Why does Adobe Reader need so many updates?
reddit.com
reddit.com
My first try was Foxit. I found its short name promising. The installer confused me with talks of Javascript and safe mode, did not look good. First paper I opened crashed the program. *sigh. Sumatra was had the colourful charm of the web in the 90s. I was almost ready to give up the resistance. I took a deep breath and clicked the link of the installer. Before the next breath it was installed and I was opening PDFs that looked just fine.
TL;DR remove adobe reader, install Sumatra
I would strong recommend PDF-Xchange. I was a heavy Foxit user, but then it became bloated too and Sumatra lacks some features like highlighting and commenting.
... Try to print anything... Remove Sumatra... Install Adobe Reader.
If you have flash and acrobat installed and let the plugins run anytime a site requests them you're begging to be owned (and owned and owned).
I've been using Flash and Adobe/Acrobat reader for years and have yet to be "owned" through either channel, and I spend a lot of time browsing the web.
Poll a few people who do security work and ask them if they have acrobat or flash or the jdk installed at all, or running on pages by default. You'll hear about the same thing.
Even 5 years ago was a very different world as far as threats go.
I'd strongly suggest using an alternate PDF reader (apple, google, evince, sumatra) and using flashblock.
Having said that, I run both Flash and Adobe Reader (and Foxit for dubious stuff) on my normal machine. The number of 0-days exploited in the wild is not actually that big (I'd like to see stats here but I am not aware of any) and the odds of being hit by an 0-day exploit is really low. When people get owned through Adobe exploits, it is because they are not updating regularly.
But (as I'm sure you know) Adobe does have 0-days quite often and can take weeks to distribute a patch. The sep 14 cve-2010-2883 drop for example was being exploited seemingly quite widely by ~sep 20, and Adobe didn't push a patch until Oct 4. That's a pretty big window to be open to a drive by iframe vuln. Also, doesn't adobe updater take 7 or 14 days between update checks? It used to, at least.
The thing about not running them at all (or on opt-in) is it also mitigates some of the danger in update lagging. It seems a majority of the time when I touch someone else's computer they have an adobe product that's out of date and being actively exploited (on the internet) - even if they appear to try to keep up to date with the patches.
What methods do you use to determine if you're running hostile code? How often do you look? Do you check from another OS? Keep hashes of system files?
Let me expand on the theory that most malware hosts have absolutely no idea (and not just the dumb ones):
Once installed many threats actively evade AV, personal firewalls, and code signing requirements. Are you booting a livecd and checking hashes of the boot block and boot chain against previously saved values? What about the hash of your EPROMS?
I understand that sounds very paranoid - but advanced toolkits that attack the BIOS or boot loader are widely available. Are they only for juicy targets? TDL4 - an advanced threat that starts in the boot block and has used private 0-days - is engaged in the super spy thriller business of clickfraud. $10k will buy you a kit from Israel that inserts similar code into the system BIOS and is designed for non-techies to deploy.
Expecting to see increased resource usage? CPU, RAM, network speed are all far outstripping most actual application needs and the resources needed for a keylogger, afinity rewriter, ad inserter or similar are vanishingly small.
Expecting a signature hit in some security software? Authors check their own code frequently - when signatures get deployed that catch them they simply recompile and tweak until they're undetected again.
Expecting pop up ads, AV scareware, spamming activity or fraud alerts on your credit card? Some threats are like that, yes, but shrinking. Just as or more likely are threats that manipulate search results, add affiliate tags to big ticket items, slip paid SEO links into blogs, steal your banking credentials but decide you're too poor or in an inconvenient county or steal company IP/plans/etc for chinese, russian, french, korean etc. competitors - the impact of which may take years or never be identified.
Expecting unknown, suspicious or hidden processes? Hiding in plain sight is a common and effective tactic. Can you tell the difference between a game installed codec, a useful codec with legal clickstream collections installed by a torrent downloader and a codec that was installed by exploit and rewrites your network traffic? Looking at a process list how many are you positive were running last month? Can you tell if skype is loading a dll or so that it wasn't before?
Think you're an unlikely target? Odds are that's true. However, automated tools can be deployed against thousands of targets and if only one or two have something really juicy it was a worthwhile effort. Proprietary IP of almost ever type has some value to someone be it term sheets, source code, M&A data, business process, sales leads, P&L data etc. Could your SO think you're cheating? Smartphone malware sold for 3000 yaun (~$450) supposedly marketed to houswives was found running on 150,000 chinese phones - it real time tracks your location, records audio, video and pictures regularly or on demand, steals credentials and all email/im/sms traffic. If you're of no interest it's possible your next door neighbor is, or his girlfriend, or someone who gets coffee where you do.
20 years ago malware was made by hobbyists. 10 years ago malware was made by small independent businessmen and specialty concerns. 5 years ago malware was made by organized crime, corporate espionage and intelligence agencies. Today malware is made by private organizations with hundreds of employees and traditional office space, teams supporting major M&A lawyers, the FBI to execute wiretapping warrants, defense contractors, ad networks, energy companies, virtual currency resellers, intelligence services conducting broad surveillance on foreign populations and security services conducting broad surveillance on their own citizenry.
One reason you don't hear a lot about it is there are very few practical solutions out there to be implemented. Microsoft, Google, Apple, Oracle and Intel are all making inroads to various degrees but practically it is decidely a losing game so far. For the time being their profit margins depend on people not getting scared away. Law enforcement and Intelligence services that might have warned against such threats in another era are by in large too busy exploiting them.
I fully understand that this all sounds very tinfoil hat and extremist. All the examples given are real and happening to very real people every day. The threat model has radically changed - it may just take another 3-5 years for everyone to understand the new rules.
For the life of me, I can't think of a single reason why I would ever want to launch Reader by itself (and not by launching a PDF file).
The second time, I tried to open one with Foxit and was informed that I MUST use Acrobat, which I dutifully installed. This PDF was actually a browsable archive of OTHER PDFs.
We already have video files, and even streaming video. We already have zip files. I want to beg Adobe to stop the madness, but if they've already put an email server inside Reader, there is truly no hope.
However, if those PDFs are requested via HTTP, unless the bank gives appropriate caching headers I think Chrome is technically correct in re-requesting them: they might have changed in the meantime. (I assume it does the same with webpages when you save them.)
The fact that the bank gives you a URL you can only HTTP GET once does sound like very bad implementation on their behalf. Perhaps it's a cookie issue, or even a bug in Chrome itself?
Here is one example: You opened the front page of some news site a few hours ago and now want to save it. Since news sites change frequently you would save a completely different page compared to what you actually wanted to save if the page were re-requested when saving. This is destructive behavior! No browser should do that.
(I just tested what Google Chrome actually does. It does not actually re-request the page when saving.)
Preview is also pretty good though, it has nice gems like cropping pages. http://hints.macworld.com/article.php?story=200711012305556
Evince on Unbuntu has worked great for the past few years for me.
Actually, last time I updated Adobe Reader it came with a copy of McAfee something or another...
That was when I nuked all traces of Reader off my system. Not only is their software crappy, bloated, and slow, but it's also a crapware vector to boot.
If I were a dev on the Reader team, I'd be pretty depressed about my life - millions of people cursing your name, eviscerating your product in forums and boards everywhere, everyday... and they're right.
When you think about some of the most common reasons why people use software like Acrobat and Word (e.g. viewing a document, filling out & saving a PDF form, commenting on a presentation with a group), these are all things that should be easy to do online or on your mobile device. That's the vision we're working towards at Crocodoc: view and collaborate on any document on any device.
I've been using evince (or whatever it is that ships with Ubuntu this year) for years and never even considered that there might be a case where one would want to install a separate PDF viewer. Before that, xpdf was the standard reader and it was enough, too. Maybe Linux desktop isn't that bad all together.
However, I'm not sure there's a good way for Flash to provide that kind of seamless update experience in the same way. It's not an application in itself, so it can't check for updates with the consistency that a browser can, and when it does run it's always to immediately execute whatever flash content was requested, so there's less leeway for it to start updating itself in the background and potentially impact performance. Currently it pops up a window on startup every once in a while (I skipped it the first time and it didn't bug me again for maybe 2 weeks) and its maybe 2 clicks and 20 seconds of downloading. It's not Chrome-level seamless, but it's pretty damn good and I was surprised by how good it was compared to Acrobat and every other updater I've used in the past.