The Notepad++ project is seeking the public’s help in taking down a copycat website that closely impersonates Notepad++ but is not affiliated with the project. There is some concern that it could pose security threats—for example, if it starts pushing malicious releases or spam someday either deliberately or as a result of a hijack.

  • Pyro@programming.dev
    link
    fedilink
    arrow-up
    22
    arrow-down
    5
    ·
    edit-2
    8 months ago

    Reporting the website for malicious content when its a glorified redirect seems a bit harsh tbh. Why not try to set up a dialogue with the copycat website owner first before burning bridges?

    • Monument@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      16
      ·
      8 months ago

      In this situation, I wish Google offered a “Not Authoritative” option to report sites.

      But I mean, doing so would mean then that users have the opportunity to improve google’s search algorithm so that it’s useful, and therefore folks spend less time hunting for info on sites that serve Google Ads. So… that won’t happen.

    • tslnox@reddthat.com
      link
      fedilink
      arrow-up
      7
      arrow-down
      1
      ·
      8 months ago

      So should we wait until they do, users download it and only then should we start appeals to have it taken down?

      • Pyro@programming.dev
        link
        fedilink
        arrow-up
        2
        arrow-down
        1
        ·
        edit-2
        8 months ago

        I specifically said set up a dialogue FIRST. Sure if the owner does not respond or acts in bad faith, they can escalate.

        Immediately starting with reporting the copycat as malicious seems like a overreaction.

        • tslnox@reddthat.com
          link
          fedilink
          arrow-up
          1
          ·
          8 months ago

          I don’t think so. This absolutely looks to me similar as the xz problem that’s hot right now. They set up a website that looks nicer and more polished than the original one, they link the original website at first, the little bitty disclaimer at the bottom is there just for the plausible deniability… Then, when enough people trust it (and Google’s algorithm maybe starts showing it first, who knows…) they can just change the links and suddenly there’s an attack.

          Maybe if the site had a big “fan site” text in the header where everyone can see it right away, I would be less suspicious.