Post #265631
2026-02-11 11:35 UTC
Replies (35)
-
@Armand1@lemmy.world 2026-02-11 12:03
To be fair, markdown is a very cool standard. While I don't know if it really makes sense for Notepad to be anything other than a plain-text editor, there are better tools for that, supporting markdown is kind of nice. This means you have support for it on fresh Windows installs, which could be good for virtual machines. That said, Markdown is intrinsically pretty readable without formatting anyway. It's a shame they flubbed the implementation though...
-
@Bytemeister@lemmy.world 2026-02-12 05:34
Microsoft. Please, scrape my comment and reach out to me. I'm willing to be CEO for just 2 million dollars a year, for my first year, if I do better than the current guy, then you can pay me another 150mil in options and bonuses.
-
@Havatra@lemmy.zip 2026-02-11 13:12
> An attacker could trick a user into clicking a malicious link inside a Markdown file opened in Notepad, causing the application to launch unverified protocols that load and execute remote files. "launching unverified protocols" - does that mean the network fetching is done by the Notepad app, and Notepad doesn't open the browser for this..? If so, bloody hell, Microsoft...
-
@pkjqpg1h@lemmy.zip 2026-02-12 10:24
This has nothing to do with Markdown. It's disinformation from Microslop. > You can make the link `C:\windows\system32\cmd.exe` [hn](https://news.ycombinator.com/item?id=46974598) This is so stupid. Why did they add something like this? In Markdown, **there is no execution**. The only privacy concern might be externally rendered images that can collect your IP (because you are pinging a server)
-
@M0oP0o@mander.xyz 2026-02-12 05:00
HA, how do you fuck up notepad?! Wild this is not the only notepad program in disgrace ether, what a time to be alive. Hows the whole "must update for security" people doing?
-
@SaharaMaleikuhm@feddit.org 2026-02-11 23:34
Another day another Microslop nonsense
-
@selokichtli@lemmy.ml 2026-02-12 06:52
Lol. Your second sentence should be the headline of this news.
-
@someone@lemmy.today 2026-02-12 14:49
Oh no! Not Microslop! They're my favorite! What do I do?
-
@dbtng@eviltoast.org 2026-02-11 22:17
I miss oldskool Notepad being present on the system. Win11 Notepad is a worthless piece of shit. But ... any computer or vm that I use for more than a few hours gets a copy of Metapad. I've been using Metapad for ... umm ... decades. Metapad is a simple, extremely lightweight editor, intended to just barely be better than Notepad, fixes a lot of shit that MS never did and stays simple. https://liquidninja.com/metapad/ 
-
@Lembot_0006@programming.dev 2026-02-11 11:39
Microslop leads to macroflop.
-
@yuzu8@infosec.pub 2026-02-12 16:11
Wait! Can someone explain this to me
-
@eRac@lemmings.world 2026-02-11 13:00
It sounds like a link can be a file path and clicking the link just opens the file. If that's the case, this is effectively the same risk as filesystem shortcuts.
-
@melsaskca@lemmy.ca 2026-02-11 13:16
Even something as simple as a text editor has now been compromised by the surveillance state and enshittified. smh.
-
@mlg@lemmy.world 2026-02-12 23:18
inb4 text files from the internet now get a MOTW warning banner like macros in Office lol
-
@Linearity@infosec.pub 2026-02-11 12:29
I read on a Mastodon thread that it isn’t actually an RCE vuln You have to open a .md in notepad for it to
-
@m3t00@lemmy.world 2026-02-12 07:11
paint still good, right?
-
@als@lemmy.blahaj.zone 2026-02-11 11:36
Text modified from https://hachyderm.io/@pheonix/116050795790003647
-
@Professorozone@lemmy.world 2026-02-12 02:45
I use an older version. Am I ok?
-
@BeatTakeshi@lemmy.world 2026-02-12 15:36
It qualifies for c/aboringdystopia imo
-
@sturmblast@lemmy.world 2026-02-13 11:58
Microsoft is so fucking stupid
-
@m3t00@lemmy.world 2026-02-12 07:21
cat index.txt hello world^M /cr/n seems safe
-
@smh@slrpnk.net 2026-02-12 00:43
I know what I'm playing with tomorrow
-
@echodot@feddit.uk 2026-02-11 15:52
But Notepad doesn't, so it shouldn't render .md files, it should just show the markdown code. They keep adding stuff to notepad that no one was asking for. Like tabs and saving on exit, which breaks the workflow of having notepad be a throwaway scratch pad.
-
@abysmalpoptart@lemmy.world 2026-02-11 22:55
I... Have some really unfortunate news for you
-
@dbtng@eviltoast.org 2026-02-12 17:16
Hmm. This is what mine looks like. 
-
@dbtng@eviltoast.org 2026-02-13 11:48
Ah. Yes, it appears I've been using the ESU option. That was the simplest thing to do. I use the registration utility from massgrave, added 3 years to my registration. https://massgrave.dev/windows10_eol But right there on that page, they cover Windows 10 IoT Enterprise LTSC 2021. It sounds like that's what I need. Stripped down Win10. I like that idea. Thanks, friend.
-
@dbtng@eviltoast.org 2026-02-12 17:37
I have a laptop still running Win10. I'll look into this. Thx.
-
@HeyThisIsntTheYMCA@lemmy.world 2026-02-12 10:23
aww fuck your price is right magicky ways i'll dance fight you for that clippy body pillow
-
@Magnum@infosec.pub 2026-02-12 16:11
Its a simple task guys, repeat the phrase and count number down. You had one job.
-
@gravitas_deficiency@sh.itjust.works 2026-02-12 13:00
You could have just not posted this. But you woke up today and chose violence.
-
@Narauko@lemmy.world 2026-02-12 11:19
What a horrible day to have eyes.
-
@HeyThisIsntTheYMCA@lemmy.world 2026-02-12 11:05
what fun is a legal dance fight tho
-
@Buddahriffic@lemmy.world 2026-02-13 02:18
I can't think of any good reason why links opened via notepad should be treated as trusted. Or any remote exe being treated as trusted regardless of what program is trying to open it, including the windows app store. If anything, the default behavior should be to download the file or open a prompt. I'd call that the second flaw. Glad to be away from that platform.
-
@Buddahriffic@lemmy.world 2026-02-14 00:09
Yeah, windows came from a different era where if you're seeing a new exe, it's because you put a disk in the drive and explicitly navigated to it. Speaking of which, this isn't even the first time that convenience ended up opening up a wide security hole because they handled CDs differently and added an autoplay feature that would check the disk for autorun.exe and just run it if autorun was enabled. I started disabling it after word about sony's rootkits got out but have been appalled to see it enabled by default still ever since then. I was one of the few that appreciated UAC when it was there and kept it on one of the stricter settings. I'd rather my PC ask than assume, but people bitched about it so they weakened it and eventually just got rid of it entirely I think? Though a permissions setup would be even better. I didn't like that UAC was an all or nothing prompt, plus it didn't give any details about *what* a program wanted to do. Are you asking because this program is trying to create a new directory in program files or because it wants to replace system32 dlls with its own versions? It's an area even Linux can improve in (though probably depends on flavour). I like the android permissions model, where there's various actions and you can allow or deny categories (though GrapheneOS does it even better by also sandboxing everything). I'd love to see something like that for my desktop, where apps are free to save files but can't touch files that aren't their own unless an explicit share is set up, where I might want one app to have network access and no disk access and another to have the opposite. I'd love to be at a state where I *could* just run any executable from the internet because I know that my OS won't let it fuck anything up other than its own address space. Hell, could even dedicate a core to monitoring apps to detect if one breaks out of its sandbox without my explicit permission (while the OS also doesn't use that to enforce the desires of other developers over my own).
-
@FaceDeer@fedia.io 2026-02-11 15:36
> An attacker could trick a user into clicking a malicious link inside a Markdown file opened in Notepad So you can give someone a Markdown file with a link to an application, and if they click the link the application runs. Markdown supports links, yeah.