated which I assume are there to help pay for hosting. Mr. Ho already has hosting charges and he uses GitHub. For those who use GitHub, he could continue his GnuPG method for signing. Additionally, GitHub integrates with Sigstore. Windows wouldn’t trust his signature but at least there would be better traceability. Version 8.8.7 labeled “authenticity guaranteed” is a step in that direction. The real “issue” here was his outside hosting platform for updates from my reading of the article.
- hjoutfbkfd 8mo agothe issue was not the money, but that it was difficult to get a certificate without having some sort of legal entity
- firesteelrain 8mo agoCertum.eu has this figured out. https://support.certum.eu/en/code-signing-required-documents/ https://support.certum.eu/en/code-signing-required-documents... https://shop.certum.eu/open-source-code-signing-on-simplysign.html https://shop.certum.eu/open-source-code-signing-on-simplysig... $49 (EU) Gross
- _zagj 8mo agoDelaware LLCs are "cheap," but you're still looking at $300-500 a year in fees.
- Chaosvex 8mo agoIt was negligence. You don't need a certificate to prevent update tampering.
- 1una 8mo ago$0 at SignPath. Quite a few OSS projects use it.
- Chaosvex 8mo agoYou don't even need a certificate to prevent update tampering like this. The updates could have shipped with an ECDSA signature and this wouldn't have happened. It's also free and doable in an afternoon.
- sbohacek 8mo agoThe lack of signing and/or checking the signature when updating is the real issue here. But the write up blames the attack on the hosting server. That doesn't bode well for future security.