

I don’t get how this was exploited in practise.
Even if the signatures on the downloaded packages weren’t checked properly, how would you modify the content of the XML file returned from https://notepad-plus-plus.org/update/getDownloadUrl.php?version=8.8.0 ? For that you’d have to break or MITM the TLS too, no?
The usual case for TLS MITM is when a company decides DPI is more important than E2E encryption and they terminate all TLS on the firewall, but if the firewall is compromised there would be much easier avenues of entry other than notepad++








You are allowed to deduct the money you spent on union dues from your income, thereby lowering your taxable income. So on that portion of income that you deducted, you don’t pay taxes. That’s how all deductions work.