3 ms·
How is this different than Adobe Reader, where the ability to execute code within a document reading application has resulted in world wide exploits of operatin
by rm-rf 15y ago
How is this different than Adobe Reader, where the ability to execute code within a document reading application has resulted in world wide exploits of operating systems?
If my document reader can execute any code in any language, then any document that I read has the potential to execute malicious code on my computer, and I now have an exploit vector that I need to consider when downloading documents & opening e-mail attachments.
I understand that the code can be sandboxed, but before I implicitly trust the sandboxing technology, I'd have to see an example of an unexploitable sandbox. I don't know of any - but that doesn't mean they don't exist.
- rakkhi 15y agoChrome one has stood up the best thus far
- ComputerGuru 15y agoRight, but "the best" being a very misleading term for anyone not in the know. It too has failed to do the job.. But, of course, no code is perfect. Just keep that in mind. http://www.informationweek.com/news/security/attacks/229500086 http://www.informationweek.com/news/security/attacks/2295000...
- tobylane 15y agoAdobe gives the same access it has to save to any folder on the drive, to the scripts in the PDF. Apple doesn't make those kind of mistakes.