Authoring - PDFzone
PDFZone Ziff-Davis Enterprise
Authoring | Utilities | Content Management | Document Management | Mobile | DRM | Other Formats | Tips
Home arrow Authoring arrow The PDF Sky's Not Falling (Yet)
The PDF Sky's Not Falling (Yet)
By Don Fluckinger

Rate This Article:
Add This Article To:
Opinion: Recent reports of PDF vulnerabilities to hackers are very real, but patching the problem is simple.

News of online PDFs' vulnerability to so-called Universal Cross-Site Scripting (UXSS) attacks via Explorer, Firefox, and Opera should be taken seriously, and IT folks would do well to heed Adobe's advice on protecting their desktop PCs and servers.

Left unaddressed, this vulnerability gives hackers the ability to piggyback on any legitimate PDF to access a person's hard drive, or steal cookies in order to obtain sensitive information from otherwise secure sites (like, say, your bank).

Adobe ranks this vulnerability as "Important," one degree shy of "Critical," reserved for problems that expose a user to malicious activity "potentially without a user being aware."

ADVERTISEMENT

That's the bad news.

The good news? Upgrading to Reader 8 will solve the problem. Those who can't can also download a Reader 7 incremental patch.

Another way to avoid hacker action is to do what I do anyway, which is view downloaded PDFs in something other than your browser. On the PC, I typically choose Acrobat Reader, and on Mac OS I use the built-in Preview utility or Reader for heavy-duty research.

I do this because I find it much easier to move through PDFs—especially lengthy ones—in these utilities. There's also the old-habits-die-hard factor: Back in the days when PDF and the Web were relatively new technologies and download (and processing) speeds were turtle-slow, opening and paging through a document in one's browser could be an all-afternoon affair, especially when a thoughtless PDF author loaded it with fat, print-sized graphics.

So, while the solution is pretty easy for people with half a brain (or IT watchdogs keeping tabs on security issues on behalf of those who don't) this problem's a doozy for Adobe's PR department.

Unlike Microsoft and other vendors whose software took root in the enterprise environment back when Adobe was a lil-ol' graphics software company, Adobe's come through the hacker wars mostly unscathed, if you don't count the e-book thing.

Sure, there have been other less-severe vulnerabilities exposed and patched over the last few years, but none garnered such sky-is-falling statements such as "the ease in which this weakness can be exploited is breathtaking" on the Symantec Security Response Weblog. That doesn't help Adobe among enterprise software buyers.

While the drama might be a little overstated there, it does go to show that the more trust Acrobat and PDF earns for its typically strong security, the more enticing it looks to bad actors out there in the hacker-sphere.

Deep in the bowels of Microsoft's security enclave, someone's probably already said what we're all thinking: Welcome to our world, Adobe.


Discuss The PDF Sky's Not Falling (Yet)
 
>>> Be the FIRST to comment on this article!
 

 
 
>>> More Authoring Articles          >>> More By Don Fluckinger
 



FREE ZIFF DAVIS ENTERPRISE ESEMINARS AT ESEMINARSLIVE.COM
  • Dec 5, 2 p.m. ET
    Case Studies in MSP Profitability: 10 Processes to Automate to Achieve 2008 Goals
    with Michael Krieger. Sponsored by Autotask
  • Dec 6, 12:30 p.m. ET
    The State of the Great Windows Vista Migration
    with Aaron Goldberg. Sponsored by Dell & Microsoft
  • Dec 6, 2 p.m. ET
    Three Best Practices for Securing Microsoft Exchange
    with Michael Krieger. Sponsored by Entrust
  • Dec 6, 3 p.m. ET
    Simplify Your World, part 2: A Virtual Desktops Case Study
    with Joel Shore. Sponsored by EqualLogic
  • 12-19 VTS LOGO for BotMod
    Join us on Dec. 19 for Discovering Value in Stored Data & Reducing Business Risk. Join this interactive day-long event to learn how your enterprise can cost-effectively manage stored data while keeping it secure, compliant and accessible. Disorganized storage can prevent your enterprise from extracting the maximum value from information assets. Learn how to organize enterprise data so vital information assets can help your business thrive. Explore policies, strategies and tactics from creation through deletion. Attend live or on-demand with complimentary registration!
    FEATURED CONTENT

    Sponsored by Ziff Davis Enterprise Group


    DOWNLOADABLE ROI CALCULATORS & TOOLS FROM BASELINE
      Calculate Cost and ROI of Spam, VOIP, RFID, Sarbanes-Oxley and more...


    Featured Calculators:

     



    See More Tools!
    By Category| Planners |Calculators | Quizzes

     

    Special Report


    PDFzone Special Report: Making the Perfect PDF
    The Perfect PDF
    PDFzone shows you how to shine and polish your PDF by adding the reader-friendly touches your audience desires.

    Special Report


    PDFzone Special Report: Microsoft's PDF Play
    Microsoft's PDF Play
    Microsoft planned to offer a "Save to PDF" function in Office 2007, but the threat of legal action from Adobe may have them reconsidering.

    Special Report


    PDF conversion
    PDF Conversion Central
    Convert anything and everything to PDf and back again. Word docs, RSS, AutoCAD and more.
    ADVERTISEMENT