18 ms·
So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer? Anyway, I hope the au
by edb_123 8mo ago
So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer?
Anyway, I hope the author can be a bit more specific about what actually has happened to those unlucky enough to have received these malicious updates. And perhaps a tool to e.g. do a checksum of all Notepad++ files, and compare them to the ones of a verified clean install of the user's installed version, would be a start? Though I would assume these malicious updates would be clever enough to rather have dropped and executed additional files, rather than doing something with the Notepad++ binaries themselves.
And I agree with another comment here. With all those spelling mistakes that notification kind of reads like it could have been written by a state-sponsored actor. Not to be (too) paranoid here, but can we be sure that this is the actual author, and that the new version isn't the malicious one?
- hinkley 8mo agoThis reminds me of college, when some of my professors were still sorting out their curriculum and would give us homework assignments with bugs in it. I complained many times that they were enabling my innate procrastination by proving over and over again that starting the homework early meant you would get screwed. Every time I'd wait until the people in the forum started sounding optimistic before even looking at the problem statement. I still think I'd like to have a web of trust system where I let my friends try out software updates first before I do, and my relatives let me try them out before they do.
- ozim 8mo agoFor windows updates r/sysadmin has people who run updates and post their experience on patch Tuesday.
- Melatonic 8mo agoYou can delay by a week or two very easily and automatically as well
- Nition 8mo agoAh, I remember those days. One that wasn't an error exactly was an assignment that had a word limit of 2000 words or something. I'd written maybe 3000 words and spent quite some time cutting it down, getting it to just under the limit. Then someone else who also wrote too many words asked the professor if that was okay and they sent out an update to everyone saying it's fine to ignore the word limit.
- nxpnsv 8mo agoSo you accidentally learned how to edit a text? Sounds like a win to me…
- Nition 8mo agoThat's a nice positive way to view it. I would even say that was probably intended as a feature of the original assignment brief.
- whywhywhywhy 8mo agoYou were working within the system of academia, the other student in the system of the real world.
- greazy 8mo agoI work in a lab as an analyst (bioinformatician), we are register and pay for quality assurance programs that contain an embarrassing about of technical errors.
- wiether 8mo ago> an embarrassing about of technical errors amount? ;)
- Gander5739 8mo agoNumber?
- hinkley 8mo agoAutocorrect makes us all sound like jackasses these days. Have some pity.
- greazy 8mo agoHaha I laughed after reading your comment and mine. Yep auto correct got me good.
- skeledrew 8mo ago> let my friends try out software updates first before I do And who do they let try the software before they do? And so on... Where does it ended?
- timbit42 8mo agoThere is always a fresh group of people who haven't learned that lesson yet acting as the guinea pigs.
- hinkley 8mo agoThere's a few months every year when I'm feeling brave or crazy. We could take turns. The thing is that most supply chain attacks are going to hit you when you are least prepared to deal with them, because that's exactly how they get you. When you're distracted. Upgrades are deep work, but the commands to start them feel like shallow work.
- dec0dedab0de 8mo agoThey should have just gave out extra credit for finding bugs.
- QuiEgo 8mo agoI had a professor who did this. One letter grade bump *after curve* applied per assignment per bug found (reproduce case and fix required). Loved that class.
- user3939382 8mo agoIf there’s anything I’ve learned from IBM, Red Hat, and CentOS, it’s that bleeding edge is actually what I’m supposed to want.
- FpUser 8mo ago8.4.7 here. phew
- topspin 8mo ago8.5.7 here (built Sept 6, 2023) Now I need to worry about this one. I've been anxious about vscode lately: apparently vscode extensions are a dumpster fire of compromises.
- FatalLogic 8mo ago>I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer? Notepad++ site says The incident began from June 2025. On their downloads page, 8.8.2 was the first update in June 2025 (the previous update 8.8.1 was released 2025-05-05) So, if your installed version is 8.8.1 or lower, then you should be safe. Assuming that they're right about when the incident began. edit: Notepad++ has published, on Github, SHA256 hashes of all the binaries for all download versions, which should let users check if they were targeted, if they still have the downloaded file. 8.8.1 is here, for example - https://github.com/notepad-plus-plus/notepad-plus-plus/releases/download/v8.8.1/npp.8.8.1.checksums.sha256 https://github.com/notepad-plus-plus/notepad-plus-plus/relea...
- z3t4 8mo agoOlder download links doesn't seem to work!?
- JoystickX02 8mo agoJust checked my 8.7.9 that I installed in April 2025 and never updated. The hash seems to be identical to the version I installed around that time. Seems like it was a good choice to always skip the Update Dialog when using Notepad++ lol.
- otherme123 8mo ago> And perhaps a tool to e.g. do a checksum of all Notepad++ files, and compare them to the ones of a verified clean install of the user's installed version, would be a start? Did I understand the attack wrongly? The software could have a 100% correct checksum, because the attack happened in a remote machine that deals with call home events from Notepad++, I guess one of those "Telemetry" add-ons. The attackers did a MITM to Notepad++ traffic.
- tempestn 8mo agoThe remote machine that was compromised was responsible for Notepad++ updates, so the concern is that it could cause a compromised version of the software to be installed. But if it could do that, it could probably cause anything to be installed anywhere on the user's machine, so inspecting the installed N++ binary probably wouldn't be too useful.
- 7bit 8mo agoChecksums are useless in this case. The binary would have to be signed and the installation routine would have to check that the new binary would have been signed with the certificate. That adds complexity, but would have thwarted this specific attempt. However, there are ways around this, too. No solution is perfect.
- tasuki 8mo ago> So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer? Is this surprising? My model is that keeping with the new versions is generally more dangerous than sticking with an old version, unless that old version has specific known and exploitable vulnerabilities.
- illiac786 8mo agoYes, it is very much atypical. Most hacks happen because admins still haven’t applied a 2 years old patch. I hate updates, but it‘s statistically safer that running an old software version. Try exposing a windows XP to the internet and watch how long it takes before it‘s hacked.
- card_zero 8mo agoDebatable. "I connected Windows XP to the Internet; it was fine" - https://news.ycombinator.com/item?id=40528117 https://news.ycombinator.com/item?id=40528117 One comment there points out that XP is old enough for infected attack vectors to have all died out. I dunno.
- illiac786 8mo agohttps://www.tomshardware.com/software/windows/idle-windows-xp-and-2000-machines-get-infected-with-viruses-within-minutes-of-being-exposed-online https://www.tomshardware.com/software/windows/idle-windows-x... But good we are talking about my point rather than than the example.
- badsectoracula 8mo ago> YouTuber Eric Parker demonstrated in a recent video how dangerous it is to connect classic Windows operating systems The video referenced in that article explicitly connects directly to the internet, using a VPN to bypass any ISP and router protections and most importantly disables any protections WinXP itself has. So yeah, if you really go out of your way to disable all security protections, you may have a problem.
- 1vuio0pswjnm7 8mo ago"So, let me get this straight. If I've been lazy, postponed updates and I'm still on 8.5.8 (Oct 2023) - it turns out I'm actually...safer?" This is true for a large number of software "security" issues A software version earlier in date/time is not necessarily inferior (or superior) to a version later in date/time As it is "updated" or rewritten,, software can become worse instead of better, or vice versa, for a vaariety of reasons Checking software's release date, or enabling/allowing "automatic updates" is not a substitute for reading source code and evaluating software on the merits
- beached_whale 8mo agolol, im on 7.3.x for extra safety
- bulbar 8mo agoI disable auto update for everything that does not have direct contact with the Internet otherwise (mail app, browser, OS, router,...). Probability for some random app being exploited because updates were skipped is insignificant compared to the probability of a malicious update. Updates are a direct connection from the Internet to your computer. You want to minimize that. Just do a manual update from time to time.
- jollyllama 8mo agoYes, of course you're safer. If your system is working as desired, updates can only break it. This is just Engineering 101, but for whatever reason, all logic is abandoned on the topic of security updates.