dslreports logo
 
    All Forums Hot Topics Gallery
spc
Search similar:


uniqs
1029

antdude
Matrix Ant
Premium Member
join:2001-03-25
US

2 recommendations

antdude

Premium Member

'Better than Adobe' Foxit PDF plugin hit by worse-than-Adobe

... 0-day

New security hole: How an evil URL will ruin your day..."

»www.theregister.co.uk/20 ··· in_vuln/

Lagz
Premium Member
join:2000-09-03
The Rock

2 recommendations

Lagz

Premium Member

Perfect example of why I no longer use browser plug-ins to open files within a browser when I can avoid it. Foxit doesn't require you to install the plugin and lets you open the PDF independently of the browser. I use Foxit reader and will continue using it, without the plugin of course. I hate my browser being able to internally open anything. I minimize using the browser to open files internally at all cost. The only browser plugins I use or would recommend is Adblock plus and NoScript.

StuartMW
Premium Member
join:2000-08-06

5 recommendations

StuartMW

Premium Member

I hate opening any file within a browser. I either "Save As" or have my browser configured to do so. Downloaded files are then scanned with AV before opening.

therube
join:2004-11-11
Randallstown, MD

therube to antdude

Member

to antdude
quote:
Note that that exploit deals with the Plugin (npFoxitReaderPlugin.dll), so if you don't install the Plugin ...
»[Updated] [Free] Foxit PDF Reader 5.4.4

Blackbird
Built for Speed
Premium Member
join:2005-01-14
Fort Wayne, IN

1 edit

2 recommendations

Blackbird to antdude

Premium Member

to antdude
It's the same old war between convenience and security. I, like Lagz See Profile and StuartMW See Profile, never open apps files within a browser. I first download the file and then scan it sixteen-ways-to-Sunday with multiple AV tools before opening it directly within the appropriate application. I consider that merely an ordinary element of "safe hex".

On the other hand, I personally know many users who want the file to open directly in the browser... for "speed and convenience". Some of them have gotten badly infected that way, others of them seem to perpetually be struggling with various functional problems with their browser when it attempts to open the connections to the appropriate viewer or apps software... and their resolved problems seem to revisit them almost every time their browser version is updated. That seems to me to be a high risk to run and a lot of frustration to wrestle with, all in the name of 'speed and convenience'.

siljaline
I'm lovin' that double wide
Premium Member
join:2002-10-12
Montreal, QC

1 recommendation

siljaline to antdude

Premium Member

to antdude
Also spotted:
• »www.h-online.com/securit ··· 636.html

StuartMW
Premium Member
join:2000-08-06

1 recommendation

StuartMW to Blackbird

Premium Member

to Blackbird
said by Blackbird:

..."speed and convenience". Some of them have gotten badly infected that way...

In the engineering world there's the time, cost, quality triangle--pick any two.

Perhaps there's a speed, convenience, security triangle too.

PS: Maybe I should explain that better. The point is that whatever two you pick you lose/give up the third.
HELLFIRE
MVM
join:2009-11-25

1 recommendation

HELLFIRE

MVM

In IT it's called the "cheap-fast-perfect" triangle.

In ITSec it's call the "secure-convenient-intrusive" triangle.

Regards

StuartMW
Premium Member
join:2000-08-06

2 recommendations

StuartMW

Premium Member

I figured there was an equivalent.

I used to have a big printed copy of the triangle on my cubical wall. I'd point to it when someone in management came to ask about stuff

ashrc4
Premium Member
join:2009-02-06
australia

ashrc4 to antdude

Premium Member

to antdude
Does nobody else surf/open PDF's using sandboxie properly configured.
Call it "Proactive layered HEX".