Adobe Reader is world's most-exploited app
theregister.co.uk
theregister.co.uk
I keep reader up to date but often these exploits hit either right after an update as been released so the patch hasn't been applied, or there just isn't a patch yet. It's almost enough to make me switch to foxit. I just have to do the research to see if it supports the advanced features (forms, digital signatures, encrypted files) that people are using.
Very few apps (I actually can't name one) with that market footprint fare better than Reader is now. Microsoft has poured supernatural amounts of money into Internet Explorer, and they're still getting in the paper over IE zero day.
http://www.jwz.org/doc/easter-eggs.html
Adobe is giving the market what it wants. It may be part of the current zeitgeist that software developers have a paternal responsibility to defer functionality in favor of security and reliability, but that notion --- if it exists in reality anywhere --- is extremely recent.
Reader got complicated long before any major software vendor got religion about security.
On the other hand, if I had deadlines and a decade of backward-compatibility to worry about I might have different values. I don't mean to be the highbrow/ivory tower security dude, I'm just speaking to what I value.
Reader doesn't just have to show a paper in an office. It could have a form. It could have a CAD drawing. It could do all sorts of magic that a business can come to rely on.
Imagine how much simpler it is to send a PDF to a client to sign and "submit" as opposed to managing faxes.
It's also an ISO standard, so there aren't a lot of degrees of architectural freedom in simplifying and hardening it. Remember that much of PDF predates "modern" vulnerability research.
I personally do not use Adobe Reader on any platform. I found the alternatives to be both leaner and not lacking any relevant features.
Is there a properly full-featured PDF viewer for Mac that isn't from Adobe?