Xkcd Tech Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 5 August 2010

Critical Adobe Reader Flaw Virtually Ignored

Posted on 19:31 by Unknown
If a tree falls in the woods and there's no one there to hear it, does it still make a sound? Such is the conundrum faced by philosophers for generations.

What if a critical flaw in Adobe Reader was demonstrated before a group of security professionals at the Black Hat conference and none of them made a sound, either?

That's what Charlie Miller must be thinking. He's the security expert that presented the vulnerability at Black Hat. His lament?

"Adobe security is so bad that […] not a single person tweeted it. Sad."

Adobe has acknowledged the flaw and is said to be working on a fix. Whether the patch is released out of band or at Adobe's next scheduled quarterly security release remains to be seen. Also unclear is the list of versions impacted by the vulnerability. The only good news is that there are no reports of exploits in the wild.

Some question how many more security blows Adobe can endure before going down for the count. My response is to look at Microsoft's track record. Many years into their latest secure coding push, Redmond is scheduled to release 14 patches to close 34 vulnerabilities in their August 2010 Bulletin Release. This mandates a massive amount of testing and deployment for enterprise customers, yet Windows is still the dominant operating system and office suite. The cost of switching away is substantial due to user training, infrastructure, and application impacts that it's almost cheaper to stick with the ugliness you know.

The same holds true for Adobe. It's the PDF reader with the most saturation, and not just among corporate environments. Home users are virtually guaranteed to have Adobe Reader installed on their systems, even though fully functional alternatives exist. Many have found Reader installed as a bundled offering from another application. The home user is also more likely to have an unpatched operating system and outdated software offerings, making exploit trivial. Antivirus protection? Please.

Adobe's install base and numerous versions places the company in the same predicament as Microsoft. There's a lot of old, insecure stuff out there, and even offering an automatic update solution only partially solves the problem. If Adobe can get 80% of the vulnerable installs patched, that still leaves hundreds of thousands, perhaps millions, of ripe targets out there. And when the next critical Adobe flaw appears - and you know it's when, and not if - the hamster wheel spins again.

My advice is the same as always. Dump Adobe products for less target-rich alternatives. A simple Google search on PDF readers will return scores of options onto your screen. Be sure to completely uninstall any Adobe software currently on your machine, being wary of third-party apps that might have plunked down some version while you whistled through a boring install routine. If in doubt, use Task Manager to look for processes associated with Adobe products.

Otherwise, abandon hope all ye who enter Adobeville. Like another Scream sequel, this will not end well.





Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Adobe, vulnerability | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • SMBC - Ass Acne
    Saturday Morning Breakfast Cereal
  • The Shame
    Oh, McRib. You are one saucy bitch.
  • Sharron Angle - All Fringe, All The Time
    The highlight of Harry Reid's political career must be that joyous moment when Sharron Angle won the Republican primary and become Reid...
  • Mad World
  • Maslow's Hierarchy of Robot Needs
    Via lunchbreath's photostream on flickr
  • Rain, rain, go away...
    Ugh. More rain. It's been so wet the last few weeks that I'm suffering from a bad case of trench-house. Back to you, Chet.
  • (no title)
    Hi. You may not remember me, but I am Kevin's son. As you may know, we have been coping with the loss of my mom, and it is very difficul...
  • Steve Jobs
    There's been a lot of talk since Jobs died about his passion for thinking differently, and how the "crazy ones" are actually t...
  • Goodnight iPad
  • Adobe Flash Player Update Fixes 32 Security Flaws
    It should tell you something that Adobe's latest Flash Player update, released in response to ongoing exploits of a particular vulnerabi...

Categories

  • activism
  • Adobe
  • advertising
  • Afghanistan
  • aging
  • airlines
  • Apple
  • Arizona
  • art
  • banking
  • Barack Obama
  • Barbie
  • blog
  • Bobblespeak Translation
  • business
  • charity
  • childhood
  • CNN
  • Colbert
  • Columbus
  • comic
  • commentary
  • compassion
  • computers
  • conservatives
  • crime
  • cyber security
  • DADT
  • data protection
  • David Letterman
  • death
  • democracy
  • dogs
  • Ebert
  • economy
  • education
  • EFF
  • energy
  • England
  • environment
  • evolution
  • exploit
  • Facebook
  • faith
  • feminism
  • finance
  • flowchart
  • food
  • football
  • Fox
  • fraud
  • gadget
  • gadgets
  • Gawker
  • gay
  • geek
  • Glenn Beck
  • Google
  • government
  • GraphJam
  • guns
  • hacking
  • history
  • holiday
  • humor
  • information security
  • iPhone
  • Japanese
  • Java
  • John Hodgman
  • Jon Stewart
  • journalism
  • law enforcement
  • legal
  • life
  • lunchbreath
  • mainstream media
  • malware
  • McCain
  • McDonald's
  • media
  • medicine
  • merchandise
  • Metasploit
  • Microsoft
  • military
  • movie
  • movies
  • MSNBC
  • Muppets
  • music
  • nature
  • New Orleans
  • news
  • newspapers
  • NFL
  • NY Times
  • Obama
  • odd
  • Oddly Specific
  • Ohio
  • Olbermann
  • parenting
  • Paul Krugman
  • pets
  • philosophy
  • photo
  • piracy
  • poetry
  • politics
  • prank
  • privacy
  • protest
  • psychology
  • Rachel Maddow
  • racism
  • radio
  • religion
  • Republicans
  • right-wing
  • robots
  • Sarah Palin
  • sarcasm
  • satire
  • Saturday Morning Breakfast Cereal
  • science
  • security
  • Seinfeld
  • sexism
  • sexy
  • SMBC
  • social networking
  • socialism
  • sports
  • Star Trek
  • Star Wars
  • Steelers
  • Stephen Colbert
  • Taibbi
  • taxes
  • tea bagging
  • technology
  • television
  • terrorism
  • The Daily Show
  • the internet
  • The Onion
  • threats
  • toys
  • veteran
  • video
  • video game
  • vulnerability
  • Wal Mart
  • xkcd.com

Blog Archive

  • ►  2013 (1)
    • ►  March (1)
  • ►  2011 (23)
    • ►  November (1)
    • ►  October (4)
    • ►  September (5)
    • ►  April (4)
    • ►  March (5)
    • ►  February (3)
    • ►  January (1)
  • ▼  2010 (476)
    • ►  December (8)
    • ►  November (7)
    • ►  October (24)
    • ►  September (10)
    • ▼  August (28)
      • Republican Young Guns Go 'Pew Pew'
      • Glenn Beck - I Have A Scheme
      • Comfort Wipe - Like A Really Big Qtip For Your Ass
      • Does Red Robin Have Bedbugs?
      • Rachel Maddow Responds to Bill O'Reilly's Response...
      • Sam Seder Calls BS on Manhattan Muslim Mosque Mong...
      • Who does Google know that you know? - Boing Boing
      • Cat Safety Propaganda - A Short Animated Film
      • Pulp Fiction With Mickey Mouse and Donald Duck
      • Christopher Hitchens Talks About God and Cancer
      • Jon Stewart Thinks About Giving Up
      • Praying for a Big Dick
      • Critical Adobe Reader Flaw Virtually Ignored
      • Sarah Palin Thinks Obama Is Over His Head
      • Dog(s) Days of August
      • Sofia Vergara Fights With Gordon Ramsay on Leno
      • Rachel Maddow - Prop 8 Decision
      • XKCD: Atheists
      • Dick Pen
      • Severe, Rampant Diarrhea Can't Be Good
      • Beatles Flowchart
      • Olympic Badminton Rant
      • Maslow's Hierarchy of Robot Needs
      • SMBC - Carl Sagan
      • Fox Gets A Front Row Seat
      • Wrightsville Beach Diner
      • Drill, Baby, Drill: A Coke Talk Analysis
      • Meaty Spam in my Inbox
    • ►  July (44)
    • ►  June (83)
    • ►  May (147)
    • ►  April (125)
Powered by Blogger.

About Me

Unknown
View my complete profile