3 ms·
It would certainly solve a lot of the problems associated with the files. Requiring JavaScript should only be allowed if a sufficient justification is provided.
by x0ner 16y ago
It would certainly solve a lot of the problems associated with the files. Requiring JavaScript should only be allowed if a sufficient justification is provided. Simple things could be done to solve a lot of these problems, but alas, we love our Internet calling functions.
- hga 16y agoHowever there are "sufficient justifications"; the best I've seen is a Missouri individual state income tax form, which besides the expected sorts of things generates a 2D barcode with all the important data encoded into it. Print it out, they scan it in, I can't imagine how much time, money and hassle it saves. Allows for fast refunds as well. So, given that and other useful form type pages, how could we properly manage allowing Javascript for the masses?
- x0ner 16y agoOffhand I can't really think of a way to manage the problem. Instead I am looking at ways to identify the bad parts of it and improve detection. Email me if you would like more details. At this point the specification is not going to just remove or change the problem elements simply because outside the context of the Internet, their not bad. The specification merely offers flexibility to those using or creating PDF files. It is the abuse of that flexibility that make it extremely difficult to identify "known bad" files or protect against them. What I was getting at was a centralized approval system similar to an issuing certificate. In other words, to use certain functionality, you would need to request it from a trusted entity. This of course would be outrageous and likely to be circumvented, but it never hurts to dream.