Live data from Hacker News

GCHQ's Boiling Frogs paper on software development

github.com

51–60 of 85 posts

Re: GCHQ's Boiling Frogs paper on software development

#51

http://imgur.com/a/pbazB Contents of this PDF, page by page, in JPGs.

PNG would be more fitting for content like this.

(In case folks don't know, PNG better for text because JPG's compression introduces "ringing" artifacts around sharp edges, such as the black/white transition of text.) https://en.wikipedia.org/wiki/Ringing_artifacts

Re: GCHQ's Boiling Frogs paper on software development

#53
I really doubt this PDF is infected with anything like people are suggesting, but why is it on here at all? It seems incredibly empty and buzzword-y to me, interspersed with such charming insights as "It can make good sense to use external suppliers." Lots of talk about "disruption". It reads... well, it reads exactly like what it is, a vacuous corporate "whitepaper".

Re: GCHQ's Boiling Frogs paper on software development

#55
post #53

I really doubt this PDF is infected with anything like people are suggesting, but why is it on here at all? It seems incredibly empty and buzzword-y to me, interspersed with such charming insights as "It can make good sense to use external suppliers." Lots of talk about "disruption". It reads... well, it reads exactly like what it is, a vacuous corporate "whitepaper".

Because GCHQ are having a PR drive and they have enough accounts here to up-vote it to the front page?

Re: GCHQ's Boiling Frogs paper on software development

#57

Earlier quoted context omitted.

That makes literally no sense.

It literally makes sense. Do you mean to say it is paranoid?

No. The origin of a PDF has no relation to the security or otherwise of the format.

Re: GCHQ's Boiling Frogs paper on software development

#58
post #48

Earlier quoted context omitted.

Yeah, those are vulnerabilities in some PDF readers. Different deal.

That's a bit no-true-Scotsman? There's a history of PDF exploits that have made people wary. The exploits are delivered in the PDF, therefore some PDFs are 'unsafe'. (As other comments have said, we shouldn't take "omg gchq are going to serve me an exploit PDF" too seriously, but there have been incidents of security services using PDF exploits to spear-phish people) Edit: an example bank PDF exploit is mentioned in:…

That's true, only in the sense that all software ever published may have vulnerabilities, meaning there is no format which is 'safe'. That's fine, if that's your definition, but it's obviously useless for comparison.

Re: GCHQ's Boiling Frogs paper on software development

#59

http://imgur.com/a/pbazB Contents of this PDF, page by page, in JPGs.

PNG would be more fitting for content like this.

Are the contents of the link so very pixelated that you are unable to follow along without PNG conversion? If yes, may I recommend a quick trip to your local optometrist?

Re: GCHQ's Boiling Frogs paper on software development

#60

Earlier quoted context omitted.

PNG would be more fitting for content like this.

(In case folks don't know, PNG better for text because JPG's compression introduces "ringing" artifacts around sharp edges, such as the black/white transition of text.) https://en.wikipedia.org/wiki/Ringing_artifacts

JPGs are also a lot safer as PDFs can ping remote resources using carefully hidden beacon images.

Although that said, I sometimes use this to see who opened my files. I once left hundreds of these on a very popular cloud hosting provider (not naming names), and somebody working there was stupid to open the PDF on a machine connected to the internet, thereby proving abuse by employees and proving any random stranger can access 'your' files in the so called 'cloud'.

Look up 'honeydocs'. Some interesting articles about this technique

Post reply on HN