Is PDF as an attack vector such a widespread threat? I never payed much attention to them, assuming it's a document format that is relatively harmless even if it can include javascript.
This is an honest question, by the way.
PDFs are "harmless" on their own, but they are user-generated documents that conform to a complex specification. Viewing them requires software that parses them. These parsers are often written in unsafe low level languages.
The (in)security of unsafe parsers reading user-generated input is a tale as old as time itself.
While browsers are sure not without security vulnerabilities, I sure trust the PDF viewer within to be way more sandboxed than most standalone desktop PDF viewer applications.
If the vulnerability (which I assume was RCE) was in a web browser, then it's a major bug.
Yes, I understand this, keep in mind I'm a software engineer.
Let me re-phrase. It's understood that, in general, document formats are more or less harmless unless they execute macros/code, and even then, this code must be able to exploit the platform's vulnerabilities to be able to do harm.
What is different about PDF than, say, JPEGs? I don't know of anyone who would hesitate to open an image file on their work computer, yet they are also complex formats requiring readers (viewers) which are often written in unsafe low-level languages. Yet I have never ever head of someone recommending "be careful before opening a JPEG (or PNG, or whatever) file".
I'm assuming we are not talking about ye olde "PDF.exe" or "JPEG.exe" trick here, but actual vulnerabilities in document files (not just renamed executables).
Both JPEG (or any other ubiquitous image format) and PDFs are nontrivial formats. And both have their fair share of CVEs (the list of JPEG vulnerabilities is also pretty long, based on that CVE database).
Something that sticks out to me is that JPEG (and most other image formats) is basically a header followed by a large blob of compressed image data, whereas PDF is a mixed-media format combining images and other multimedia, fonts, and a PostScript. And of course, we know that PDFs have all sorts of other crazy fancy features like forms and embedded JavaScript and digital signatures. Based on these facts alone, PDF features is a superset of image formats, and certainly by quite a wide margin. And more features means much bigger attack surface.
There's also another practical consideration of how users generally interact with these formats. Users interact with images primarily through browsers (or Electron-based software), which are sandboxed and have very well-funded security teams behind them. User-uploaded images to image hosts are often re-encoded (and sanitized as a side effect). Notable exceptions I can think of are loading images from a camera (generally a trusted source; and certainly there must be plenty of vulnerabilities in RAW parsers, but people almost never share RAWs) and iMessage (...which is a thing). It's very unusual for a user to be forced the view the image outside of a browser.
PDFs are a different situation: while browsers have well-sandboxed PDF viewers these days, they intentionally implement a subset of PDF features (I think forms is a big one left out, and signatures). You can imagine how easy it is to convince a user that need to download the PDF to disk and open it with Adobe Reader so that they can digitally sign a job offer. I'm aware that DocuSign exists, but I don't think it's ubiquitous enough that every user will wonder "hmm why am I being asked to sign with Adobe Reader instead of using DocuSign".
I hope that better answers your question.
Unless this was a zero day, but I would have assumed the article would mention that fact ..
"Hey, you need a PDF viewer with scripts enabled for the digital signing.. can you install Adobe XXX?" would be a good line to get the mark to use a less-than-secure PDF viewer.
But also, since it was the North Korea hacking group, I'm not ruling out a 0-day... hopefully more details will come at some point.
do you at least dual boot?
have a separate user account?
I guess its fine as long as your computer doesn't have the credentials to the company slush fund.
Friend of mine I traveled with carried 3 macbooks with her: school issued, work issued, and personal. They had different software licenses tied to the machine, whadyagonnado?
When I was on the road all the time I also had separate phones to ensure I never got stuck with a dead phone.
Counterpoint: I've been completely and utterly allergic to opening anything personal from any company system for longer than that.
I get MDM profile updates from IT on my work machine. One time they auto-installed a cloud backup service and sent out a company-wide email after they already did it. Something like: “Now nobody has to deal with lost data. You’re welcome!”
Huge backlash from employees on that move. But I get both perspectives. These are work machines, and a mundane accident with the equipment shouldn’t incur significant losses to the business.
But apart from the potential loss of personal privacy, it feels wrong. Especially so, when you’re looking for other jobs.
I know they monitor some things because they are upfront about it: Chrome says it's company managed, and there is an antivirus and some VPN software that must be always one.
But why do I care? They don't crack down on us, and know everyone plays games or visits non-work-related sites, watches YouTube, or even do homework on these laptops.
I'm not going to work for the competition using the company's laptop, so why worry?