Earlier quoted context omitted.
Most browsers have a sandboxed pdf reader implementation. What are you afraid of?
They are much better in my opinion, but not perfect. Last year there was a pdf.js vulnerability: https://blog.mozilla.org/security/2015/08/06/firefox-exploit...
“Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
21–30 of 43 posts
Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
#22I can't help but think that the HN post has that title to give the impression that Adobe knows about an issue and isn't fixing it. But isn't this blog post an announcement about patches that have be deployed for people to install and Adobe included that line to emphasize the importance of the patch?
Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
#23Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
#24Adobe exploits are still a thing. I regularly get emails from silicon valley investors asking for me to open their pdf file which contains their propsal...I chuckle everytime at that line, THERES SIMPLY NO WAY IM GOING TO OPEN A PDF or visit a site with Flash turned on in 2016.
Why not open it in firefox with pdfjs? PDF is still the single best/easiest format to use to render some things.
For regular use, I have come to really like SumatraPDF on Windows, it is relatively lightweight can be used without an explicit installation (hence no admin privileges are required to get it to work), and most importantly, it saves the position on opened PDF files, so if I open a file again later, I am back right where I stopped reading.
Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
#25Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
#26Adobe's attitude towards security is mediocre, possibly irresponsible. They know that Flash is being phased out, so they invest no effort. For 2014--15, they relied on Google Project Zero to find and sometimes even fix their security flaws.
"Thoughts on Flash" is almost 6 years old. http://www.apple.com/hotnews/thoughts-on-flash/ Adobe is a business. They need to move on too. When companies like Microsoft or Adobe, for example, let users hang on for too long to legacy software, it hurts everyone.
Flash is still widely used, and so many websites still rely on it that it will take a lot of time to fully abandon it, so Adobe will still have to fix all security issues for years.
Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
#27Meanwhile I just noticed that my Windows Firefox plugins for Reader DC are not 2015.010.20060 but .20056. I leave these completely disabled at all times anyway.
And nothing annoys me more than having to download the self-deleting autodownloader in Windows.
What a total waste of time for something I rarely use these days...
Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
#28Completely disabled Flash in my main browser (Firefox) a couple months ago. The occasional video player doesn't have a HTML5 fallback, but otherwise it's all good.
Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
#29Adobe exploits are still a thing. I regularly get emails from silicon valley investors asking for me to open their pdf file which contains their propsal...I chuckle everytime at that line, THERES SIMPLY NO WAY IM GOING TO OPEN A PDF or visit a site with Flash turned on in 2016.
Is the PDF format itself broken, or just the awful Adobe Reader? There are dozens of PDF reader implementations, including all the major browsers. I cannot imagine they are all exploitable in the same way.
Given that nearly all reader implementations are written in C/C++, it's always going to be an easy target. Sandboxing hash helped a lot, but there's just a lot to go wrong and always will be.
Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
#30I'm a bit confused about the title of this post. The actual title of the blog post is "Security Updates Available for Adobe Flash Player (APSB16-08)". The current HN link text is “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”. I can't help but think that the HN post has that title to give the impression that Adobe knows about an issue and isn't fixing it. But isn't this blog post an annou…