Hacker News new | ask | show | jobs
by rm-rf 5475 days ago
How is this different than Adobe Reader, where the ability to execute code within a document reading application has resulted in world wide exploits of operating systems?

If my document reader can execute any code in any language, then any document that I read has the potential to execute malicious code on my computer, and I now have an exploit vector that I need to consider when downloading documents & opening e-mail attachments.

I understand that the code can be sandboxed, but before I implicitly trust the sandboxing technology, I'd have to see an example of an unexploitable sandbox. I don't know of any - but that doesn't mean they don't exist.

2 comments

Adobe gives the same access it has to save to any folder on the drive, to the scripts in the PDF. Apple doesn't make those kind of mistakes.
Chrome one has stood up the best thus far
Right, but "the best" being a very misleading term for anyone not in the know. It too has failed to do the job.. But, of course, no code is perfect. Just keep that in mind.

http://www.informationweek.com/news/security/attacks/2295000...