zlacker

[return to "Notepad++ hijacked by state-sponsored actors"]
1. OsrsNe+a2[view] [source] 2026-02-02 02:21:25
>>myster+(OP)
So the hosting provider was hacked? Who was their hosting provider?

This is also why update signatures should be validated against a different server; it would require hackers to control bother servers to go undetected

◧◩
2. gruez+c3[view] [source] 2026-02-02 02:32:10
>>OsrsNe+a2
>This is also why update signatures should be validated against a different server; it would require hackers to control bother servers to go undetected

No, it should be a hardcoded key held by the developer, preferably using a HSM, and maybe with some sort of notification capability in case the key was lost. Adding a second server adds marginal security. For instance if the developer's mail was hacked, an attacker would likely be able to reset passwords for both hosting providers.

[go to top]