Xkcd Tech Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 5 August 2010

Critical Adobe Reader Flaw Virtually Ignored

Posted on 19:31 by Unknown
If a tree falls in the woods and there's no one there to hear it, does it still make a sound? Such is the conundrum faced by philosophers for generations.

What if a critical flaw in Adobe Reader was demonstrated before a group of security professionals at the Black Hat conference and none of them made a sound, either?

That's what Charlie Miller must be thinking. He's the security expert that presented the vulnerability at Black Hat. His lament?

"Adobe security is so bad that […] not a single person tweeted it. Sad."

Adobe has acknowledged the flaw and is said to be working on a fix. Whether the patch is released out of band or at Adobe's next scheduled quarterly security release remains to be seen. Also unclear is the list of versions impacted by the vulnerability. The only good news is that there are no reports of exploits in the wild.

Some question how many more security blows Adobe can endure before going down for the count. My response is to look at Microsoft's track record. Many years into their latest secure coding push, Redmond is scheduled to release 14 patches to close 34 vulnerabilities in their August 2010 Bulletin Release. This mandates a massive amount of testing and deployment for enterprise customers, yet Windows is still the dominant operating system and office suite. The cost of switching away is substantial due to user training, infrastructure, and application impacts that it's almost cheaper to stick with the ugliness you know.

The same holds true for Adobe. It's the PDF reader with the most saturation, and not just among corporate environments. Home users are virtually guaranteed to have Adobe Reader installed on their systems, even though fully functional alternatives exist. Many have found Reader installed as a bundled offering from another application. The home user is also more likely to have an unpatched operating system and outdated software offerings, making exploit trivial. Antivirus protection? Please.

Adobe's install base and numerous versions places the company in the same predicament as Microsoft. There's a lot of old, insecure stuff out there, and even offering an automatic update solution only partially solves the problem. If Adobe can get 80% of the vulnerable installs patched, that still leaves hundreds of thousands, perhaps millions, of ripe targets out there. And when the next critical Adobe flaw appears - and you know it's when, and not if - the hamster wheel spins again.

My advice is the same as always. Dump Adobe products for less target-rich alternatives. A simple Google search on PDF readers will return scores of options onto your screen. Be sure to completely uninstall any Adobe software currently on your machine, being wary of third-party apps that might have plunked down some version while you whistled through a boring install routine. If in doubt, use Task Manager to look for processes associated with Adobe products.

Otherwise, abandon hope all ye who enter Adobeville. Like another Scream sequel, this will not end well.





Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Adobe, vulnerability | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • The Three Great Alabama Icons
    Music by Drive-By Truckers.
  • Colbert - Sunday Morning Fact-Checking
    The Colbert Report Mon - Thurs 11:30pm / 10:30c Sunday Morning Fact-Checking - Jake Tapper & Bill Adair www.colbertnation.com Colbert Re...
  • Krugman - Results, Not Process
    I listened to part of Obama's post-election presser today, and I had to turn it off. I thought about what he was saying and knew I had a...
  • (no title)
    Hi. You may not remember me, but I am Kevin's son. As you may know, we have been coping with the loss of my mom, and it is very difficul...
  • EFF - Six Things to Know About Facebook Connections
    Each time Facebook makes a change to their privacy practices, it pisses me off a little bit more. So you can guess how infuriated I was when...
  • Rain, rain, go away...
    Ugh. More rain. It's been so wet the last few weeks that I'm suffering from a bad case of trench-house. Back to you, Chet.
  • SMBC - Ass Acne
    Saturday Morning Breakfast Cereal
  • Ben Stein is a Dick
    A tiny dick, to be sure. Here's what Ben has to say about the unemployed: The people who have been laid off and cannot find work are gen...
  • Mad World
  • The Walken Dead

Categories

  • activism
  • Adobe
  • advertising
  • Afghanistan
  • aging
  • airlines
  • Apple
  • Arizona
  • art
  • banking
  • Barack Obama
  • Barbie
  • blog
  • Bobblespeak Translation
  • business
  • charity
  • childhood
  • CNN
  • Colbert
  • Columbus
  • comic
  • commentary
  • compassion
  • computers
  • conservatives
  • crime
  • cyber security
  • DADT
  • data protection
  • David Letterman
  • death
  • democracy
  • dogs
  • Ebert
  • economy
  • education
  • EFF
  • energy
  • England
  • environment
  • evolution
  • exploit
  • Facebook
  • faith
  • feminism
  • finance
  • flowchart
  • food
  • football
  • Fox
  • fraud
  • gadget
  • gadgets
  • Gawker
  • gay
  • geek
  • Glenn Beck
  • Google
  • government
  • GraphJam
  • guns
  • hacking
  • history
  • holiday
  • humor
  • information security
  • iPhone
  • Japanese
  • Java
  • John Hodgman
  • Jon Stewart
  • journalism
  • law enforcement
  • legal
  • life
  • lunchbreath
  • mainstream media
  • malware
  • McCain
  • McDonald's
  • media
  • medicine
  • merchandise
  • Metasploit
  • Microsoft
  • military
  • movie
  • movies
  • MSNBC
  • Muppets
  • music
  • nature
  • New Orleans
  • news
  • newspapers
  • NFL
  • NY Times
  • Obama
  • odd
  • Oddly Specific
  • Ohio
  • Olbermann
  • parenting
  • Paul Krugman
  • pets
  • philosophy
  • photo
  • piracy
  • poetry
  • politics
  • prank
  • privacy
  • protest
  • psychology
  • Rachel Maddow
  • racism
  • radio
  • religion
  • Republicans
  • right-wing
  • robots
  • Sarah Palin
  • sarcasm
  • satire
  • Saturday Morning Breakfast Cereal
  • science
  • security
  • Seinfeld
  • sexism
  • sexy
  • SMBC
  • social networking
  • socialism
  • sports
  • Star Trek
  • Star Wars
  • Steelers
  • Stephen Colbert
  • Taibbi
  • taxes
  • tea bagging
  • technology
  • television
  • terrorism
  • The Daily Show
  • the internet
  • The Onion
  • threats
  • toys
  • veteran
  • video
  • video game
  • vulnerability
  • Wal Mart
  • xkcd.com

Blog Archive

  • ►  2013 (1)
    • ►  March (1)
  • ►  2011 (23)
    • ►  November (1)
    • ►  October (4)
    • ►  September (5)
    • ►  April (4)
    • ►  March (5)
    • ►  February (3)
    • ►  January (1)
  • ▼  2010 (476)
    • ►  December (8)
    • ►  November (7)
    • ►  October (24)
    • ►  September (10)
    • ▼  August (28)
      • Republican Young Guns Go 'Pew Pew'
      • Glenn Beck - I Have A Scheme
      • Comfort Wipe - Like A Really Big Qtip For Your Ass
      • Does Red Robin Have Bedbugs?
      • Rachel Maddow Responds to Bill O'Reilly's Response...
      • Sam Seder Calls BS on Manhattan Muslim Mosque Mong...
      • Who does Google know that you know? - Boing Boing
      • Cat Safety Propaganda - A Short Animated Film
      • Pulp Fiction With Mickey Mouse and Donald Duck
      • Christopher Hitchens Talks About God and Cancer
      • Jon Stewart Thinks About Giving Up
      • Praying for a Big Dick
      • Critical Adobe Reader Flaw Virtually Ignored
      • Sarah Palin Thinks Obama Is Over His Head
      • Dog(s) Days of August
      • Sofia Vergara Fights With Gordon Ramsay on Leno
      • Rachel Maddow - Prop 8 Decision
      • XKCD: Atheists
      • Dick Pen
      • Severe, Rampant Diarrhea Can't Be Good
      • Beatles Flowchart
      • Olympic Badminton Rant
      • Maslow's Hierarchy of Robot Needs
      • SMBC - Carl Sagan
      • Fox Gets A Front Row Seat
      • Wrightsville Beach Diner
      • Drill, Baby, Drill: A Coke Talk Analysis
      • Meaty Spam in my Inbox
    • ►  July (44)
    • ►  June (83)
    • ►  May (147)
    • ►  April (125)
Powered by Blogger.

About Me

Unknown
View my complete profile