Sunday, February 6, 2011

OMG! WTF? PDF! (week 7 posting)

Sorry everyone for not posting anything in a while, I was in an accident and things have been a little hectic around the house for a little over a week now. Things are returning to normal so it's time I get caught up on my work...

So what's up with the tittle there? If you know your memes you know the tittle is a spinoff from the "OMG! WTF? BBQ!" meme. I can't take credit for this one however. This variation was brought around by Julia Wolf as she recently gave a presentation at the 27th Chaos Communication Congress. Her presentation focussed on the growing problem of Adobe Acrobat's file format, PDF. I hope the meme sticks becuase like the BBQ reference it seems as though you can't read any sort of cyber or information security literature that isn't riddled with instances in which the PDF format was the vector of choice for some sort of attack.

Just do a search for the title and you will find the presentation on youtube, no worries. It's a rather interesting account of all the "fun" stuff that makes PDF such a wonderful platform for hackers and cyber criminals. In the end you probably won't "learn" more than you already knew minus a few technical details, so yes PDF is bad, always has been always will. This, I think, was the purpose of the presentation. Not to teach us something new, but to serve as a slap in the face like a Homer Simpson "DOH!" when we think to ourselves "Why are we still using PDF?"

I have gone over it in my head a few times and there is nothing PDF provides that other formats can't. To those who would say that its the ease of use since PDF is more of an encapsulating format than anything else I would respond by saying "This is why hackers love it too!"

So why don't we just drop the format completely? Start simple, have your company, your school, your home block incoming pdf files and remove the mime type from your computer while uninstalling Adobe Acrobat. See how much of a disruption it causes. My guess would be that it wouldn't be much and your network will probably be fairly free of nastiness to boot!

No comments:

Post a Comment