I haven't used Notepad++ in awhile
-
Always check your downloads against SHA-256 checksum hashes (if available).
-
@benroyce china took one look at my open notepad++ tabs and noped out.
-
It was a targeted attack. That's the only reason they were able to stay undetected for that long. So no worries. Almost everyone was unaffected, even if your auto updater did check for updates in these months.
- Well, except if you've ties to something-something government(s).
-
Always check your downloads against SHA-256 checksum hashes (if available).
And how does that help if they compromised the servers of the developer?
You don't have any out-of-band way to acquire and verify it. At most you'd be able to get the SHA-256 sum from their website...
(Also this was their server used for the auto-update functionality getting compromised, so...)
-
-
@benroyce I always thought the very best hacks would be the distribution sources. Waiting for news of Google Play Store.
Also chapeau to the developers of Notepad++ for creating something so useful it was considered a good target.
-
R ActivityRelay shared this topic
