Slashdot Mirror


Adobe Security Chief Defends JavaScript Support

Trailrunner7 writes "Despite the fact that the majority of [PDF-related] malware exploits use JavaScript to trigger an attack in Adobe's PDF Reader product, the company says it's impossible to completely remove JavaScript support without causing major compatibility problems. In a Q&A on Threatpost, Adobe security chief Brad Arkin says the removal of JavaScript support is a non-starter because it's an integral part of how users do form submissions. '"Anytime you're working with a PDF where you're entering information, JavaScript is used to do things like verify that the date you entered is the right format. If you're entering a phone number for a certain country it'll verify that you've got the right number of digits. When you click 'submit' on the form it'll go to the right place. All of this stuff has JavaScript behind the scenes making it work and it's difficult to remove without causing problems," Arkin explained.'"

1 of 216 comments (clear)

  1. You're and idiot and don't know what you are... by gbutler69 · · Score: 0, Troll
    ...talking about.

    It's a pathetic excuse for a scripting language, let alone a full programming language

    This proves it. If you don't understand that Javascript, you'd think that. But, you probably don't think LISP/SCHEME are REAL programming languages either. You probably don't even know WTF "Lambda Calculus" is? Shut the Fuck Up!

    --
    Over-the-top Response Guy! Giving "Over-the-Top Responses" since 1970.