Xkcd Tech Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 5 August 2010

Critical Adobe Reader Flaw Virtually Ignored

Posted on 19:31 by Unknown
If a tree falls in the woods and there's no one there to hear it, does it still make a sound? Such is the conundrum faced by philosophers for generations.

What if a critical flaw in Adobe Reader was demonstrated before a group of security professionals at the Black Hat conference and none of them made a sound, either?

That's what Charlie Miller must be thinking. He's the security expert that presented the vulnerability at Black Hat. His lament?

"Adobe security is so bad that […] not a single person tweeted it. Sad."

Adobe has acknowledged the flaw and is said to be working on a fix. Whether the patch is released out of band or at Adobe's next scheduled quarterly security release remains to be seen. Also unclear is the list of versions impacted by the vulnerability. The only good news is that there are no reports of exploits in the wild.

Some question how many more security blows Adobe can endure before going down for the count. My response is to look at Microsoft's track record. Many years into their latest secure coding push, Redmond is scheduled to release 14 patches to close 34 vulnerabilities in their August 2010 Bulletin Release. This mandates a massive amount of testing and deployment for enterprise customers, yet Windows is still the dominant operating system and office suite. The cost of switching away is substantial due to user training, infrastructure, and application impacts that it's almost cheaper to stick with the ugliness you know.

The same holds true for Adobe. It's the PDF reader with the most saturation, and not just among corporate environments. Home users are virtually guaranteed to have Adobe Reader installed on their systems, even though fully functional alternatives exist. Many have found Reader installed as a bundled offering from another application. The home user is also more likely to have an unpatched operating system and outdated software offerings, making exploit trivial. Antivirus protection? Please.

Adobe's install base and numerous versions places the company in the same predicament as Microsoft. There's a lot of old, insecure stuff out there, and even offering an automatic update solution only partially solves the problem. If Adobe can get 80% of the vulnerable installs patched, that still leaves hundreds of thousands, perhaps millions, of ripe targets out there. And when the next critical Adobe flaw appears - and you know it's when, and not if - the hamster wheel spins again.

My advice is the same as always. Dump Adobe products for less target-rich alternatives. A simple Google search on PDF readers will return scores of options onto your screen. Be sure to completely uninstall any Adobe software currently on your machine, being wary of third-party apps that might have plunked down some version while you whistled through a boring install routine. If in doubt, use Task Manager to look for processes associated with Adobe products.

Otherwise, abandon hope all ye who enter Adobeville. Like another Scream sequel, this will not end well.





Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Adobe, vulnerability | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Praying for a Big Dick
    Saturday Morning Breakfast Cereal
  • The Shame
    Oh, McRib. You are one saucy bitch.
  • Give Mom The Gift of Masturbation for Mother's Day
    Wow. I've heard of targeted marketing before, but the thought of giving your mother a DC-powered sex vibe is one forward-leaning way to ...
  • Chamber of Whores
    GRIT TV has put together a damning behind-the-scenes look at the U.S. Chamber of Commerce that details from where the money comes, and to wh...
  • Maslow's Hierarchy of Robot Needs
    Via lunchbreath's photostream on flickr
  • Matt Taibbi on Olbermann Suspension
    How Matt Taibbi is able to continually squeeze through the bullshit and come out crystal clear on the other side is beyond me, but his analy...
  • Who does Google know that you know? - Boing Boing
    It's unsettling to click a link and find that you're connected to thousands of people without your knowledge, even though that's...
  • Goodnight iPad
  • SMBC - Ass Acne
    Saturday Morning Breakfast Cereal
  • What's With All The Anal Sex Studies?
    The NYC Department of Health recently released a report entitled, "Women, Unprotected Anal Sex and HIV Risk", in which female resp...

Categories

  • activism
  • Adobe
  • advertising
  • Afghanistan
  • aging
  • airlines
  • Apple
  • Arizona
  • art
  • banking
  • Barack Obama
  • Barbie
  • blog
  • Bobblespeak Translation
  • business
  • charity
  • childhood
  • CNN
  • Colbert
  • Columbus
  • comic
  • commentary
  • compassion
  • computers
  • conservatives
  • crime
  • cyber security
  • DADT
  • data protection
  • David Letterman
  • death
  • democracy
  • dogs
  • Ebert
  • economy
  • education
  • EFF
  • energy
  • England
  • environment
  • evolution
  • exploit
  • Facebook
  • faith
  • feminism
  • finance
  • flowchart
  • food
  • football
  • Fox
  • fraud
  • gadget
  • gadgets
  • Gawker
  • gay
  • geek
  • Glenn Beck
  • Google
  • government
  • GraphJam
  • guns
  • hacking
  • history
  • holiday
  • humor
  • information security
  • iPhone
  • Japanese
  • Java
  • John Hodgman
  • Jon Stewart
  • journalism
  • law enforcement
  • legal
  • life
  • lunchbreath
  • mainstream media
  • malware
  • McCain
  • McDonald's
  • media
  • medicine
  • merchandise
  • Metasploit
  • Microsoft
  • military
  • movie
  • movies
  • MSNBC
  • Muppets
  • music
  • nature
  • New Orleans
  • news
  • newspapers
  • NFL
  • NY Times
  • Obama
  • odd
  • Oddly Specific
  • Ohio
  • Olbermann
  • parenting
  • Paul Krugman
  • pets
  • philosophy
  • photo
  • piracy
  • poetry
  • politics
  • prank
  • privacy
  • protest
  • psychology
  • Rachel Maddow
  • racism
  • radio
  • religion
  • Republicans
  • right-wing
  • robots
  • Sarah Palin
  • sarcasm
  • satire
  • Saturday Morning Breakfast Cereal
  • science
  • security
  • Seinfeld
  • sexism
  • sexy
  • SMBC
  • social networking
  • socialism
  • sports
  • Star Trek
  • Star Wars
  • Steelers
  • Stephen Colbert
  • Taibbi
  • taxes
  • tea bagging
  • technology
  • television
  • terrorism
  • The Daily Show
  • the internet
  • The Onion
  • threats
  • toys
  • veteran
  • video
  • video game
  • vulnerability
  • Wal Mart
  • xkcd.com

Blog Archive

  • ►  2013 (1)
    • ►  March (1)
  • ►  2011 (23)
    • ►  November (1)
    • ►  October (4)
    • ►  September (5)
    • ►  April (4)
    • ►  March (5)
    • ►  February (3)
    • ►  January (1)
  • ▼  2010 (476)
    • ►  December (8)
    • ►  November (7)
    • ►  October (24)
    • ►  September (10)
    • ▼  August (28)
      • Republican Young Guns Go 'Pew Pew'
      • Glenn Beck - I Have A Scheme
      • Comfort Wipe - Like A Really Big Qtip For Your Ass
      • Does Red Robin Have Bedbugs?
      • Rachel Maddow Responds to Bill O'Reilly's Response...
      • Sam Seder Calls BS on Manhattan Muslim Mosque Mong...
      • Who does Google know that you know? - Boing Boing
      • Cat Safety Propaganda - A Short Animated Film
      • Pulp Fiction With Mickey Mouse and Donald Duck
      • Christopher Hitchens Talks About God and Cancer
      • Jon Stewart Thinks About Giving Up
      • Praying for a Big Dick
      • Critical Adobe Reader Flaw Virtually Ignored
      • Sarah Palin Thinks Obama Is Over His Head
      • Dog(s) Days of August
      • Sofia Vergara Fights With Gordon Ramsay on Leno
      • Rachel Maddow - Prop 8 Decision
      • XKCD: Atheists
      • Dick Pen
      • Severe, Rampant Diarrhea Can't Be Good
      • Beatles Flowchart
      • Olympic Badminton Rant
      • Maslow's Hierarchy of Robot Needs
      • SMBC - Carl Sagan
      • Fox Gets A Front Row Seat
      • Wrightsville Beach Diner
      • Drill, Baby, Drill: A Coke Talk Analysis
      • Meaty Spam in my Inbox
    • ►  July (44)
    • ►  June (83)
    • ►  May (147)
    • ►  April (125)
Powered by Blogger.

About Me

Unknown
View my complete profile