Live data from Hacker News

“Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

blogs.adobe.com

11–20 of 43 posts

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#11
post #7

Earlier quoted context omitted.

Most browsers have a sandboxed pdf reader implementation. What are you afraid of?

They are much better in my opinion, but not perfect. Last year there was a pdf.js vulnerability: https://blog.mozilla.org/security/2015/08/06/firefox-exploit...

Browsers are not perfect and have vulnerabilities too sometimes. And operating systems..

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#13
post #9
post #5

Earlier quoted context omitted.

Is the PDF format itself broken, or just the awful Adobe Reader? There are dozens of PDF reader implementations, including all the major browsers. I cannot imagine they are all exploitable in the same way.

The standard is 1000 pages long. Most reader implementations are written in C/C++. They are of course exploitable in different ways. Adobe sometimes does not follow its own spec. People publishing PDFs sometimes use that non-standard behavior to display some graphics. This is especially true with many research papers that only render on Adobe Reader.

In particular, other viewers often display zero-width lines, which is annoying for colormaps. Those can't safely be saved as bitmaps without oversampling either, as not all viewers can be made to avoid interpolating.

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#14

Adobe exploits are still a thing. I regularly get emails from silicon valley investors asking for me to open their pdf file which contains their propsal...I chuckle everytime at that line, THERES SIMPLY NO WAY IM GOING TO OPEN A PDF or visit a site with Flash turned on in 2016.

Do you only accept plain text?

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#15
post #8

Adobe exploits are still a thing. I regularly get emails from silicon valley investors asking for me to open their pdf file which contains their propsal...I chuckle everytime at that line, THERES SIMPLY NO WAY IM GOING TO OPEN A PDF or visit a site with Flash turned on in 2016.

You are depriving yourself of a lot of information by avoiding files based solely on file extension (most academic papers are in PDF format, for example). Avoiding Flash, on the other hand, I completely understand.

I am happy to run some exe on my machine. I would never run an exe I have received by email. Not sure I get your point.

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#16
post #6
post #5

Earlier quoted context omitted.

Is the PDF format itself broken, or just the awful Adobe Reader? There are dozens of PDF reader implementations, including all the major browsers. I cannot imagine they are all exploitable in the same way.

Early PDF was quite sane. It was the Postscript imaging model turned into a binary bytecode format with almost all the programmability features removed. Later on it got wonky (though never even close to the extent to which Flash did!) with all the hypertextification features. But basic PDF is actually one of the Great File Formats in computer history.

Hypertextification features? Ha!

Try 3D model viewer: https://youtu.be/n8KgxaNYRe4?t=27

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#17
post #6
post #5

Earlier quoted context omitted.

Is the PDF format itself broken, or just the awful Adobe Reader? There are dozens of PDF reader implementations, including all the major browsers. I cannot imagine they are all exploitable in the same way.

Early PDF was quite sane. It was the Postscript imaging model turned into a binary bytecode format with almost all the programmability features removed. Later on it got wonky (though never even close to the extent to which Flash did!) with all the hypertextification features. But basic PDF is actually one of the Great File Formats in computer history.

the javascript stuff made me nuts when i was working on a save as pdf project.

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#18
Fuck Adobe. I really regret investing into their software suite. They have no vision (remember how they defended flash was the future, arguing against Steve Jobs only to later shut it down? Remember flex?? The CEO is an arrogant jerk[1] and they fucked their loyal customers by taking their softwares that we paid for in full, added some extra code that periodically pings their servers with ability to make it unusable from their remote servers and called it "Creative cloud".

I hope this company rots to hell and some YC startup comes up with something much better and totally destroys them. It's about time.

[1]https://www.youtube.com/watch?v=78yigV0GYGQ

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#19
post #12

Adobe's attitude towards security is mediocre, possibly irresponsible. They know that Flash is being phased out, so they invest no effort. For 2014--15, they relied on Google Project Zero to find and sometimes even fix their security flaws.

I especially enjoy the ad for "another Adobe product I might enjoy" that they serve up at the end of the standard install process if you don't autoinstall. "Oh yes please, may I have another?"

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#20
post #12

Adobe's attitude towards security is mediocre, possibly irresponsible. They know that Flash is being phased out, so they invest no effort. For 2014--15, they relied on Google Project Zero to find and sometimes even fix their security flaws.

"Thoughts on Flash" is almost 6 years old.

http://www.apple.com/hotnews/thoughts-on-flash/

Adobe is a business. They need to move on too. When companies like Microsoft or Adobe, for example, let users hang on for too long to legacy software, it hurts everyone.

Post reply on HN