PDF Tool – Modify PDFs in the browser without uploading
pdftool.org
pdftool.org
When I decided on a local html for the app, I wanted something that did not require installing a language like python, did not require installing, and would work on Windows and Mac.
I'm not really sure what the solution is, but I'd love to be able to navigate to a site like that and know that it's not uploading my files somewhere, without having to take your word for it.
One thing that seems worse with software-on-a-webpage is the risk of malicious behaviour getting added later (this is also possible with non-browser software with automatic "updates"): you could mitigate it, if you trust or have verified one particular version of such a webpage, by saving the HTML file (put it in a Dropbox folder say) and opening the file (maybe with network disabled), whenever you need to use it. But then you lose the advantage of "don't have to install anything"; it's a trade-off.
I have been looking far and wide for a tool that replicates Acrobat's /fill and sign/ feature, allowing me to fill out NON-form-fillable PDFs.
Something where I can fill it out, save, and then open up later to edit and add/remove previous additions.
Adobe as a business, their pushiness about creating an account and the fact that they bundle McAfee's shitware with Acrobat never sat well with me, so I'd love an alternative.
Surprisingly there's a few decent options on Android, but nothing worth while I could find for Windows or Linux.
Maybe someone here can help a guy out with a pointer?
It's available for PC, Mac and Linux. (While the Linux version isn't as full-featured, I'd expect/hope all the versions have these 2 features...though I see that the feature-matrix on their website shows the Linux version doesn't have the Form Filling feature that the other versions have, FWIW, so it might lack one or both of the features I've mentioned).
The Fill-and-Sign feature is accessible from the Home tab -- there's a tool right end of the ribbon called "Fill & Sign".
The text-typing feature is also accessible from the Home tab: you choose the Typewriter tool from the ribbon, move the cursor where you want the text to show up, click there, then start typing -- the text will show up in a faint box (which disappears when you e.g. click somewhere else).
Later, you can click the Typewriter's arrow cursor on the text and the box will reappear -- you can then delete the box and its text, if you like, or you can double-click inside the box and get a text-cursor, which you can use to delete/add text.
I've used the Typewriter a bunch -- it works pretty well. (I think I've used Fill & Sign in the past, but not as often).
Can we save this page as .html file on a local folder and run it from browser -- never triggering the firewall / websense blockers etc?
I am not sure I understand this though:
> i just created an account for you :-)
( I was wondering if you meant you created an account on your app for me :) )
More context always helps. I guess another (lengthy) way to write that - can be - “I just created my HN account to post this comment”.
Not paranoid but just want to know if this tool can be downloaded once and run from browser forever -- without having to disable internet.
Does it not generate any network traffic at all - zero - even when there is internet connectivity available? Whether to the home domain or otherwise? Even telemetry?
You can turn off Internet for a single tab through Chrome's dev tools. F12, Network, change from "No throttling" to "Offline." Would be a bit annoying to do each time you use the app though.
Unfortunately not aware of a quick easy way to cut off Internet to a single tab in Firefox, but if you're fine temporarily killing Internet access to the entire browser (all tabs), you can do Alt > File > Work Offline. With the keyboard shortcuts (Alt > F > K) it's actually very fast to do.
It would be nice though if you opened a local .html file if it by default was cut off from accessing the Internet until it asked for and was granted permission by the user, much like GPS, webcam and mic use are. Would be much more convenient than the two options above (which require you to remember to do that each time you use the app.)
EDIT: we also use google ads since a few hours, to cover hosting expenses (1 ad on the page, should be enough for this small site)
Web applications are sandboxed, available on almost all the platform desktop and mobile and does not require installation.
I have a perfect png signature with transparency, but there's no way to import it.
https://support.apple.com/guide/preview/annotate-a-pdf-prvw1...
Page addition: drag a page from another PDF sidebar into the Preview sidebar
Merging: same, but for a whole PDF
Encryption: File > Edit Permissions > Require Password to Open Document
Decryption: If you have the password, then the same flow
Redaction/Markup/Signatures: All from the Markup menu
https://github.com/pdfarranger/pdfarranger and https://gitlab.com/scarpetta/pdfmixtool for such tasks.
They also have flatpaks available on flathub, which makes it easy to install + keep updated.
And it's open source as well: https://github.com/torakiki/pdfsam
Sure you can do it with Pdftk (or stapler these days), and a mish-mash of pdfinfo, Imagemagick and so on but the GUI programs mostly seem pretty bad offerings considering they're a fairly thin shell around library operations.
It’s free and does not require an account (I don’t like websites that force you to sign up to do anything)
Disclosure: I’m the solo developer behind it
You can add (“merge”), remove, delete pages, which is technically editing.
You can annotate the document by adding text, pictures, signatures, checkboxes as well as fill PDF form fields: unfortunately as you noticed you cannot “edit” existing text.
(I initially used the term annotator but it confused people so much that I changed it for edit and editor)
Adobes OCR can't handle a simple black-white tax document. To say nothing of OCRing scans. God help you if one text field wasn't recognized, because you sure as hell can't add the missing field.
And handy functions like "combine two PDF pages into one" (for example, combining front and back scan of something) are always easier to do by Googling than by using any software, even when you pay for it.
For example, I want to have a “check” in a form by clicking, not by dragging an “X” onto the box.
Since CoreGraphics on MacOS has fairly rich PDF support, Preview can do some degree of PDF manipulation: reorder pages, delete pages, insert pages, rotate, crop, annotate, etc.
> Ah I see what you mean, I was talking more about “editing” in the sense being able to fill all kinds of form entry and edit them and other text.
> For example, I want to have a “check” in a form by clicking, not by dragging an “X” onto the box.
Maybe, fortunately, most PDFs I consume are the reading kind.
It's meant as a scanning tool but works just fine without scanning just drag and drop a pdf on it.
It doesn't do in-page editing or annotation, it's "one layer above" that.
It's a crazy timeline we're on.
Per Wikipedia, PDF is a standard that was originally developed by Adobe. It was a proprietary standard for ~15 years before it became an open standard.
Nowadays, the relationship between Adobe and PDF is like Google and Chromium. Other PDF tools are playing catch up, but it’s en enormous amount of tedious work that mist would only do for a good paycheck, which is hard to find outside of Adobe.
Preview doesn't show the values I put into the fields in Chrome.
Also kinda unrelated but also worth mentioning, if you have a PDF document with a version less than 1.7, opening and reexporting or even reprinting it in Preview.app as PDF will not actually manage to get you a document that's PDF1.7 or above.
I had to use postscript to do it.
The issue that many people were raising is with regards to privacy (not saying your app infringes upon it in any way). If PWA deployment can ensure that the app truly stays offline, then that’s a good thing.
I personally like open source better, as it is easier to examine the inner workings of the app. It also helps tech-savvy users fix bugs and verify that it doesn’t do anything they don’t want it to do. Etc etc
Also, Electron apps can be sandboxed using Flatpaks for instance. Flatpaks aren’t perfect of course, but they do provide some guarantees. You can even use Flatpaks while keeping the source code closed.
i've used it for basic things and had a positive experience thus far.
I'm interested in this but I would be even more so if there was source so I can audit. Since it's running locally in my browser anyway.
always ironic when ppl say this on websites hosted in the us, a country with the most documented cases of governmental organisation backdooring/spying :/
That is because other countries do not let you document/publish this information. :-)
https://www.nytimes.com/2022/03/04/world/europe/russia-censo...
https://www.eff.org/deeplinks/2022/08/uks-online-safety-bill...
At least not as much as American courts will allow. The US has it's own censorship laws, but American resistance/choosing to ignore, is quite strong.
Parent poster talked about backdooring being documented in the US, not comparing the two in general. I posted links about non-US governments making it illegal to document the backdooring or other things the government may worry about an unpopular reaction to. The practice of the 1st amendment in the US offers very strong, but not absolute, protections against this.
> In its release, WikiLeaks said "Marble" was used to insert foreign language text into the malware to mask viruses, trojans and hacking attacks, making it more difficult for them to be tracked to the CIA and to cause forensic investigators to falsely attribute code to the wrong nation. The source code revealed that Marble had examples in Chinese, Russian, Korean, Arabic and Persian.
https://en.wikipedia.org/wiki/Vault_7
The government and media pretends that attribution is a slam-dunk when it virtually never is. On the other hand, there are big career benefits to discovering the next "Chinese" malware vs. stumbling upon some US/EU script kiddy nonsense that included Chinese characters as a prank/red herring. There is incentive to misattribute & sensationalize.
I would wager that ~100% of CIA/NSA malware (or any state actor, really) has a plausible red herring cover. It would be foolish not to.
(once again, it's a combination of current technical capability, concentration of current and early important technologies being developed in your jurisdiction, concentration of current and popular technologies being developed in your jurisdiction, etc)
WebAssembly has no implicit access to browser APIs so I wouldn't think so.
How is checking a web page's network connection, WebAssembly or not, harder than reading ALL the source code (if you don't read them all you can't be sure!) of a non-trivial app?
Edit: After some consideration, maybe they're worried that someone else would create a service using their work.
It might also be worth trying if the PDF reader in a Chrome/Chromium can use its “pages per sheet” option when using a print-to-PDF driver (included by default with Windows these days IIRC, likely available as an option at least on other OSs). You may lose some fidelity on things like images this way, depending on the options selected in the print to PDF driver.
` pdftk {{input.pdf}} cat {{1-10}} output {{output.pdf}} `
If you want to do multiple files you may want to burst them and recombine. If you are doing it for file size purposes there may be better options though, as I dont think there is any way to split in 500kB chunks for example.
There supposedely is a windows version [here](https://www.pdflabs.com/tools/pdftk-the-pdf-toolkit/). I haven't used it though.
But I've done it with Illustrator previously, at least.
I was literally trying to create something like this
Anyways good job
> Source not available, no acknowledgement or explanation as to why
> Hacker News upvotes it to the front page
[0] https://developer.chrome.com/docs/devtools/network/reference...
1. Install ServiceWorker.
2. Save data to LocalStorage/IndexedDB/ServiceWorker Cache/ServiceWorker Memory.
3. Wait for devtools to be closed, enabling internet access, send data from ServiceWorker.
Work around that.
Easy. I use HTTP/3.
No, really, HTTP and SOCKS proxies cannot carry QUIC traffic, so browsers don't even try. They just send it right through.
If you block UDP, I guess I can still try DNS for exfil. HTTP proxies don't support DNS, and browsers need to be explicitly configured to proxy DNS through SOCKS, if the SOCKS proxy even supports it. Chances are, DNS exfil will work.
Now, if you were to do what I do to disable network access, then I'd have no chance: network namespace in a jail with zero network interfaces (not even loopback).
edit: tested this the old-fashioned way with Firefox 116.0.3 on Ubuntu and nginx 1.25.1. Firefox does connect over HTTP 3 and CORRECTLY DOESN'T CONNECT AT ALL with a (bad) proxy configured. You are spreading FUD.
My Chrome 115.0.5790.170 doesn't seem to use HTTP 3 at all.
That's what I thought, at first. But, back when Chrome introduced QUIC, this was a known phenomenon in proxy-restricted but not-UDP restricted setups. I doubt I'd be able to find a bug report for it, given Google's nature, but there's a few reports[1][2][3] by proxy vendors asking for QUIC to be disabled or traffic will go through, even when Chrome is configured to use a proxy.
And here's[4] a user report with the same observation, with Chrome connecting directly to its mothership without going through the configured proxy. The user reports successful blocking upon disabling QUIC
1: https://www.currentware.com/support/disable-quic/
2: https://support.umbrella.com/hc/en-us/articles/360051232032-...
3: https://support.forcepoint.com/customerhub/s/article/0000154...
4: https://superuser.com/questions/1688524/why-google-com-doesn...
> You are spreading FUD.
I assure you, I had no such intention. I was just reporting from memory, of years ago, back when I was in college and had to deal with a proxy-restricted network, and QUIC was being rolled out.
> My Chrome 115.0.5790.170 doesn't seem to use HTTP 3 at all.
Maybe your Chrome has HTTP/3 blocked for some reason. Or, more likely, Chrome supports a different draft of the HTTP/3 spec than the server you're testing against. It has a history of doing that too.
In this thread we were talking about the user willingly configuring a proxy in the browser or OS.
Sorry, I didn't look too closely through any of those links, because I never used those specific products myself.
But I do clearly remember this being an issue for me back in the day. So I dug further. You'll be happy to see this bug report[1] and this commit[2]. Note these words from a Chromium dev: "This code was written when we discovered a problem with QUIC bypassing proxies."
1: Issue 389684: QUIC bypasses proxy settings | https://bugs.chromium.org/p/chromium/issues/detail?id=389684
2: Issue 217783003: Do not use QUIC for requests that are through a proxy. | https://codereview.chromium.org/217783003
Yeah, I agree. I should've checked the validity before posting it, instead of just going by memory from years ago.
> ... finding this reference ...
It was a lot more effort than I'd have liked to put into my original comment, but hey, I was ticked off by your accusation of spreading FUD. Also didn't help that search engines today aren't what they used to be.
(menubar File => Work offline)
It applies to the whole browser, not the current tab. But good enough.
1. starts by suggesting devTools, which is simple, elegant, and wrong.
2. improves by suggesting the "Work Offline" menu option of the File menu, which is hidden by default on both Windows and Linux, and also wrong.
3. improves to a state of minimal functionality with implicitly ordered steps to use Private Browsing, Offline Mode, and confidential file "upload." And, I guess, always remembering to close all private browsing windows upon completion?
I'll rankly speculate f this ever caught on, 25% of users will forget to check offline mode until after they have finished editing their confidential document, 40% will leave a stray Private Browsing window open at all times, 10% will accidentally continue doing all their browsing in the same Private Browsing window, and 1% will somehow paste their private GPG keys in the query string of the URL.
Websites are not meant to not use the internet.
Why can I not simply disable network access in the app settings? Why am I not being asked to grant this permission just like I'm asked to grant access to my photos?
Permissions systems on desktop platforms are mostly useless for regular users and only somewhat less useless on mobile.
Perhaps with the source you could setup an offline server on your own computer so you don't have to upload your data anywhere?
Without the source, you can't trust binary blobs. That was just a reflection why people want the source.
Works as advertised.
Gains trust
Changes app
Steals data
And I doubt that everybody always disables the internet connection while they use the app.
That's the point of gaining trust.
I can do all of this offline for free already with Acrobat or Preview.app on macOS.
> We try to make up some of the cost that we pay for hosting this service by employing a small amount of ads on our website.
Why?
Reordering pages, splitting, joining all worked in the free version, and it's not bloated. Windows only though. I think they might watermark the output when using the Save option directly, but you can get round that using Print to PDF.
Their site looks a bit "scammy", but it's actually decent software.