Civilloquy
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
schizoidman@lemmy.zip to Technology@lemmy.worldEnglish ·
edit-2
3 months ago

Notepad++ updater installed malware

www.heise.de

external-link
message-square
26
fedilink
309
external-link

Notepad++ updater installed malware

www.heise.de

schizoidman@lemmy.zip to Technology@lemmy.worldEnglish ·
edit-2
3 months ago
message-square
26
fedilink
The updater for the open-source editor Notepad++ has installed malware on PCs. An update to Notepad++ v8.8.9 corrects this.

https://archive.is/uCWNB

  • floofloof@lemmy.ca
    link
    fedilink
    English
    arrow-up
    45
    arrow-down
    1
    ·
    3 months ago

    Until version 8.8.7 of Notepad++, the developer used a self-signed certificate, which is available in the Github source code.

    That doesn’t sound wise.

    • asbestos@lemmy.world
      link
      fedilink
      English
      arrow-up
      17
      arrow-down
      1
      ·
      3 months ago

      So the private key was left in the Github source code and nobody caught it? Or was it the public key? (which makes this statement way less impactful)

      • Samskara@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        12
        arrow-down
        1
        ·
        3 months ago

        Private key probably. Only the public key is not enough to sign the package.

    • techt@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      3 months ago

      This is the explanation for why:

      https://notepad-plus-plus.org/news/v883-self-signed-certificate/

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 4.07K users / day
  • 7K users / week
  • 12.6K users / month
  • 23.7K users / 6 months
  • 1 local subscriber
  • 82.5K subscribers
  • 16.6K Posts
  • 527K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.world
  • BE: 0.19.5
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org