Security Flaws in Adobe Acrobat Reader Allow Gaining Root on macOS Silently
rekken.github.io
rekken.github.io
It's a shame because as someone who has a lot of interest in design, photography, etc. I acknowledge that they create some very powerful tools. I still miss Lightroom. But I'm just not willing to give them this much control over my computing environment any longer.
From memory, in addition to sticking some pseudo-randomly named files in /System/Library, /Library, and -/Library, it would place a file in the root directory of all hfs+ volumes with xattrs set to hide and write-protect the file. Installers would then look for these files to check licensing status.
At the time, this was a fairly common trick with pro/prosumer proprietary software.
[0]: https://en.wikipedia.org/wiki/FlexNet_Publisher#Issues_with_...
What's nice about their subscription model is that there is no sunk cost when giving up. It's $5/month and you just stop paying it.
(I switched to Affinity Photo for editing but never found anything I liked for organization/library management. I just copy files around now. It ends up being OK because about 50% of my photos are from my phone, 25% are from a DSLR, and 25% are from film scans. Lightroom never helped me with phone or scanned photos, really, so I didn't give much up. Would still like some central self-hosted photo collector, though. Maybe Perkeep is what I want.)
Don't they try to get you to make a year commitment? I remember spending about 30 minutes with someone at Adobe getting them to cancel it when Lightroom was too slow to use on my Mac at the time (which had been more than fast enough for Aperture). After the second or third time that I told them I wasn't going to buy a new computer just for the privilege of running their software, they agreed not to charge a hefty early termination fee.
Be careful though, some card issues will forward the new card details on to (some?) services you have a payment agreement with.
Adjustment and FX layers don't translate, as well as some compositing and blending options.
For anyone who tries these programs, many of their developers and users hang out at https://discuss.pixls.us/
I really, really wish that was the case, but there's no competition for Photoshop, Illustrator and InDesign.
Even after years of destroying their software with cloud crap, useless home screens, changing 30 years of muscle memory just because, all while adding a WebKit and Node.js instance for every new dialog box…
…nothing comes even close to any of those tools.
Pro software is hard.
I'd be fine with cloud subscription software if the TCO ended up being lower than buying a boxed product, but it's seemingly more expensive than it ever was. $10USD/mo doesn't seem bad, but if you're comparing to a two-year, $200 upgrade price, then you're spending $40 more and can't opt to skip the latest menu reshuffle.
If you assume the answers to these questions are "no", what is your response to GP?
Photoshop puts like 5 folders in Utilities folder for no reason in macOS and runs bunch of daemons (which apparently can be a cause of bad vulnerabilities) and is dog slow in performance compared to a modern alternative like Affinity Photo.
Market dominance surely puts customer satisfaction to the end of the line.
It was a small thing. With Photoshop I can open a .PNG or .JPG file, edit, and pick Save (cmd-s/ctrl-s) and it saves back to the .PNG/.JPG. If I added layers or something I can press Ctrl/Cmd-Shfit-E to merge it all down then Cmd/Ctrl-S. This means the workflow is fast.
Affinity has no such workflow. You can open a .JPG but you have to follow the export workflow to save back to .JPG which is tedious.
I had say 150 files to edit. I reasoned my time was worth more than $120 to pay for a current version of Photoshop than to put up with a slow workflow.
I also recently tried to use Affinity's batch processing features but they aren't ask good as Photoshop's. I think they are trying to be helpful in that they scan all the photos before you start so you can see what they are going to operate on before you pick "Go". Unfortunately that's not actually a good flow if you're going to process 100s or 1000s of files. Instead of getting stuff done you have to wait for Affinity for several minutes while it goes and makes a thumbnail of all 100 or 1000+ images just so you can then click "Ok, do it!"
That is 9 background processes for an app I haven't used in a week.
Unix gives you just enough rope to hang yourself - and then a couple of more feet, just to be sure.
[0]: https://www.azquotes.com/quote/1293001I really like these kinds of projects. NixOS and Fedora Silverblue are a couple others.
my Fujifilm XT2 was stolen during a trip to Europe last year and i've switched back to Nikon since the battery life of the mirrorless was disappointing (due to the EVF).
now i have some Fujinon macro glass collecting dust as rather expensive paperweights :(
Photoshop - https://affinity.serif.com/en-gb/photo/
Illustrator - https://affinity.serif.com/en-gb/designer/
InDesign - https://affinity.serif.com/en-gb/publisher/
50% off each product (one-time purchase with updates, no subscription) too during the COVID pandemic.
Won't take you long to adjust at all as they're very similar and the apps are more lightweight and faster than Adobe's products have ever been. Also iPad versions if you want to edit on a tablet.
Been using Affinity Photo for a while now as an alternative to Photoshop and wouldn't look back.
I imagine it's not so simple in the graphic design world, and without such a simple interface that everyone can agree on, it's much harder to create standardized plugins that everyone can use.
If you think about it, much of the original point of desktop-publishing software, back when OSes could only natively use bitmap fonts, was that desktop-publishing software could do WYSIWYG layout and preview-rendering for vector-font "instructions" (e.g. PostScript.) Fonts were indeed a lot like VSTs!
For windows I'm done with adobe. I'm not looking for an alternative to photoshop to stick with the company that made me leave photoshop.
Pathetic. I tried to get a refund, oops buying through Apple's App Store makes that impossible.
RAW files are more a lightroom thing from what I've heard
We have to run an older (years older) Premiere Pro on our Macbook that somehow can edit them without any issues at all, with a newer up-to-date version on our much faster PC for recent videos. We've tried transcoding and various things like using an older version on Windows, but nothing else seems to work.
Then the other day I had to stay up until 3am because a video being edited just stopped saving with an uncaught exception and no useful information on both versions. I finally figured out that some effects like loudness and reverb control applied to the sound channel had become corrupted (after noticing it would save with sound off, then fiddling with the clips for another 2 hours having no idea what I'm doing).
Ever since the Flash days I've been wary of their software quality. Paying over $800 per year is fair if you're earning money and the stuff just works, but they don't seem to be holding up their end of the bargain.
https://www.blackmagicdesign.com/products/davinciresolve/
For transcoding your footage nothing but the best, FFmpeg:
However, if you don't need the absolutely full array of switches available in FFmpeg, Ive used the fork FFmbc to get into standard broadcast formats with easy presets:
I've got ffmpeg and Handbrake for transcoding but for some reason they both caused issues in Premiere Pro still (audio sync, choppy/repeating footage, etc) on those files. I'm not very experienced, so that might be on me, but it didn't seem to happen outside of Premiere Pro.
It's a mature product at this point and have had a good experience for years now.
At least the PDF reader in Firefox is a Javascript App that runs in a Browser sandbox and doesn't support 99% of the crap a PDF can do.
I agonized about installing Acrobat Reader, but Suspicious Package says it wants to run 88 install scripts. I don't feel like tracking down that much malware when I uninstall it after filling out a form.
Go Foxit!
Readdle just needs to add exact phrase searching/finding; then it'll be wholly better than Preview imo.
You can read more about Preview's struggles with annotations here https://eclecticlight.co/2020/04/07/how-preview-mangles-anno...
The app offered to convert the PDFs if I would email them to PDF Expert, and suggested Adobe products as an alternative. Nice try, but Foxit displayed the PDFs and allowed me to fill in the fields.
While you're at it, please ask the user whether he wants to sync at all during installation. By default it should not sync.
I only have Creative Cloud installed because I am a Lightroom and Photoshop user. I use the sync feature in Lightroom but do not need another generic file system cloud sync.
1. The CC app itself gets updates. If you're a purely Illustrator user you might not notice (or use! which is ok!) the features we've added, but it now has the ability to add custom fonts to your Adobe account, we've added new tutorials, and community features, support for CC Libraries, and a new unified search. One of these new features is notifications, which is #2.
2. Our notifications can be a little noisy, especially if you're not a frequent user. In the Creative Cloud app, you should see under Preferences > Notifications, the ability to select which notifications you want. So, if you want to disable App update notifications, you can.
3. On top of the features, there are some update/sync processes that go on in the background that won't function. Our current messaging just says "pending installations" which doesn't cover it all and we've heard a lot of feedback from users internally and externally about it. We're going to make that message more tailored to anything that's actively going on, and if there's nothing, allow you to close the app silently. To double check that nothing is actively installing, you can check the cloud icon in the top right to confirm. If there's nothing there, you can close it with confidence that it isn't installing an update.
Hope to get these enhancements out to our user base soon. Thanks for your feedback! Please note, we do actively track anything we see on our User Voice (http://creativecloud.uservoice.com) and try to engage on social media, in case you'd like to keep giving us more feedback outside of HN. Thank you!
2) See above
3) Again, see above. I don't want anything to work in the background.
I’ve been meaning to get out of the adobe photo software ecosystem, maybe this weekend is the time to find the right alternatives. Save a few bucks per month too.
No freaking app should ever be given this much or any control over a user computer. Every app (except system maintenance tools and other apps which genuinely need full access to fulfill their very purpose) should be constrained within a directory meant right for it + the files the user wants them to open.
Hopefully I can move to the KDE video editor for NLE, and Pixelmator is already better than Photoshop IMO. The only other two I need to replace are Lightroom and After Effects. I think the latter will be hard/impossible.
It's pretty much spyware behavior at this point. Like with certain video games DRM, Adobe software is one of those cases where the pirated version is actually better than the paid one.
Qubes OS says hello.
This seems totally unsuited to desktop non-enterprise use.
PDF Export does a good job of filing in the gaps.
Editing/Form Fill/etc: Nitro[1]
Signing: Nitro[1], HelloSign[2], airSlate[3], Smallpdf[4] (limited functionality)
I only wish Preview would do two things:
- open files in "maximized" view.
- when opening a file, Left/Right arrow keys don't let you navigate the pages. Instead, they move the current page a few pixels left/right! (they work like horizontal scrollers)
What Preview doesn't support is JavaScript, as far as I can tell, so it can't work with "smart" PDF's, e.g. that will do calculations for you.
Is that what you're referring to? Or I'd love to know any specific issue you've run into with form fields.
EDIT: I looked into some of the PDFs again and it seems I had been wrong. Not sure what they use but it doesn't seem to be js.
EDIT EDIT: But I found other forms which where affected see my response below.
I've encountered JavaScript-heavy PDF's before, but which were obviously so. (Automatically calculating values for one form field based on another, generating QR codes, etc.)
I've never come across a seemingly "normal" form PDF but which secretly used JavaScript for normal things like form filling, so that normal form-filling tools didn't work. I don't understand why the normal PDF type-in-a-text-box tool wouldn't work.
Have you actually come across this? Can you point to any examples?
You can be sure that even Adobe won't add JS for forms with plain text fields. ;=)
EDIT: I looked into some of the PDFs again and it seems I had been wrong. Not sure what they use but it doesn't seem to be js.
Sorry about this.
For example I found following:
`/JS (if \(this.getField\("inst1"\).value == "bitte auswählen"\){\r\nthis.getField\("Hinweis"\).display = 2\r\n} else\r\n{\r\nthis.getField\("Hinweis"\).display = 1\r\n}\r\n)$ /S /JavaScript`
This (in the given PDF) causes a "notice" overlapped on top of other form fields to disappear once the first multiple choice field was selected.
So if you try to fill it out without JS some form fields are not visible (but selectable by tab). Luckily it's not included in prints.
Had to install the linux version of Adobe, which is many years out of date now.
Worse many "office" people which create PDF's with form fields use Adobe tools, so they never see that what they hand out to thousends of students isn't working with >90% of PDF viewers....
https://en.wikipedia.org/wiki/XFA
Further reading: https://eclecticlight.co/2019/06/18/pdf-without-adobe-23-the...
For stuff like sign a PDF and form are not things normal people need to use.
- it is plausibly open
- there are enough edge cases that your tool is the only one that does it reliably.
This is similar to doc format - apple tools or openoffice can open it, but screw it up for everyone if they try to write it.
There is a wonderful rant about another adobe file format .PSD in this code here:
EDIT: I mean sign with a certificate, not add an image. Personally I would prefer to not have any adobe software on my mac.
There will be some obvious trends, but I suspect there will also be some surprises.
So I sign all signatures on a lease with Preview except for the very last one, which I did using a digital signature under Adobe Reader. it was a self-signed one certificate but the goal is still to have the other person feel comfortable with doing a contract over email than in person anyways.
I, too, prefer Preview to Acrobat. But part of my workflow occasionally involves copying text from a PDF to create a web page. Preview cannot be counted on to reliably or accurately copy that text. It seems to have particular problems with the letter "f" when next to a letter "s," in addition to other flaws.
Acrobat, on the other hand, always copies the text correctly.
Aside from this one use, however, I always employ Preview because otherwise it is far superior.
That's such a weird bug. I wonder if Preview is trying to be too cute with "less common" stylistic ligatures. Try some of the other ones mentioned in Wiki: https://en.wikipedia.org/wiki/Orthographic_ligature#Stylisti...
That’s your answer. Apple being Apple either have no lower-res screens to test on, or once again have decided to force the industry forward.
https://www.howtogeek.com/358596/how-to-fix-blurry-fonts-on-...
I have similar feelings about their office suite. In general their add-on and utility software is just great. I'd miss all of it on any other platform (and do, when I use those—yes, even the file manager, which is still less crashy, less prone to weird interface bugginess, and more consistent than any featureful equivalent I've used on Linux, and I've used... oh, all the big ones, over the last 20 years, and I don't find it any worse than Windows Explorer, aside from preferring some of the latter's hotkeys) but of all of them... yeah, Preview may be #1, which was not something I expected when I first started using OSX/macOS about 10 years ago.
https://en.wikipedia.org/wiki/Quartz_2D
https://en.wikipedia.org/wiki/Quartz_(graphics_layer)#Use_of...
To give a few examples, there is no JavaScript interpreter in Quartz (https://www.adobe.com/devnet/acrobat/javascript.html), nor does it have 3D graphics rendering built in (https://helpx.adobe.com/acrobat/using/displaying-3d-models-p...), or a Flash engine (https://helpx.adobe.com/acrobat/using/flash-player-needed-ac...; this has bee removed from the Acrobat install, but used to ship with it)
To support PDFs fully, all of that would have to be implemented on top of Quartz.
The software is flawed even beyond security issues but for creating or editing PDF files there is not much competition. (There is some and I’ve used that too and it’s mostly worse. It’s a hard problem apparently.)
And it's a dream to use on a touch screen. Trying to open the same high quality/density PDFs in Adobe (even just the reader) is an unresponsive nightmare.
I don't even understand how there can be such a significant difference in performance when Adobe created the format....
Where does this complexity comes from?
the better idea is to segment out what exactly you want to use it for and use a specific file format for it.
IE. Do you want vector graphics? Do you want document signing? Do you want to just do printing of a text only document? Do you want to encode picture bitmap information? Do you want to show a document online? Do you care about colour spaces? Unicode? If unicode, what kinds of unicode? Font rendering? How do you like your glyphs and ligatures to look?
The spec is so big because it has like 10-20 purposes.
* All rendering done by raster chunks that get pieced together. If the pdf has a photo in it, it would be used as its own raster chunk.
* No special font rendering, but an idea of where text is so it can copy paste as though it is selecting text. Really it just outlines parts of the pre-rasterized text. Potentially text could be rasterized per letter for compression, but no dependency on font rendering abilities or local fonts should exist.
* No vector rendering, but the ability to select a rasterized vector image chunk and save as either .svg or .imgType.
* The ability to click html links
* The ability to write (with non-special fonts) into areas as to fill out a form
* A basic Regex (limiter => error/warn message) for form fields
-------
I think this would be enough to cover everything I've done with a pdf. Tests to pass:
1. Looks the same everywhere
2. Can click links (great for resumes)
3. Can view photos, and select them for download
4. Can fill out forms
5. Can copy text
6. ???
-------
Obviously size would be an issue here as you get to larger documents but I suspect compression could be made efficient enough to be just fine in most cases.
What I want is basically an entirely static (no javascript, forms, media elements, etc) copy of a web page, with a logical deterministic rendering, and a fixed page size (no reflowing). Basically, if you took a web page and printed in color on pieces of paper, the HTML + CSS that describes the stuff shown on the piece of paper is what I want a "portable document format" to be. (Along with a set of rules that specify exactly how that code should be rendered.)
What I want in the spec is basically dictated by that:
* vector graphics: yes, SVG is supported in all major browsers. https://developer.mozilla.org/en-US/docs/Web/SVG
* bitmap support: yes, let's start with PNG, JPEG, etc, and updates to the spec can introduce new formats
* color management: yes, should be required by the spec
* unicode: yes, we can probably be UTF-8 only at this point?
* font rendering: deterministic; make it part of the spec. Fonts should be embeddable in the document. Ideally the font rendering for the end users should be as high quality as possible (this is quietly one of the things PDFs are already doing very well).
* glyphs / ligatures: should look exactly as they are determined by the author of the document. The spec should allow for the full use of the capabilities of an OTF font.
I think this probably covers the stuff 95% of people want from 95% of their PDFs, and it's vastly simpler than what's currently in the spec.
Honestly, PDF/A comes pretty darn close to getting there. The most recent version allows embedding arbitrary files, however, and there's lots of annoying cruft from the PDF format. (Renderers have to support displaying embedded XML forms, for example.)
I do like the spec a lot and have actually used it to track down bugs in files before. It's very easy to follow if you're just looking at certain operations.
The spec is also partially used for specifying and bootstrapping a publishing and printing system on its own, so it's like JS + cups + PostScript + Unicode + font rendering all combined into one mega spec.
Why on Earth should Acrobat have any part even running as root? This design seems detective.
What makes Adobe’s apps so special that they do need privileged access?
Some applications do a check on start-up to see if there is a new version available. This is a lot better. Why isn't this good enough for Adobe?
`sudo dnf -y update` is such a time saver
And things are better and worse depending on your Linux distro (ref: Snaps in Ubuntu).
The problem is a lot of useful software isn't (for good reason) available on the App Store.
Infuriating. I just want to use the software not randomly be interrupted throughout the day as one of the 50ish applications I use on a regular basis decides to do a "minor bugfix and localizations" update and thus totally interrupting what I'm doing. Oh and after it does its update, the document I double-clicked on isn't opened or there is a FTUE showing me "exciting updates."
Most modern software sits there idle all the time, why not do this nonsense in the background? Why do you need to interrupt me at precisely the one moment I actually want to use you? (This is especially annoying of gaming consoles and other "appliances")
Modern software is actively work-hostile.
My favorite recent example is DBeaver. The update to v7 destroyed their own SQL directory which had saved in it a SQL scratchpad document containing little SQL snippets I had written over the last few months, some fairly complex that I ran once or twice a week. I had restarted DBeaver dozens of times over those months, my SQL snippets returning each time ready to be run...
Then one day, like an idiot, I clicked the "Update" button and all that hand-written SQL was gone, like tears in the rain. Gee, thanks DBeaver! I love v7! Tell me more about your new features! I love having my careful work destroyed for an update...
Fuck the perfectly functional updater built in the Mac store.
It doesn't even have to be like this though. Why not a simple notification directing me to the download? I guess reduced friction but is that really it?
The problem is that, if every app decides to use its own updater, there's a good chance that your internet line could get saturated when everything decides to update at once (especially when this awful PDF reader is 180MB). A system-wide updater avoids this issue.
Nowadays self-updating software, from the user perspective, can be as easy as using Touch ID, so why Adobe and other companies are still messing around with complex, insecure and fragile autoupdate permission bypasses is beyond me.
That 15% recurring is not too much to spend to have a secure system without all the malware adobe installs on your laptop. Disgusting company.
Could you imagine if other engineering disciplines had the kind of liability protection that software companies do?
Edge, Chrome, and Firefox all have built-in PDF readers. macOS's built-in Preview app can read PDFs. Just counting those four solutions, most users already have at least two PDF readers on their computer without installing Acrobat, Nitro, Foxit, or whatever.
Stop installing dedicated apps for reading PDFs! They are bloatware meant to encourage users to buy PDF editors which most will never need!
Obviously those are all readers, so they are not able to edit PDFs or create them from scratch. However, neither can Adobe Acrobat Reader or most free PDF bloatware.
It's also Free software & respects data/privacy.
Don't like KDE-based software? How about Evince, Skim, Xpdf, gv...
I say, stop moving everything to the web browser!
Actually... stop using OS X altogether. The infamous High Sierra root-login vulnerability is harrowing enough and I'm gobsmacked as to why folks didn't abandon Apple at that point.
I've been happy, gainfully employed, and quite successful in all ventures using Debian + free software, exclusively, for nearly 8 years. I'm not the only one. Happy to help anyone migrate should they have challenges!
- Highlight
- Leave expandable comments
- See the page thumbnails
- Have access to area select/table select
- Configure my pdf reader quite a bit
I spend a lot of time reading .pdfs because I'm in grad school right now. Using Okular is way more convenient than trying to use browsers. This is not a strange use case at all, many people who frequently read .pdfs have the same needs.
And it's clearly not trying to sell me on a pdf editor, because it's not related to a paid editor. Or at least I'm not aware of it, either way is fine by me.
https://www.liquidtext.net/liquidtextadeeperdive
(To a sibling comment, just stop using MacOS: it's not a rule, but the usability and craftsmanship sensibilities that create software like LiquidText tend to cluster with the usability and craftsmanship sensibilities that appreciate MacOS.)
I was really hoping to find a good application for reading & annotating PDFs on Linux behind this link.
:(
You know how some people make websites? Well, what if instead of a website, we make a pdf that you can upload a document to and then click a submit button in the pdf. And for good measure, lets make it so it only works in Adobe Reader's internet explorer plugin.
Welcome to the Bank Secrecy Act e-filing system brought to you by the united states department of treasury.
Whether that preference will get changed back to edge in a feature update is another story.
Basically you use it by uninstalling any existing Adobe Reader installations, installing the customization wizard and then downloading the enterprise installer for Adobe Reader[2] and extracting it with 7-Zip[3] (or the commands Adobe provides in the documentation). Then, you open the msp file in the wizard and customize your options. Finally, you save the changes and run setup.exe in the directory of extracted files. Once you're done, you can uninstall the customization wizard.
There is also a version of the wizard for macOS[4], but it seems to be far more limited in terms of what can be configured through the UI, and most of the configuration has to be done by manually editing plist files.
[1]: https://www.adobe.com/devnet-docs/acrobatetk/tools/Wizard/in... [2]: https://get.adobe.com/reader/enterprise/ [3]: https://www.7-zip.org/ [4]: https://www.adobe.com/devnet-docs/acrobatetk/tools/AdminGuid...
If you have a mac, you might want to know what version of Adobe Acrobat Reader DC is necessary to have the patches.
The OP doesn't appear to say? The CVE's referenced (which ordinarily would say the patched version I think) all still appear to be protected/private, at the point I write this.
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9615
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9614
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9613
My Mac does have "Adobe Acrobat Reader DC" on it. [btw, when did "DC" become part of the name and what does it mean?] If I open it up and choose "Check for Updates" from the "Help" menu, it does say "Adobe Acrobat Reader is already up to date." I'm not sure exactly when/how it would have been updated though.
Under "About Acrobat Reader DC", it claims to be version `2020.009.2063`. It does not include a release date with the version.
Am I up to date and protected? How would I know?
It took forever. When I was done with the project I “uninstalled” everything and then deleted every single file and folder from the list and manually poked around to see if there was anything lurking that I might have missed. I thought for sure I’d won.
About a week later I got a notification that Adobe Creative Cloud was requesting keychain access.
I’m convinced it’s un-uninstallable.
https://labs.adobe.com/downloads/acrobatcleaner.html?PID=408...
https://helpx.adobe.com/creative-cloud/kb/cc-cleaner-tool-in...
Except Acrobat lets you modify PDFs. If you're trying to send someone something that they cannot usefully modify, you're kind of doomed from the start.
Acrobat won't let the Average Joe modify a password-protected PDF. Neither will Preview. There are ways around it, but for 95% of the people receiving a PDF, it's as good as locked.
IANAL but I seems like for many non-software products there would be legal repercussions of they caused damage or had other issues. Is there any reasonable way to apply or morph those kinds of laws to software? Ideally it seems like it would be nice if the incentives changed so running all these services in the background is too big a legal risk and they stop?
I suppose that doesn't answer the question of whether pdf.js specifically runs inside one of the sandboxed processes, but it seems very likely that it does.
I use Xournal for editing PDFs. Would love if evince could do more than just annotations.
I've lost track of the services they have scattered around my Mac that are running silently, doing things I can only hope are not malign.
Just today I was debating whether to move back fully to Preview or keep Adobe's bloatware on my Mac, and I think this made the decision for me.
Given that Adobe has generously scattered a bunch of random stuff around my Mac, could one expect something like AppCleaner to find and clean out all the bits and pieces, or is that too much to ask?
The only way to be sure is to start from scratch.
From wikipedia: "to present documents, including text formatting and images, in a manner independent of application software, hardware, and operating systems."
I wish W3C would come up with container format for a HTML webpage that would pack all assets and run in any standard browser.
PDF was, in relationship with printing.
I think this is clearly a quality people want (whether they "should" or not), so it's unlikely they will stop using PDF unless there's another thing that can provide that quality. I don't think HTML is the right avenue for it.
I would say the ePub format comes pretty close to what you are asking for though, a container format for HTML webpage that would pack all assets and run in... well, standards-based software from several different sources. I'm not sure if browsers will actually display ePub or not? They presumably could fairly easily if they had a desire to, since it's all standard html/web technology. ePub is not W3C maintained though, I don't think.
https://en.wikipedia.org/wiki/EPUB
It has moved in on PDF territory in some limited areas -- mainly ebooks of course, the use-case it's focused on. I think this is because it turns out "pixel perfect same everywhere" is a clear DOWNSIDE for ebooks, you want them to be formatted properly for your device's screen size, not have the same page size everywhere. So while PDFs were sometimes used for this, it works poorly enough for the user that another solution was demanded. (and thankfully we got an open standards one). Most uses of PDF still work "good enough" for most users (certainly not all; there can be accessibilty probelms). Even if it's a nightmare under the hood, PDFs generally work "good enough" for most developers too (again not all). It's a lot of investment to reproduce to replace, it would require popular use cases failing hard probably, with money to made from serving them better.
If you can answer positively to the first question, burn your computer now.
Flash had many security issues and that was also a significant motivation for its "deprecation".
But it did not have to be that way. Now, the same is happening with Adobe Acrobat.
I mean there are some special software where it still makes sense, but Adobe software clearly doesn't belong into this category.
I don't even use it that much, only for official stuff and such that requires it
I mean you can try to uninstall it. But apparently it comes back.
So it'd be immensely difficult to try to retrofit the kind of system that would be needed to give users more control over this sort of thing, and impossible/very heavy to do so in a way that wouldn't break a lot of stuff without developers updating. It's a genuinely tough nut to crack and involves some trade offs. Apple's chosen decent-in-principle solution is to harden the base default system pretty heavily and have a curated ecosystem (the MAS) that they nudge users into by default, and where they can flat out ban this kind of thing. Ideally users who opted for other channels would know what they were doing.
The big problem is that the MAS fucking sucks in a ton of unforced ways (like no update pricing system), and is also far too limited in many others (from non-Apple source options to single safety levels). So in turn a vastly higher percentage of users than would be ideal are forced to turn elsewhere for a lot of quality software even from small indy players. The many bad parts relieves pressure on lazy/bad developers to deal with parts that would be genuinely good. That's life with Apple sometimes though. They're bad at multitasking.
It handles most things you need for a pdf that you can do in reader.
I fill out forms in encrypted PDFs all the time with Preview, never had a problem.
I've encountered PDF's that simply don't work in Preview by design -- as far as I've been able to figure out, Preview won't run JavaScript embedded in PDF's for instance.
But all my experiences with filling out forms, makring up annotations, and all that jazz has been totally on par with Acrobat Reader. The same tools are present and all seem to work generally the same way.
What specifically have you run into that is poor in Preview?
Every other program shows the tax PDF forms as empty yellow pages. It's by design.
I assume it has something to do with being a "smart PDF" which generates scannable QR-like codes based on the numbers entered.
But, but: how is it even possible for a user-mode application to break the OS security? It must be due to a flaw in the OS, right?
Getting you to open PDFs and Office files is one of the primary ways in which your computer is taken over by hackers. They may send you an attachment or a link by email.
Other than memory safety issues, you mean?
Just run-of-the-mill TOCTOU and poor validation.