this post was submitted on 23 Apr 2024
153 points (100.0% liked)

technology

23308 readers
218 users here now

On the road to fully automated luxury gay space communism.

Spreading Linux propaganda since 2020

Rules:

founded 4 years ago
MODERATORS
 
(page 2) 25 comments
sorted by: hot top controversial new old
[–] CarbonScored@hexbear.net 12 points 6 months ago* (last edited 6 months ago) (1 children)

This is missing the event from a few years back where Notepad++ was revealed on Wikileaks as being vulnerable to CIA spyware built into its libraries (supposedly since patched out).

~~Weirdly, I see notepad++ since deleted their blog post about it.~~ Blog here, they changed their URL formats. Relevant partial copy here

[–] RyanGosling@hexbear.net 6 points 6 months ago* (last edited 6 months ago) (2 children)

what-the-hell

"Vault 7: CIA Hacking Tools Revealed" has been published by Wikileaks recentely, and Notepad++ is on the list.

The issue of a hijacked DLL concerns scilexer.dll (needed by Notepad++) on a compromised PC, which is replaced by a modified scilexer.dll built by the CIA. When Notepad++ is launched, the modified scilexer.dll is loaded instead of the original one. It doesn't mean that CIA is interested in your coding skill or in your sex message content typed in Notepad++, but rather it prevents raising any red flags while the DLL does data collection in the background.

It's not a vulnerability/security issue in Notepad++, but for remedying this issue, from this release (v7.3.3) forward, notepad++.exe checks the certificate validation in scilexer.dll before loading it. If the certificate is missing or invalid, then it just won't be loaded, and Notepad++ will fail to launch.

Checking the certificate of DLL makes it harder to hack. Note that once users’ PCs are compromised, the hackers can do anything on the PCs. This solution only prevents from Notepad++ loading a CIA homemade DLL. It doesn't prevent your original notepad++.exe from being replaced by modified notepad++.exe while the CIA is controlling your PC.

Just like knowing the lock is useless for people who are willing to go into my house, I still shut the door and lock it every morning when I leave home. We are in a f**king corrupted world, unfortunately.

Otherwise there are a lot of enhancements and bug-fixes which improve your Notepad++ experience.

[–] quarrk@hexbear.net 2 points 6 months ago

Otherwise there are a lot of enhancements and bug-fixes which improve your Notepad++ experience.

lol

"Your baby boy is speaking in tongues and likely to be the Antichrist; ~anywho~, please be sure to return for a check-up in three weeks, and here's a coupon for some baby formula."

[–] frauddogg@lemmygrad.ml 5 points 6 months ago

This is why I do all my scrap coding in regular-ass notepad; fuck this guy honestly

[–] zkrzsz@hexbear.net 4 points 6 months ago

Alternative: NotepadNext

A cross-platform, reimplementation of Notepad++. (Windows, Linux, and MacOS)

load more comments
view more: ‹ prev next ›