I'm being facetious of course, but this recent rhetorical trend of people confidently vouching for "pet" in "pet vs. cattle" is not a sustainable decision, even if it's admittedly plain practical on the short to medium run, or in given contexts even longer. It's just a dangerous and irresponsible lesson to blindly repeat I think.
Change happens. Evidently, while we can mechanistically rule out several classes of bugs now, RCEs are not one of those. Whatever additional guardrails they had in place, they failed to catch this *. I think it's significantly more honest to place the blame there if anywhere. If they can introduce an RCE to Notepad *, you can be confident they're introducing RCEs left and right to other components too **. With some additional contextual weighting of course.
* Small note on this specific CVE though: to the extent I looked into it [0], I'm not sure I find it reasonable to classify it as an RCE. It was a UX hiccup, the software was working as intended, the intention was just... maybe not quite wise enough.
** Under the interpretation that this was an RCE, which I question.
[0] https://www.zerodayinitiative.com/blog/2026/2/19/cve-2026-20...
Most people seem to see "CVE" and "RCE" and assume the worst here. As you saw though, Notepad is just making totally valid URIs clickable! Web browsers allow it too - why is it not an RCE there? Sure, they usually show a warning when the URI is going to something external but most people just click through things like that anyway.
Web browsers warn you about opening arbitrary protocols. And you have to select the program that will open it.
This Notepad vuln, allows you to click things like ssh://x....
Which just opens up SSH connecting to a server. Is that really RCE?
It'll also only work with URI schemes that are registered on your system. It's not running arbitrary commands - software you install on your PC registers URI schemes and sets what command it should run when opened. It's then up to that software to parse the URI and handle it properly. If it doesn't then the RCE belongs to them because they registered the URI scheme and failed to handle it securely. Having an allowlist of URI schemes in Notepad isn't going to fix it.
It works with your _locally_ registered protocols, not just the _remote_ protocols.
Which is why it works with JScript. And Powershell. And Visual Basic.
This is a bug that replicates why IE 4 was called insecure. Its not something that should ever surface again, today.
It is... The exact example of what an RCE is. _Local_ code executed by a _remote_ command.
> According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
> The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally.
> For example, when the score indicates that the Attack Vector is Local and User Interaction is Required, this could describe an exploit in which an attacker, through social engineering, convinces a victim to download and open a specially crafted file from a website which leads to a local attack on their computer.
The low level tool that has served to rescue more systems than I can count does not need to "change" simply because "it happens, bro."
> while we can mechanistically
You can rule it out with process as well. As in "don't change what isn't broken."
> If they can introduce an RCE to Notepad
Then they clearly feel they have no viable competition. This is table stakes. Getting it wrong should lose you most of your customer base overnight. Companies actually used to _work_ this way.
What you find a trusty "low-level" tool is a demo application for a basic WYSIWYG text editor. They modernized it so that it remains being perceived that way, instead of letting it be increasingly misclassified as a legacy product for the enthusiast, like you just did.
Plus, judging by the image, it doesn't look like there's controls to interact with the plain text markdown. It seems more like it's a "you can use markdown _codes_ to trigger text formatting. Jira has exactly this, and it's horrible.
"No, it's the customers who are wrong."
For example, Bob's one-of-a-kind trusty server from which Bob is nigh inseparable, vs. a Docker container with a version controlled config you routinely tear down and bring up instances of, maybe even in an automated fashion.
Here this would map to trusty aged codebases you don't touch out of fear and caution, vs. codebases you can confidently touch because the spec, the code, the tests, the tooling, and the processes are solid.
Pets are projects that you toy with and keep adding new features, even when the main objective has been met. Cattle are projects that do what they are supposed to and are left alone.
I'd much rather have Notepad fall into the cattle category.
maybe we should separate "real origianl text-only editor" from "fancy text editor"?
windows already got wordpad... why even lay a finger on textpad?
wtf why?????????
charge extra premium for a "secure vanilla-text™ pure unadulterated wysiwyg editor" experience should be a thing for the "security-minded" enterprises
The reason I dropped it was cause of a bug where I'd highlight text, copy, and it's actually copy the wrong block of text. Idk the trigger but seems related to larger files.
Windows 10 explorer.exe is 100x faster than Windows 11 explorer, it's not even close.
It also signals the death knell for Windows native apps. Microsoft can't make them anymore. It won't be long until even Excel is a Electron sloplication.
20231109 https://news.ycombinator.com/item?id=38212453 Windows 11 Update 23H2 is stealing users' IMAP credentials (666 points, 278 comments)
> the new Outlook is a thin wrapper around the cloud version, so the IMAP sync happens in the cloud, not locally
Btw, just before that I found this page regarding Edge, and this is why I paid more attention to these things: https://learn.microsoft.com/en-us/legal/microsoft-edge/priva...
That list is way too long for my taste, and it really indicated me that Windows became completely adversarial.
Somehow in this timeline AI can only be used to make things worse and sloppier
They forgot that Enterprises are made out of Users.
AI code that isn't properly guided and controlled by an engineer is just as sloppy as the human behind it.
AI is an accelerate for programming, but some developers create horrible code before AI, snd AI won't change that. It just lets them do it faster.
That being said, no one ever looked at good code and said "that's AI gold," so opinions may be skewed.
Think one step ahead. They will want you to pay them for some LLM "agent" to use the GUI instead. It's not important that GUI is human usable anymore, actually the opposite.
The inverse has been happening. AI seems to be best at JS and React, so many projects use this just to have the best results. I think this is the whole reason that Claude Code is actually React that's then mapped onto a terminal.
I don't think that was ever not the case. The popular UI toolkits include a WYSIWYG editor where you can pick widgets and just put them where you want them with the mouse. Sure, that might not be what developers like to use, but invoking a widget constructor is not that hard and gets you a lot more functionality out of the box, that you would need to implement in JS.
Cross-platform GUIs is also more of a problem of theory. It used to be a big thing, because the GUIs don't look native to the platform, but that concern has gone out of the window with websites now. Win32 programs run with WINE, which I guess is not desirable for deploying to ordinary users, but I guess the people who write for Win32 generally do not care much about porting their programs outside of MS Windows. GTK+ and Qt both run on MS Windows. TCL/Tk comes built-in with Python and looks native on MS Windows.
Encoding algorithms is not that much different across C-like (Algol-derived) languages. Registering callbacks also looks kind of the same. I guess what makes a real difference is the ubiquity of async in JS, where you would use threads more in native applications.
I think what is an actual difference is the mindset around styling and layout. This is something that you actually need to adapt. CSS is more declarative, much like writing constraints for sizes, because you just write a formula about e.g. size in relation to other sizes. On native toolkits you would need to implement this stuff imperatively, I guess this looks like a real downgrade coming from the web, but it is really just a different mindset. Also when you run on the actual machine you have actual access to the device/viewport characteristics and can adapt based on that, and don't need to write an abstract layout. The other side of the coin is that the default widget packaging mechanism has been grid based while CSS only gained that later.
What I guess is also easier in JS, is just drawing on a canvas. The native UI toolkits want to nudge you into implementing a custom widget which implements all the required functionality of widgets. That results in a way better interface for the user, but when you just want a raster graphic you can click on, it can feel like a huge waste of time.
Since now native toolkits also support CSS, have JS bindings and Webpage targets, a guess the difference blurs.
I have a hard time believing this. I'm pretty sensitive to performance losses and I haven't noticed any difference between those. It wouldn't make sense either, given they should both host the same shell icon views. Are you sure the difference you're seeing is in explorer.exe? As opposed to something else, like a new shell extension or a new filesystem filter driver on Windows 11?
Ultimately, what difference does it make? The file explorer in Windows 10 is much faster than the one in Windows 11, and it's very noticeable. Turn on the old context menus, and try right clicking a file. Instant in Windows 10, visible delay in Windows 11.
It does offer some new features for businesses. Nothing useful for the consumer, and nothing to justify the massive performance loss
An i9 with 128GB RAM isn’t enough resources to open a menu?
M$ has now introduced web-latency into the desktop along with their adoption of web-tech into the OS. You gotta get used to staring at that spinning blue circle, counting the many precious moments of your life draining away.
So we're back to the woes of Active Desktop on Windows 98. Everything old is new again.
Do you want the users to blame Microsoft, all Microsoft employees including catering and cleaning workers, and Gates personally? This is how you make the users blame all the before mentioned but not the culprit.
The new calculator even manages to screw up basic input. The old calculator accepted both commas and periods as decimal separator inputs. It just worked no matter what I typed in. The new calculator has some sort of "clever" localization where my inputs change depending on the language of the operating system. My language uses commas so of course it only accepts those. Infuriating. Hope whoever coded this is enjoying their promotion.
It wasn't very sophisticated. But it was fast and it handled commas and periods. It wasn't localized, but it could be.
Sad to think that me having a month of coding experience made a better product than MSFT, yet whoever coded the calculator is probably making ten times what I am right now.
To me it's not sad, it's infuriating. This corporation is worth a trillion dollars. Why can't they do their jobs? I'm sure the old calculator could be maintained and improved without screwing it up beyond belief. Send us some fat stacks and we'll do it.
> It looks like you're trying to calculate averages. Would you like help with that?
> Did you know Microsoft™ Office™ Excel™ has a formula for that? Rent Microsoft™ Office™ Excel™ today! Only $200/month in a perpetual payment plan!
What a time to be alive.
Prayer won't help you now ;)
With numbers >1000 they are of course displayed with thousands separators as 1,000 (text) now like you would see in financial reports, how attractive. Big numbers have a few commas too. No longer displayed as unseparated numerical constants, like you know, computers have always used.
And if you copy the figure from the calculator display, by right-clicking for the context menu or CTRL-C, you get the whole separated text with commas included to paste into where you need it.
So the receiving textbox you pasted to now needs to have the commas manually edited out before you can go forward, unlike any other Windows calculator.
I guess somebody forgot that people might want it to be at least as useful as it was since the 1990's.
You can still paste plain numeric text in without any commas, it just doesn't copy back out in the same usable format like it always did before.
You can't make this up.
A calculator is supposed to be the perfect example of a no-brainer :\
Edit: If you do the math it must have been more than one person who forgot, you have to think, is it even possible for one person alone to be responsible for quality declines like we have seen on their own? If so who would that be?
Just for the record, I just timed how long it took for the calculator to open. Eleven seconds. That's how long it took for it to display a window on the screen. A useless blue filled window that did nothing. It took a total of 17 seconds for it to show the calculator controls and be usable. This isn't a loaded machine, it's a freshly booted Windows system that's been at rest literally doing nothing for over five minutes. Notepad opened and was usable in less than one second.
Reminds me of the shitty gamer laptop manufacturer apps that would take over a minute to display a glorified rectangle on the screen. All this to configure keyboard LEDs. I reverse engineered that garbage and made a Linux version that works instantly, proving their incompetence.
Whatever it is that Microsoft is doing they should probably stop. A goddamn calculator application shouldn't require a high performance workstation to even launch. It worked fine before, now it takes ages and can't even handle input properly. That's stupid and there's really no excuse for it.
And that was orders of magnitude more than W98.
Your SSDs are getting hammered like never before.
The first time you open the new, sluggish replacements for old standbys they take way more time to load, but then if you don't turn off the PC completely they are already in memory lots of times so they pop up faster in subsequent times, and with simple things like Calculator the actual calculation is not any slower than it was in 1998.
At least as long as your PC hardware is 20X as fast :\
browser.urlbar.suggest.calculator = true
I don't know if you need to restore the urlbar first, before that works.The slowdown appears to be due to XAML Islands, which allow legacy code to use modern MS UI stuff.
https://www.techindeep.com/why-is-windows-explorer-slow-7289...
Literally the best parts of Windows have been the parts they forgot existed for 10+ years and never changed.