Live data from Hacker News

Adobe CVEs

cve.mitre.org

21–23 of 23 posts

Re: Adobe CVEs

#21
post #9

Earlier quoted context omitted.

Their customers don't care and they are not altruistic like Mozilla or OpenBSD.

When Flash and Acrobat go away completely, Adobe most certainly does care because it has lost its customers.

Apparently people on HN aren't aware that nowadays Flash compiles to native code and used in many mobile games

http://www.adobe.com/devnet-apps/flashshowcase/#/main

As for Acrobat, it is daily used across all our Fortune 500 customers.

Re: Adobe CVEs

#22
post #11

Earlier quoted context omitted.

Adobe would definitely profit from languages such as Rust. But they are not a "tech" company in the traditional sense anymore, I don't see them investing in anything that doesn't yield high short term returns. It's a big company that dominates the "creative" market, because it can impose its formats on an industry that does not care about open technologies.

Rust isn't a cure-all for every security issue.

True, and there are lots of security exploits that are caused by logical error, but the majority of those CVEs are caused by memory corruption, use-after-free and out-of-bounds memory corruption.

All errors avoidable in Rust, as well as other safe languages, outside unsafe blocks.

Re: Adobe CVEs

#23
post #14
post #6

Earlier quoted context omitted.

The vastly lower attack surface in PDF viewers built into browsers has been quite frustrating for me. I've seen Adobe vulnerabilities in the wild, and I've seen the improvements to an organisations security by removing Adobe Reader. Not to mention, the immediate reduction in labour of managing its colossal updates regularly. However, try to remove Adobe PDF in a business with more than a few people, and ime, it's onl…

Is Evince capable of displaying the complex PDF's you are talking about?

Evince is usually good enough, the problem that managing type people often like to make annotations in Acrobat and to open those you have to have Adobe stuff.

Edit: not to open maybe, but to see the annotations

Post reply on HN