Slashdot Mirror


Adobe Still Ignores Elcomsoft-Discovered Holes

evenprime writes "In 2001, Dmitry Sklyarov described vulnerabilities in Adobe Acrobat and Adobe Acrobat Reader while giving a talk at Defcon 9. As has been previously mentioned, Dmitry was arrested the day after this talk. He and his company Elcomsoft were charged with violating the DMCA. Now Elcomsoft have announced that Adobe, two years later, has still not patched these bugs."

27 of 305 comments (clear)

  1. relapse by mirko · · Score: 5, Interesting

    They once warned them, then the public about their feeble rot13 encryption scheme.
    They got busted because of the DMCA.
    Now, they do it again.
    I guess Dmitri should avoid the USA during the next months, otherwise, he'll soon understand that in Soviet American Corps, sucees is not a matter of technical excellency but rather a matter of negociation skills and of litigation.
    So, why should Adobe managers solve this "bug" when they'll get promoted by complaining about a "criminal offense" ?

    (Note to the mods: I have been hard-working during 18 months in an American Corp, I know what it is about.)

    --
    Trolling using another account since 2005.
    1. Re:relapse by Goldberg's+Pants · · Score: 5, Interesting

      It's a lot less effort to sic the lawyers on people than actually PATCH the vulnerability. Security through obscurity (and fear).

      Seriously, this isn't that surprising. Outside the tech sector, the Skylarov thing was largely ignored, and the Adobe vulnerability has been too. The sad thing is, as a writer, it pains me to see a format which is SUPPOSED to be secure be swiss cheesed. Would never use it myself, but Adobe are the real criminals in this. Defrauding people by saying "yes, this format is secure" when it quite obviously isn't.

  2. What motivation do they have to fix it? by mikeophile · · Score: 5, Insightful
    They have the DMCA to sue those who exploit it for a new source of revenue.

    Maybe more companies will bait their software with easy exploits to snare those who try to circumvent it

    If nothing else, it gives the companies an excuse to their shareholders for shoddy coding.

  3. Response from Adobe Lawyer... by Anonymous Coward · · Score: 5, Funny

    [...]may we ask who found those bugs again?

  4. Bwahaha! by Quaoar · · Score: 5, Funny

    Foolish PC users! Us Macintosh people will be entirely unaffected by these exploits... ...because Adobe is starting to stop making programs for mac... :(

    --
    I'll form my OWN solar system! With blackjack! And hookers!
  5. This is the perfect example... by supersam · · Score: 5, Funny

    ... of sweeping the bugs under the rug and ignoring that they exist while punishing the kid for pointing out the bugs.

    When those bugs crawl out from under the rug... that's when you start feeling the pinch... quite literally... coz they're nasty bugs that bite.

    1. Re:This is the perfect example... by The+Grassy+Knoll · · Score: 5, Funny

      Whoah there!

      Do you think you could mix any more metaphors into that post, please?

      Possibly a case of the baby calling the kettle black, though

      --
      They will never know the simple pleasure of a monkey knife fight
  6. Well, well... by Anonymous Coward · · Score: 5, Funny

    ...if that isn't a new way of fixing bugs.

    Sueing the people until they stop caring and reporting them (the bugs).

    That amazon guy probably has already patented it.

  7. Excellent! by Noryungi · · Score: 5, Insightful

    As I have said before, one of my friend is blind.

    Have you got any idea how fscking difficult it is for the poor chap to read "protected"[1] PDF files? Trust me, it's pure hell!!

    At least, since Adobe has decided to pull an MS on its users and ignore known problems, maybe I'll be able to crack some of these protected files for my friend, so that he can read them.

    So, there are, er, ahem... unexpected benefits to this sh___y Adobe attitude...

    Just my US$ 0.02...

    [1] "Protected" as in: "can't print, can't copy, can't save as". Yes, Virginia, you can create that kind of PDF files!

    --
    The right to offend is far more important than the right not to be offended. (Rowan Atkinson)
    1. Re:Excellent! by Vendekkai · · Score: 5, Informative

      Many of the assumptions in posts above are incorrect. I installed Acrobat 6 a month ago, and can verify these features.

      1. Acrobat has a read aloud function for the visually impaired. It's not perfect, a rather tinny voice, but it is functional. I, err, listened to a chapter or so of the latest Potter book (don't ask!) while driving, and could make perfect sense of the text to speech. This function is available when read access is given to the document.

      2. Adobe does warn people in the manual that pdfs are not very secure. They don't admit that Acrobat can be cracked, but the say something to the effect of "other pdf readers may not implement the pdf security features properly, and your secure document may not retain security with those readers." Of course, you can remove any pdf security with GhostScript, using a cracked dll.

      Vend Ekkai

  8. Big vulnerability by m4g02 · · Score: 5, Informative

    You missed the point, the vulnerability is a big one and doesnt involve the final user.

    As you may already know many companies use PDF to realse secure documents, this companies are confident that adobe security will keep the document as read only so no llama will make changes for fun or copy paste their info.

    But then we have this vulnerability where you can load a custom plugin in secure mod, this plug in could use all the privileges a secure plug in has, like for example saving an unencrypted version of the file or, why not, a pain text copy.

    This sound like a big vulnerability to me, but companies that use Acrobat are the ones that should be angry.

    --
    Sigs are for morons... Wait a minute...
  9. Sklyarov by AndrewHowe · · Score: 5, Informative

    Even the article gets it wrong now.
    Sklyarov!

  10. Team up with Lexmark? by dmeranda · · Score: 5, Insightful

    Perhaps Adobe should work with Lexmark to help them out with the crypto coding; you know, that great company that protects the consumer against accidentally using cheap ink with strong cryptographic chips. Then Adobe could not only provide a PDF option to prevent you from printing a document, they could also enforce that if printed, a PDF document will only be printed with 100%-genuine Lexmark toner. Oh, I see another option with Kodak here, perhaps by embedding RFID tags directly in that specical Kodak paper.

    BTW, did anyone notice that with the latest PDF specification, version 1.5, which corresponds to Acrobat 6, that they added verbage to the copyright/license part to enforce that all software which implements the PDF specification must obey all those stupid magic security bits? They claim the specification is open and free for anybody to develop software around it, but that since the "format" is copyrighted all independently developed software must obey their fragile DRM schemes. How in the world can they copyright a format; sure their specification is copyrighted being a printed work, but the "format"?

  11. Who do we contact at Adobe? by torpor · · Score: 5, Insightful

    I, personally, would like to make my annoyance at this situation known.

    Who do we contact at Adobe? How do we make a serious stink about this? Are the board members of this company contactable somehow? I'd go to the effort of writing a decent letter explaining to them their stupidity and callousness, if I knew where to send it.

    --
    ; -- the corruption of government starts with its secrets. a truly free people keep no secrets. --
    1. Re:Who do we contact at Adobe? by lhbtubajon · · Score: 5, Funny

      I believe that would be:

      brickwall@adobe.com

  12. Re:Acrobat isn't so wonderful... by agent+dero · · Score: 5, Insightful

    As soon as you implement this, we can talk.

    Until Java is supported well cross-platform, and as soon as you can somehow get people to obey all your PHP-HTML-Java rules, then be queit.

    The beauty of PDF, is exactly it's name Portable Document Format just about every platform supports PDF in one form or another, besides a couple ignored security holes here and there, I think PDF is a functional format.

    You can have formatted text and images, looking the same on just about every platform that has a GUI.

    --
    Error 407 - No creative sig found
  13. They've to keep the lawsuits rolling by jsse · · Score: 5, Funny

    I once asked my boss why our company has to raise so many lawsuits each year. He told me under the influerence of a couple of beers that if we don't keep our lawyers busy they'd find something to sue us.

    "They're like guarddogs" after more beers "if you don't feed them well they might bite you one day"

    I know this is an unfair comparison. Accept my apology to all the faithful employees...I meant to those guarddogs.

  14. And the /. community says I told you so by lavalyn · · Score: 5, Insightful

    After all, we knew the DMCA would have this effect on companies and software, where bugfixes are unnecessary by litigation.

    Why fix software when we can send lawyers and make examples and burning effigies instead?

    --
    Doing the Right Thing should not be preempted by making a buck.
  15. Microsoft does the same... and profits!! by jkrise · · Score: 5, Interesting

    During every upgrade to a new Windows OS, we are advised to run a check for file viruses using anti-virus s/w. It's a tragedy that software exploits are described as viruses and linked to terrorists and success-haters. Why can't MS make newer releases of their OSes atleast immune to known viruses and the associated vulnerabilities???

    Every new release of s/w causes some code to break - a game here, a dll there, an application and so forth. The only thing that runs well on all flavours of MS OSes from DOS to XP is viruses!

    It's easier to obfuscate and profitable as well, apparently.

    --
    If you keep throwing chairs, one day you'll break windows....
  16. Re:Acrobat isn't so wonderful... by Zeddicus_Z · · Score: 5, Informative
    I work as an IT admin at a publishing company. We do several magazines covering various aspects of the IT industry. PDF's are vital to our production process. Why? Well, the two biggest reasons are;
    • When an advertiser sends your their ad as PDF, they can be almost 100% certain that it will appear on our systems exactly the same as it did on theirs.(*)
    • When we send our magazines off for printing, we can be almost 100% certain that what the printers see on their systems is what we saw on ours(**)
    Aside from the above, there are many other reasons why PDF is the industry standard in publishing (and, unlike Mac, it's a real standard. Once we weaned our designers off Apple and over to PC, they've been full of nothing but praise for the platform. Yep, that's right, we're a magazine publishing company that doesn't use Apple.)

    Despite your claims, HTML is never and will never be a means of displaying content the same way across multiple platforms. Heck, it wasn't even designed for that use in the first place. People try to make HTML-formatted content look exactly the same cross-platform, but when it changes layout at the even the slightest screen resolution change, it's a lost cause.

    I read the Elcomsoft post to bugtraq this afternoon, and I agree Adobe's attempt to fix the problem was, at best, a poor effort. However, their failure to fix a flaw in their application does not mean that companies can up and switch to formats that not only do not do the same basic job PDF does (consistent display cross platform), but don't even claim to do so.

    *Varibles such as colour saturation, monitor differences and even things as small as the level and angle of light being cast onto a monitor affect the display. However, this does not affect the printing process.
    **Once again, you have variables that are almost uncontrollable such as types of ink, non-PDF fuckups at the printer's end, etc.
    --
    Janie took my gun...
  17. Re:YOU ARE ALL GOAT FUCKERS!!! by Chrysophrase · · Score: 5, Funny

    I think this must be the official reply from the Adobe spokesperson.

    --
    "It usualy starts with some screaming. Afterwards there is much running around."
  18. Most people can't do both. by Futurepower(R) · · Score: 5, Interesting


    Very, very few people, apparently, have both technical knowledge and managerial knowledge.

    The problem mentioned in the Slashdot story appears to be that Bruce Chizen, Adobe president, is not prepared for the intellectual challenge of running a technical company. He's been a salesman and marketing manager all his life. Now Adobe has become dependent on Acrobat, and has a big customer for Acrobat, the IRS (U.S. Internal Revenue Service).

    It's amazing. The job pays extremely well, even though the smart people are gone, Adobe has laid off people, and the stock is slowly sliding.

    We live in a business climate in which a few people at the top make a huge amount of money, and other people suffer, even though they helped make the money.

    There seems to be a pattern with technological companies. The people who really understand the technology get tired and go on to other things, or are forced out of the company they founded (as was Jobs at Apple). Everyone pretends that nothing has happened, and the company runs on inertia for a while. With luck, the new managers, who try to hide the fact that they really don't understand what the company does, encounter a business upturn. But inside the company is dying.

    John Sculley was a sugar water salesman (Pepsi) before he came to Apple and forced Jobs out. Apple looked okay for a while, but slowly lost importance. Then Jobs came back, and Apple became very important.

    Adobe's Postscript is brilliant technology. Using Postscript to make PDF files is brilliant. Knowing what photo editing tools need to go into Photoshop requires deep technical understanding. Probably Bruce Chizen understands none of this. Can a manager run something he does not understand? No.

  19. Adobe's Response by Feldmrschl · · Score: 5, Funny

    [monty python reference]

    DIMITRI: If you will not fix rot13 encryption, we shall publish an exploit!
    ADOBE LAWYER: You don't frighten us, Russian pig-dogs! Go and boil your bottom, sons of a silly person. I blow my nose at you, so-called Dimitri Hacker, you and all your silly Russian k-nnnnniggets. Thpppppt! Thppt!Thppt!
    SLASHDOT: What a strange company.
    DIMITRI: Now look here, my good man--
    ADOBE LAWYER: I don't wanna talk to you no more, you empty headed animal food trough wiper! I fart in your general direction! You mother was a hamster and your father smelt of elderberries!
    SLASHDOT: Is there someone else up there he could talk to?
    ADOBE LAWYER: No, now go away or I shall sue you a second time-a!
    ADOBE EMPLOYEE #1: I didn't know we were Idiots?
    ADOBE EMPLOYEE #2: Of course, why else do you think we are protecting this ridiculous algorithm?

    [/monty python reference]

  20. DMCA = right to sue, != requirement to fix by cenonce · · Score: 5, Insightful

    This really shouldn't surprise anyone. The DMCA gives companies a right to sue if you reverse engineer an encyption device. But the DMCA offers no protecting to the consumer by requireing a company to FIX the problem.

    Besides /., this story has not had a whole lot of publicity. Add to that the fact that most people wouldn't know how to decrypt the e-books (and, more importantly, probably don't all that much care), there really isn't much incentive for Adobe to fix it.

    The puzzling thing to me is that it seems like it really wouldn't cost all that much to fix. I mean, it is a patch afterall and every friggin time I start up Photoshop Elements it is downloading some update (though not sending any of my personal information... hehe!).

    IAAL, so what I start to think is: Does Adobe have any liability for failure to patch the software when an author loses money because his or her ebook is pirated? No doubt in advertising and selling the software, Adobe touted the encryption as a safety feature. Contributory infringement, maybe? Misrepresentation? A warranty theory? Hmm....

  21. unsurprising and unfixable by Eivind · · Score: 5, Insightful
    This is not surprising. What Adobe is trying to do is fundamentally impossible to do as long as the users still have ultimate control over their computers.

    Adobe is trying to tell customers that they have a format in which you can send a document to someone, and that document will only be readable on that one computer, or will not be printable, or will not be copyable to the clipboard or whatever.

    This is fundamentally impossible. If my computer can display the document on screen for me, then this means that the computer MUST have all the required information to do so. This includes any and all secret keys if the document is encrypted and so on.

    This implies that the computer also has all the info needed to print the document, or copy it to the clipboard or whatever. Now, Adobes product could only work if the computer "knew" how to do this, but refused to do it anyway, in other words, if the computer was not obeying the end-user.

    This is possible with secure hardware and similar that refuse to run code that is not digitally signed by the real master (not the end-user and owner!). But with the current computers that happily run anything you the user want in priviledged mode it is not possible.

    Sure they could, and probably should, patch this spesific hole. But there's nothing Adobe can do to make they so-called "secure pdf" actually do what they claim it will do. And they know it.

  22. Re:NOT a problem by Matrix272 · · Score: 5, Informative

    This "vulnerability" means that you can run plugins WITHOUT having them signed by Adobe.

    THAT is the problem. Companies use Adobe Acrobat to create forms that should not be altered outside the company, like contracts, and send them to their customers to fill out. If said company can no longer trust that their customers won't be able to change text in their contract without notifying them, then Adobe Acrobat is completely meaningless.

    My last job was at an ISP that would create contracts and accounting papers in Acrobat, then send them to people to fill in certain information. Sometimes, the documents could be 30-50 pages in length. It obviously would take quite a long time to manually go through and verify that nothing inappropriate (i.e. the cost of getting out of the contract) would be changed. Of course, in that case, the company deserved whatever it got, but that's beside the point.

    --
    "It's better to have a gun and not need it than need a gun and not have it." ~ Christian Slater, True Romance
  23. What about the end user's responsibility? by ipour · · Score: 5, Insightful

    Too many people don't pay attention to where their plug-ins and other downloads come from - that is where a big part of the problem starts. End users need to own up to that fact that when a warning comes up about an unsigned or questionable certificate, they need to ask some serious questions before installing.

    Sure, Adobe still has a "vulnerability" in the strict sense of the word, and if they want to continue marketing a weak security product, that is their business. In my opinion, their inspired release of Acrobat Elements will make Adobe a bigger player and Acrobat a major product. Going in to this with a problem is just bad business and will not help them. And whacking the messenger with the DMCA is definitely not a solution!