Portable Document (and trojan) Format

Old news now: you can booby-trap a PDF by embedding an executable.

Let me state the blindingly obvious:

  1. The vast majority of documents in the world present formatted data, and do not require interaction or automation.
  2. Interaction and automation are vectors for attack. Corollary: you can’t get hacked viewing plain text.
  3. We need a standard format for representing non-interactive, non-automated, formatted data that is intrinsically invulnerable to booby traps (trojans, viruses, …), and is suitable for long-term archiving by allowing retrieval of the raw data or display of the original visual format.

Comments are closed.