Showing posts with label Adobe. Show all posts
Showing posts with label Adobe. Show all posts

Tuesday, August 9, 2011

Adobe CRITICAL Security Updates for August!

Adobe released another slew of 'Critical' security updates today. Here's the lineup:

- Adobe Shockwave Player - Update to v11.6.1.629. (Be careful which version you install, either 32-bit or 64-bit, to match the bit mode being used by your web browsers. If one version fails, uninstall it and try the other). Numerous memory corruption (buffer overflow) vulnerabilities.

- Adobe Flash Media Server - Update to v4.0.3 or v3.5.7. Memory corruption (buffer overflow) vulnerability.

- Adobe AIR - Update to version v2.7.1. (Apparently required as part of the Adobe Flash Player update).

- Adobe Flash Player - Update to v10.3.186.5. Numerous memory corruption (buffer overflow) vulnerabilities and a cross-site information disclosure vulnerability.

- Adobe Photoshop CS5 - Update via CS5/CS5.1 Standard Multiplugin Update. Malicious GIF file vulnerability.

- Adobe RoboHelp / RoboHelp Server - RoboHelp v9.0.1.262 users are NOT vulnerable. Earlier RoboHelp 9 users update via APSB11-23_1.zip. RoboHelp 8 users update via APSB11-23_2.zip. Cross-site scripting attack vulnerability.

You can access links to all the security announcements and update files here:

Adobe Product Security Incident Response Team (PSIRT) Blog

--

Tuesday, April 12, 2011

Warning: New Adobe Flash Flaw

--
Another month, another Adobe Flash security flaw. The following is a full quote from the most excellent SANS NewsBites Vol. 13 Number 29:
--Adobe Warns of Zero-Day Flaw in Flash
(April 11, 2011)
Adobe has issued a warning of a zero-day vulnerability in Flash Player that is being actively exploited in targeted attacks. The vulnerability can be used to take control of computers or to cause them to crash.  The attack is spreading as a Flash (.swf) file embedded in a Microsoft Word (.doc) file that arrives as an attachment.  Adobe did not say when a patch will be available.
Internet Storm Center:
http://isc.sans.edu/diary/Yet+another+Adobe+Flash+Reader+Acrobat+0+day/10696
http://news.cnet.com/8301-27080_3-20052894-245.html?tag=mncol;title
http://www.zdnet.com/blog/security/adobe-warns-of-new-flash-player-zero-day-attack/8524
http://www.computerworld.com/s/article/921572/Adobe_confirms_critical_Flash_zero_day_bug
[Editor's Note (Ullrich): In the past, I have observed users using Flash games embedded in Excel and Word documents to bypass corporate controls to prevent users from running these games. It may be a good awareness item to note the particular danger of these embedded flash files.]
You can sign up for the SANS Institute newsletters HERE.

I've also been reading about computers being PWNed via infected PDFs and Flash embedded in Excel spreadsheets.

My advice continues to be adherence to the Rules of Computing #1 and #2:

1) Make A Backup. Every day. Two of them. One on site. One off site.

2) Verify every file and application you receive or gather off the Internet as LEGITIMATE before you open it. That means doing homework. It's worth it.

Then add to that:

A) Avoidance of automatically running anything embedded in PDFs or Excel or Word or PowerPoint presentations you receive. Make sure YOU are in control of what runs when and where. No automatic anything. Make yourself the boss of your computer. The LUSER Factor remains a large problem for all of us. But we humans have a lot better scrutiny than a brainless computer program.

B) Don't Use Flash! Or at the very least use one of the many great utilities to stop Flash from running until YOU decide you want to run it. Also use utilities that KILL Flash cookies. These utilities include: The Safari Cookies extension. ClickToFlash.The Flashblock add-on for Firefox. The NoScript add-on for Firefox. The FlashFrozen application.

OF INTEREST: I read this week about a new Adobe initiative that will allow combining Flash with PHP in order to create non-Adobe Air apps for smart phones and all iOS devices. My initial response, knowing the poor security of both technologies, is OMFG. But rather than get all FUDed out, let's simply see what happens.

Stay safe. Stay secure. Laugh at the FUD. Enjoy the facts.

:-Derek
--

Tuesday, September 14, 2010

NEWEST-New CRITICAL Adobe Security Holes
déjà vu déjà vu déjà vu...


--
Question: What is the point of 'in band' quarterly Adobe security updates when this stuff keeps repeating month after month after month?

SHORT VERSION:

Don't use Adobe Reader, Adobe Acrobat, or Adobe Flash until yet-another-nother set of 'out-of-band' security updates are available. Each of these applications have NEW security holes that are being exploited IN THE WILD.

[...Hysterical laughter is heard from some distant room...]

Temporary fix options:

A) PDF Viewing

Use Preview, provided with Mac OS X, for all PDF file reading.

Delete the Adobe PDF Viewer Internet plug-in. You will find it here:
/Library/Internet Plug-ins/AdobePDFViewer.plugin
Delete Adobe Reader 9. You will find it here:
/Library/Applications/Adobe Reader 9
B) Flash Playing

Control Flash in your web browser and/or delete Flash Player:

There are several options for taking control of Flash in your web browser. I personally use ClickToFlash for Safari and other WebKit browsers, as well as Flashblock for FireFox.

OR

Just delete Adobe Flash Player from your computer.

How to remove Adobe Flash Player:

Check to see if you have the 'uninstall_flash_player_osx.dmg' file and run it. It should be located here:
/Applications/Adobe Flash Player/uninstall_flash_player_osx.dmg
OR

You can find and remove the Flash web plug-in files here:
/Library/Internet Plug-Ins/Flash Player.plugin

/Library/Internet Plug-ins/flashplayer.xpt
After deleting Adobe Flash Player files, be sure to Quit then restart your web browsers in order to clean Flash Player out of memory.

~~~~~~~~~~~~~~

LONG VERSION:

Just when you thought your Adobe apps were safe, this dark sense of wariness creeps into your subconsciousness followed by a sense of déjà vu as you read the latest news. I'll let Adobe give you the bad news. Here are the two pages at Adobe where you can find their security announcements:

Adobe Product Security Incident Response Team (PSIRT)

Adobe Security Bulletins and Advisories

The latest Adobe bad news déjà vu déjà vu déja vu (with added emphasis mine):


I) Security Advisory for Adobe Reader and Acrobat (APSA10-02)
Release date: September 8, 2010

Last updated: September 13, 2010

Vulnerability identifier: APSA10-02

CVE number: CVE-2010-2883

Platform: All

SUMMARY

A critical vulnerability exists in Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild.

We are in the process of finalizing a fix for the issue and expect to provide updates for Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 for Windows and Macintosh during the week of October 4, 2010.

Please note that these Adobe Reader and Acrobat updates represent an accelerated release of the next quarterly security update originally scheduled for October 12, 2010. With this accelerated schedule, we do not plan to release any new updates for Adobe Reader and Acrobat on October 12, 2010.

AFFECTED SOFTWARE VERSIONS

Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX
Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh

MITIGATIONS

Current exploits in the wild target the Windows platform. Customers using Adobe Reader or Acrobat 9.3.4 or earlier on Windows can utilize Microsoft's Enhanced Mitigation Evaluation Toolkit (EMET) to help prevent this vulnerability from being exploited. For more information on EMET and implementing this mitigation, please refer to the Microsoft Security Research and Defense blog. Note that due to the time-sensitive nature of this issue, testing of the functional compatibility of this mitigation has been limited. Therefore, we recommend that you also test the mitigation in your environment to minimize any impact on your workflows.

SEVERITY RATING

Adobe categorizes this as a critical issue.

DETAILS

A critical vulnerability exists in Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. Adobe is aware of public exploit code for this vulnerability.

Adobe actively shares information about this and other vulnerabilities with partners in the security community to enable them to quickly develop detection and quarantine methods to protect users until a patch is available. As always, Adobe recommends that users follow security best practices by keeping their anti-malware software and definitions up to date.

We are in the process of finalizing a fix for the issue and expect to provide updates for Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 for Windows and Macintosh during the week of October 4, 2010. These updates will also address the issue referenced in Security Advisory APSA10-03 (CVE-2010-2884).

Please note that these Adobe Reader and Acrobat updates represent an accelerated release of the next quarterly security updates originally scheduled for October 12, 2010. With this accelerated schedule, we do not plan to release any new updates for Adobe Reader and Acrobat on October 12, 2010.

Users may monitor the latest information on the Adobe Product Security Incident Response Team blog at the following URL: http://blogs.adobe.com/psirt or by subscribing to the RSS feed here: http://blogs.adobe.com/psirt/atom.xml.

ACKNOWLEDGMENTS

Adobe would like to thank Mila Parkour of http://contagiodump.blogspot.com for working on this issue with Adobe to help protect our customers.

REVISIONS

September 13, 2010 - Updated information on the release schedule, and that the releases represent the next quarterly security update (originally scheduled for October 12, 2010).
September 10, 2010 - Added the Mitigations section with instructions for a mitigation option for Windows users.
September 8, 2010 - Advisory released.

II) Security Advisory for Adobe Flash Player (APSA 10-03)
Release date: September 13, 2010

Vulnerability identifier: APSA10-03

CVE number: CVE-2010-2884

Platform: All

SUMMARY

A critical vulnerability exists in Adobe Flash Player 10.1.82.76 and earlier versions for Windows, Macintosh, Linux, Solaris, and Adobe Flash Player 10.1.92.10 for Android. This vulnerability also affects Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2884) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against Adobe Flash Player on Windows. Adobe is not aware of any attacks exploiting this vulnerability against Adobe Reader or Acrobat to date.

We are in the process of finalizing a fix for the issue and expect to provide an update for Adobe Flash Player for Windows, Macintosh, Linux, Solaris, and Android operating systems during the week of September 27, 2010. We expect to provide updates for Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 for Windows and Macintosh during the week of October 4, 2010.

AFFECTED SOFTWARE VERSIONS

Adobe Flash Player 10.1.82.76 and earlier versions for Windows, Macintosh, Linux, Solaris, and Adobe Flash Player 10.1.92.10 for Android
Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX
Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh

SEVERITY RATING

Adobe categorizes this as a critical issue.

DETAILS

A critical vulnerability exists in Adobe Flash Player 10.1.82.76 and earlier versions for Windows, Macintosh, Linux, Solaris, and Adobe Flash Player 10.1.92.10 for Android. This vulnerability also affects Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2884) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against Adobe Flash Player on Windows. Adobe is not aware of any attacks exploiting this vulnerability against Adobe Reader or Acrobat to date.

We are in the process of finalizing a fix for the issue and expect to provide an update for Adobe Flash Player for Windows, Macintosh, Linux, Solaris, and Android operating systems during the week of September 27, 2010. We expect to provide updates for Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 for Windows and Macintosh during the week of October 4, 2010.

Adobe actively shares information about this and other vulnerabilities with partners in the security community to enable them to quickly develop detection and quarantine methods to protect users until a patch is available. As always, Adobe recommends that users follow security best practices by keeping their anti-malware software and definitions up to date.

Users may monitor the latest information on the Adobe Product Security Incident Response Team blog at the following URL:

http://blogs.adobe.com/psirt

or by subscribing to the RSS feed here:

http://blogs.adobe.com/psirt/atom.xml

ACKNOWLEDGMENTS

Adobe would like to thank Steven Adair of the Shadowserver Foundation for working with us on this issue with Adobe to help protect our customers.

~~~~~~~~~~~

And now for another rant:

This past week we learned that the first version of Adobe Flash Player had been released for the Google Android OS for smartphones. We also learned that it is a dreadfully buggy, slow, battery consuming POS. Now we learn, if you read through the Adobe bulletins above, that Flash for Android has a 'critical' security hole.

These two Adobe Flash problems were known over a year ago. Dr. Charlie Miller warned us that Flash is the single biggest source of pwnage security holes on the Mac OS X platform. Steve Jobs made it clear that Flash for Mac is a resource hog, verifiable by anyone with a brain (which apparently is not the case with Adobe's current CEO). It is no surprise that Flash turns out to be a resource hog, running as slow as a one-legged dog on Android.

Conclusion: It's time for Flash to die.

Then what?

Contrary to popular mythology, there is no perfect replacement for Flash. The HTML5 video spec promises to replace one niche for Flash with a totally free-forever video playing alternative. (Yes kids. The patent holders for H.264 are giving it away for everyone forever). However, actual Flash applications will be more difficult to replace. These include games, slideshows, web page embedded applications, etc.

Once upon a time we dreamed that Java would take up these roles, and perhaps it may someday. But for now, Java is considered much more difficult to program than Flash, slow to run, and Java has its own security problems. Ideally a Java app building program, as easy as Flash, will appear and will use stringent security protocols, secure memory management and decent speed along with restrained CPU access. It could happen! For all I know, such a Java app builder already exists. Please post a comment if you have related information.

In the meantime, I'm supported the death sentence for Adobe Flash.

Share and Enjoy,

:-Derek
--

Friday, August 13, 2010

Adobe Flash, AIR, PDF, Acrobat and Reader:
Security Statistics Sources

--
Earlier today, I was helping out a reader at MacDailyNews.com who had the following question:
'BSOD' asks: "Does anyone have statistics on exactly how many security holes have been opened up by Flash, Air, and PDF? I think that we need to see that stat."
My answer is of general interest. Therefore, I am posting it here for your reading pleasure:
You can dig around at the CVE site for each of them. CVE stands for Common Vulnerabilities and Exposures. It keeps track of each reported software security problem:

http://cve.mitre.org/

Wikipedia.org also covers each of them and gives a general description of their security:

Adobe Flash: "As of May 17, 2010, The Flash Player has 77 CVE entries, 34 of which have been ranked with a high severity (leading to arbitrary code execution), and 40 ranked medium."

Adobe PDF: "On March 30, 2010 security researcher Didier Stevens reported an "exploit" that causes an arbitrary executable to be run when a PDF file is opened, after the user accepts a warning prompt. The exploit works in several different PDF viewers including Adobe Reader and Foxit Reader."

And, earlier this year Adobe were embarrassed into creating the Adobe Product Security Incident Response Tearm (PSIRT). You can keep up with their blog here:

http://blogs.adobe.com/psirt/

Adobe maintain their Security Bulletins and Advisories page, going back to 2005, here:

http://www.adobe.com/support/security/

• There are approximately 88 Adobe Flash security bulletins.
• There are 6 Adobe PDF security bulletins.
• There are over 100 Adobe Acrobat security bulletins.
• There are over 100 Adobe Reader security bulletins.
• The only Adobe AIR related bulletin is the Adobe Flash bulletin from June 10, 2010.

Tuesday, July 13, 2010

Windows Users ONLY:
Adobe Screw Up Yet-Again!
Acrobat & Reader Updates
DON'T Fix PDF Security Hole

--
For Frack's sake! Adobe = Idiotic Security.

I'm patience counting again: 1 - 2 - 3 . . .

NOTE: This is ONLY a Windows user problem. We Mac OS X users can sit back and gasp. But we are NOT affected (as far as we can tell at this time).

We know Adobe security is bad. We know their attitude toward their security problems is bad. But now we can verify that Adobe are indeed idiots at security. This incident throws their security incompetence into a whole other ballpark.

Enough ranting from me. Windows Users, read and weap this message from Intego:

Last Adobe Reader and Acrobat Update Doesn’t Fix PDF Bug

"... It turns out that Adobe’s fix was not enough. Adobe is aware of the issue and will be issuing an update to the update soon."

Keep in mind, Mac users, that if you use Windows you ARE affected. This means if you load Windows via virtualization or natively via Boot Camp. This PDF exploit is active in-the-wild. Beware.

Again, only Acrobat 8 and Reader 8 are safe. You can roll back to those versions and you're fine. It's Windows versions 9.x that are being exploited. Do NOT use them at this time on the Internet. Do NOT use them with any PDF file that you have not verified as 100% authentic and safe.

And of course, if you're affected, write Adobe a great big 'Thank You' note for being so kind, caring and conscientious toward their customers. /s

[Newbies: "/s" designates sarcasm]
--

Saturday, June 5, 2010

New Adobe Security Holes:
Get Pwned Via Flash Player, Acrobat
or Adobe Reader

--
RISK: CRITICAL
--

Adobe have posted a warning that current versions of Flash Player, Acrobat and Adobe Reader have a DANGEROUS security hole that is currently being exploited out in the wild. Here are some reading sources:

Security Advisory for Flash Player, Adobe Reader and Acrobat

Adobe Warns of Critical Flaw in Flash, Acrobat & Reader

The first article above is direct from Adobe. The second article is analysis by Brian Krebs, a professional computer security journalist.

NOT affected: Version 8.x of Acrobat and Adobe Reader. If you've got them, you can dig them out and use them safely.

You can keep track of the progress in patching this latest set of Adobe holes at either of these sites:

Adobe Security Bulletins and Advisories

Adobe Product Security Incident Response Team (PSIRT)

Because this set of security holes has been found to be exploited in the wild, I can only advise that you do NOT use any of the affected Adobe products with ANY files you encounter via the Internet.

1) Get a plugin for your web browser that TURNS OFF FLASH. (They are available for both WebKit and Mozilla based browsers). Use it and don't watch any Flash until a finished update is provided by Adobe.

2) Only open your own, or verified safe PDF files via Acrobat or Adobe Reader.

If you want to be super-duper safe, trash the Adobe Flash Plugin. You will find it here on your Mac:

/Library/Internet Plug-ins/Flash Player.plugin

Wait until the finished v10.1 Flash Player plugin has been released and install it at that time. The current unsafe Mac version of Adobe Flash Player is v10.0.45.2. When the finished version of Flash Player v10.1 is available, you will find it HERE.
--

Wednesday, April 14, 2010

PDF Security Hole:
Hacking Into Copy & Print 'Locked' PDFs
-revised-

I was hoping I was wrong, but this is what I learned today:

Anyone can hack around a password required to copy from or print a PDF. Anyone.

Thankfully, the full locking of a PDF remains unhacked. The 'Open' password is still required.

A hacking tool that allows you to hack copy and print permissions is today's Mac Update Promo deal of the day. It is called PDFKey Pro. (48% off the regular price of $24.99). This program is a hacking tool that clearly points out a fundamental security hole in the PDF format. Therefore, I see no point in using PDF password for copy and print protection. It's worthless.

Please note that I am not knocking hacking tools. I am not knocking PDFKey Pro. The way it is being sold sounds entirely legitimate. The fact that copy and print PDF protections can be entirely defeated has nothing to do with the developer of this application. It has 100% to do with Adobe. Yeah, I know some people are tired of the onslaught of knocking against Adobe these days. Tough. This is a big fat and ugly nasty problem. Adobe are responsible.

In the past I've talked with both David Pogue and Adam Engst about selling electronic books. David Pogue and I talked about selling protected PDFs as one option. He decided at the time to try Adam Engst's method of simply trusting the customer. As an opponent of DRM (digital rights manglement), I agree with Adam. However, authors and publishers are entirely within their rights to prevent anyone from being able to copy from or print their documents and books.

Therefore, if you want to lock up the copy and print permissions of your docs, look elsewhere. There are plenty of great locking and encryption tools for Mac, but I'm not aware of anything that only prevents copying and printing.

I'd very much enjoy reading an analysis of how PDF protection is hacked. Something tells me it's already out there on the net for any hacker to read and use. What a shame.
--

Wednesday, June 24, 2009

Adobe Shockwave Player v11.5.0.600 & Apple vs. Java Insecurity

--
In its recent attempt to get serious about application security, last week Adobe released Shockwave Player v11.5.0.600 for Mac. Oddly, they released the Windows version a week later. I say oddly because Mac versions of Adobe software are almost always late. It's amusing to see a swap for a change. Now if only Adobe would release the many years delayed 64 bit versions of their applications. Hint hint Adobe.

MacWorld messed up today (6/24) and reported that the Adobe security bulletin about the Windows version 11.5.0.600 of Shockwave Player had anything to do with the Mac version. So I posted a reply comment, which you'll find below. After I posted my comment I visited the Adobe site to find any news about the Mac version. There isn't any. I did however learn that Shockwave Player is compatible with Mac OS X Tiger. That's good to know. I dug around in the installer package and found nothing there as well. If you find anything relevant to Mac security improvements in Shockwave Player v11.5.0.600, please leave a comment.

Here is my comment to MacWorld regarding Adobe Shockwave Player. It is also relevant to Apple's slow poke response to Java security problems:

A couple points:

1) The Adobe Security Bulletin (it's not a blog) is specific to the Windows version ONLY, which apparently was just finished and released. The Mac version of Adobe Shockwave Player v11.5.0.600 was released a week ago on June 16th. Adobe didn't post a security bulletin for the Mac version. And that means what?!

2) bousozoku sez: "Adobe seems to be the only company slower than Apple at taking care of security concerns."

Adobe's attention to security went into deep decline until this past month.

In the meantime, Apple have been improving their attention to security exponentially over the last couple years. It appears to be in response to both the moronic anti-Apple security FUD-fest instigated by Symantec in August 2005, and the White Hat focus on Apple security bugs and vulnerabilities. As is typical with Apple, drag them through the press and they respond.

Where Apple recently fell on their face was with regards to a slew of vulnerabilities in the mess known as Java. Apple were over 6 months behind in Java patches. Sadly, Apple's incredibly slow response to Java updates is consistent. Never has Apple had a serious Java team. Of course one reason is that Apple has to do ALL the work to provide Mac OS X Java updates. Sun provides nothing.

Meanwhile, despite Microsoft's outright hatred of all things Java, to the extent that they were found guilty in court of attempting to destroy Java via their J++ monstrosity, Sun Microsystems write and provide all Windows Java updates. Microsoft never has to lift a finger. That is the single sole reason Windows gets Java updates before Mac OS X. Hey thanks Sun. Sorry you're dead.
--

Wednesday, April 29, 2009

Dump Adobe Reader? Yeah, why not.

--
Intro:
I never like articles with a title ending in a question mark. You know what you're going to get: no answer to the question. Therefore, they are typically filler. Yawn on that. So here is my question and answer title. Let's get to the point right off the bat: Adobe Reader is a security risk.

The chatter on the net this past week has come to the conclusion that the long line of security holes in Adobe Reader over the past two years is enough already. Dump the thing. It's like my conclusion from decades past that Windows, among its many disappointments, is too much of a security risk to use professionally. That any business or any government uses it greatly concerns me. But it's not Microsoft bashing day. It's Adobe bashing day. If you don't need Adobe Reader, don't use it. Thankfully, Mac OS X users have Apple's Preview application, which has not got the JavaScript vulnerabilities of Adobe Reader. So use Preview instead. It's not totally immune to infected PDF files, but it's much safer than Adobe Reader.

OK, it's not like anyone's Mac got pwned by using Adobe Reader. There is no malware targeting Macs that I know of that weasels its way in via holes in Adobe Reader. So really there is no major alarm going off telling us to kick Adobe Reader off the bus for having cooties. But considering that Mac OS X is the safest professional operating system on the planet (not that I'm dissing Linux mind you), avoiding Adobe Reader at this time is a very good idea.

Personally, I've been a fan of PDF since Adobe Acrobat version 3. It's brilliant and has only become better over time. Thank you Adobe, and especially thank you for making it an open standard. Its integration into the core of Mac OS X is incredible. However, Adobe allowed in some poor code, including support for the catastrophe oddly known as JavaScript. I'll skip my usual lecture on how it got its misnomer and how it was ruined as a standard by Microsoft. Simply know that it is a security holey mess. Apple has gotten burned by JavaScript in QuickTime since 2006. The same JavaScript insecurities are equally plaguing Adobe Reader. Apple got control of their JavaScript problems. Adobe are still playing catch up.

Me, I'll still continue to use Acrobat. I'll still keep Reader around for when I absolutely need it. And there are indeed times when I require Reader. But I'm also going to keep an eye on the latest Reader problems and continue to update it (manually!) when updates are offered.
--

Thursday, March 12, 2009

Mostly Harmless: Adobe Updater Requests Administrative Privileges!!!

--
Consider me profoundly ticked off at Adobe. This is the last straw for me regarding their Adobe Updater program. It has now been DELETED off my computer, and I suggest you do the same.

I really hope I am being alarmist about what Adobe just tried to pull on me and I get lots of letters ranting at me about my foolishness. But I believe what I just witnessed on my Mac has tipped Adobe into the Evil Zone.

Back Story:

For the last several years it has been at times hell-on-Earth updating Adobe programs via the Internet. I have never, ever seen a more diabolically BAD system for updating programs. I've written to them about it several times as have hundreds of other people.

So this past year Adobe figured out they had a PR problem and offered professionals the opportunity to describe the problems with Adobe's update system. Hundreds of people again contacted Adobe. So everything is going to get all better now. Right?

Adobe wants to rule your Mac:

Tonight I got notification from good old VersionTracker.com that Adobe Reader version 9.1 had been released. It is a critical update that plugs some very bad security holes. Everyone should update ASAP. So of course I did the update.

As per usual, stupid Adobe couldn't do just one simple update, they had to ask me again and again for permission to install stuff. Among the added rubbish was yet another version of Adobe Updater. Clearly, nothing has been improved in Adobe's idiotic updating system over the Internet.

Then came the very-very last step: A box requesting my password, for a SECOND TIME, allowing Adobe Updater to have ADMINISTRATIVE PRIVILEGES, forever!

Stop and consider that a second. An application asked me if it could always have administrative privileges to do whatever it wanted to my computer at any time. IOW Adobe Updater was asking if it could rule my computer. This is called evil. (OK, now you can tell me I'm paranoid. But I don't think so!)

My response:

I canceled the request.

And for good measure I DELETED Adobe Updater from my computer.

Then I wrote the following to Adobe:

I just installed Adobe Reader 9.1 for Mac OS X.

Why did Adobe Updater ask me for my password so it could run, at will, with Administrative Privileges?

This is profoundly insecure, DANGEROUS and a bad idea in ALL situations.

As a result I CANCELED this privileges request. I also took Adobe Updater and ERASED IT from my computer. Adobe Updater will remain erased from my Macintosh computer until such time as Adobe explains itself regarding this DANGEROUS request. It had better be good. I will be publishing my disgust regarding your privileges request on the Internet and in computer user group newsletters this coming week.
And so I have. And if (a big if) Adobe get off the arrogance kick and actually respond, I'll let you know and share what they say. You can start holding your breath . . . NOW.

Until then:

Clutch your Mac firmly to your breast. Adobe are coming to take it away.
--