logoalt Hacker News

Someone1234yesterday at 11:40 PM2 repliesview on HN

I'm out of the loop: How did they bypass Notepad++'s digital signatures? I just downloaded it to double-check, and the installer is signed with a valid code-signing certificate.


Replies

gruezyesterday at 11:53 PM

The updater doesn't check the certificate of the updated installer, it just executes whatever.