top | item 46851791

(no title)

tech234a | 28 days ago

Notably Notepad++ was recently shipping unsigned/self-signed updates, apparently overlapping with the time of this incident, see releases 8.8.2-8.8.6: https://notepad-plus-plus.org/news/

discuss

order

sbohacek|28 days ago

The lack of signing and/or checking the signature when updating is the real issue here. But the write up blames the attack on the hosting server. That doesn't bode well for future security.

bakugo|28 days ago

So they just conveniently decided not to sign their releases right around the time they were supposedly "hacked"?

Something doesn't seem right here.

adzm|28 days ago

Code signing certs are unfortunately expensive