Live data from Hacker News

GCHQ's Boiling Frogs paper on software development

github.com

41–50 of 85 posts

Re: GCHQ's Boiling Frogs paper on software development

#41
post #32

Earlier quoted context omitted.

My question is, why?

It's a PDF from GCHQ. It's almost certainly loaded with a surveillance payload. Probably even some sort of of brainwave scanner.

https://helpx.adobe.com/security/products/acrobat/apsb16-14....

https://www.cvedetails.com/product/497/Adobe-Acrobat-Reader....

Re: GCHQ's Boiling Frogs paper on software development

#47
post #18

Earlier quoted context omitted.

You know that PDFs aren't unsafe, right?

http://www.malwaretracker.com/pdfthreat.php http://security.stackexchange.com/questions/64052/can-a-pdf-...

Yeah, those are vulnerabilities in some PDF readers. Different deal.

Re: GCHQ's Boiling Frogs paper on software development

#48
post #18

Earlier quoted context omitted.

http://www.malwaretracker.com/pdfthreat.php http://security.stackexchange.com/questions/64052/can-a-pdf-...

Yeah, those are vulnerabilities in some PDF readers. Different deal.

That's a bit no-true-Scotsman? There's a history of PDF exploits that have made people wary. The exploits are delivered in the PDF, therefore some PDFs are 'unsafe'.

(As other comments have said, we shouldn't take "omg gchq are going to serve me an exploit PDF" too seriously, but there have been incidents of security services using PDF exploits to spear-phish people)

Edit: an example bank PDF exploit is mentioned in: http://ftalphaville.ft.com/2016/05/13/2161789/how-to-steal-a...

Re: GCHQ's Boiling Frogs paper on software development

#49
GCHQ have a puff piece planted in the FT today about their new twitter feed.

Anyone else going to roll over and forgive them for being the key component in Western citizen surveillance?

Even if they have got someone to draw some cute pictures of frogs whilst trawling all my email?

Not me.

Post reply on HN