> I know it's annoying to hear this, but I'm going to keep saying it: this stuff is silly. The DLL injection stuff in the CIA leaks should embarrass the CIA.
Are you calling Notepad++ or the CIA silly, here?
If the first case (which I assume) you're comically missing the point yourself, which is a big middle finger to a hostile government agency. This is an international Open Source software, used worldwide, that has taken a stance against US politics before (export restrictions).
So yeah maybe it is to embarrass the CIA, but not quite in the way you describe.
By publicly releasing this "fix", they're making a noise calling out LOOK WHAT THE CIA IS DOING PEOPLE, instead of shrugging "eh, is that all, I sure hope they got better exploits from my tax money" and "gosh I wonder why whoever released all this is angry with the US or something, I bet it's cause they're biased".
Now there's a public post on their site, on record, being shared everywhere that says BUGFIX BECAUSE THE CIA ACTIVELY TARGETED OUR SOFTWARE, so that people know this is no longer some "'They' could potentially do X and Y" but that it's actually happening and in this particular case "They" are the CIA.
I think you understand perfectly well how this sends a very different message to a very different (broader) audience than the (admittedly much more serious) revelations at Blackhat conferences. You remember that all these serious capabilities have been around for a long time, but the public didn't really take it seriously because many people believe "they wouldn't really" or the attacks were surely theoretical or otherwise we'd hear more about it, right? Or even when the capabilities have been right there, clear as day, for a decade, to actually assume "They" are really listening on your Samsung Smart TV's microphones (or you name it), has been flat out conspiracy nut territory or at best you could say "surely they only deploy these capabilities on a very small, targeted scale, responsibly".
And now they're not. We know it's happening. New proof of new scandalous breaches of privacy of individual indiscriminate members of the public comes out every other month or so. The whole world knows that the US/UK surveillance apparatus has spiralled out of control and is surveilling, spying and collecting data on everyone, everywhere. To say now, let's not make a big deal out of this because it just confirms what everybody could have known all along, is an idea that should have its motives questioned (by which I mean, you should maybe ask yourself, not that you're doing it deliberately).
Does Notepad++ really believe that with this fix they've successfully defended their software against CIA (or other gov.actor) exploits? Of course not. But they do get to make a big fuss out of it. And that's important too. If the police beat you up, is that something to make a big fuss out of and try to fix and make sure they don't get away with, even if it doesn't help with them still getting away with actually shooting people dead elsewhere? You can argue about that, but I wouldn't call it "silly".
Are there now people who will think "phew at least now Notepad++ is protected against CIA hacks"--well, probably, quite a few. But you're not addressing or helping those people by talking about Blackhat and hypervisor rootkits.
(... and if it's the second case, "silly" is a bit of an understatement given what these people have been up to the past half century or so--it's not actually quite as funny as in the film Burn after reading)
Are you calling Notepad++ or the CIA silly, here?
If the first case (which I assume) you're comically missing the point yourself, which is a big middle finger to a hostile government agency. This is an international Open Source software, used worldwide, that has taken a stance against US politics before (export restrictions).
So yeah maybe it is to embarrass the CIA, but not quite in the way you describe.
By publicly releasing this "fix", they're making a noise calling out LOOK WHAT THE CIA IS DOING PEOPLE, instead of shrugging "eh, is that all, I sure hope they got better exploits from my tax money" and "gosh I wonder why whoever released all this is angry with the US or something, I bet it's cause they're biased".
Now there's a public post on their site, on record, being shared everywhere that says BUGFIX BECAUSE THE CIA ACTIVELY TARGETED OUR SOFTWARE, so that people know this is no longer some "'They' could potentially do X and Y" but that it's actually happening and in this particular case "They" are the CIA.
I think you understand perfectly well how this sends a very different message to a very different (broader) audience than the (admittedly much more serious) revelations at Blackhat conferences. You remember that all these serious capabilities have been around for a long time, but the public didn't really take it seriously because many people believe "they wouldn't really" or the attacks were surely theoretical or otherwise we'd hear more about it, right? Or even when the capabilities have been right there, clear as day, for a decade, to actually assume "They" are really listening on your Samsung Smart TV's microphones (or you name it), has been flat out conspiracy nut territory or at best you could say "surely they only deploy these capabilities on a very small, targeted scale, responsibly".
And now they're not. We know it's happening. New proof of new scandalous breaches of privacy of individual indiscriminate members of the public comes out every other month or so. The whole world knows that the US/UK surveillance apparatus has spiralled out of control and is surveilling, spying and collecting data on everyone, everywhere. To say now, let's not make a big deal out of this because it just confirms what everybody could have known all along, is an idea that should have its motives questioned (by which I mean, you should maybe ask yourself, not that you're doing it deliberately).
Does Notepad++ really believe that with this fix they've successfully defended their software against CIA (or other gov.actor) exploits? Of course not. But they do get to make a big fuss out of it. And that's important too. If the police beat you up, is that something to make a big fuss out of and try to fix and make sure they don't get away with, even if it doesn't help with them still getting away with actually shooting people dead elsewhere? You can argue about that, but I wouldn't call it "silly".
Are there now people who will think "phew at least now Notepad++ is protected against CIA hacks"--well, probably, quite a few. But you're not addressing or helping those people by talking about Blackhat and hypervisor rootkits.
(... and if it's the second case, "silly" is a bit of an understatement given what these people have been up to the past half century or so--it's not actually quite as funny as in the film Burn after reading)