I wish the hackers would leave PDF alone!
Tuesday, 3 August 2010
In case I haven’t made myself clear in other posts, I like PDF documents. I mean I Really Like PDF documents.
And I want to be able to treat a PDF file exactly as I would a sheaf of printed pages.
Then along comes someone who exploits yet another bug in someone’s PDF renderer. A few months ago Acrobat Reader was all over the news. Today I saw that all of the cool kids are jailbreaking their iPhones using a simple web site that exploits a PDF defect in mobile Safari in iOS4.
And if the slick website can inject code that does something as profound as jailbreaking your iPhone, it should be child’s play for a black hat to use the same thing to take over your iPhone and ring up millions of dollars of charges to some telephone extortion outfit in a remote part of Africa.
I guess all of the fancy PDF features are a double edged sword—recall that Active-X controls and DDT were both amazing and powerful when they were introduced, but the improper use of both have sullied their good names. I just hope that the goal of a pure paper replacement standard is not lost and that these events do not cause PDF to become a marginalized technology.


