Adobe Putting PDF Reader In a Sandbox
Captain Eloquence writes "The next major version of Adobe's PDF Reader will feature new sandboxing technology aimed at curbing a surge in malicious hacker attacks. The initial sandbox implementation will isolate all 'write' calls on Windows 7, Windows Vista, Windows XP, Windows Server 2008, and Windows Server 2003. Adobe security chief Brad Arkin believes this will mitigate the risk of exploits seeking to install malware on the user's computer or otherwise change the computer's file system or registry. In a future dot-release, the company plans to extend the sandbox to include read-only activities to protect against attackers seeking to read sensitive information from the user's computer."
What do we use PDFs for which involves writes?
Malware installation.
Sounds suspiciously Apple-like. iPhone apps do this very thing.
No shit Sherlock: sandboxing, emulation, memory and hardware virtualization, CPU ring modes are all Apple inventions from 1970s and Windows 7 you're browsing from right now has its code base from Apple Lisa of that era.
Huh? How the hell are you going to save the top scores for the pacman game embedded on page 23 of the PDF, if you can't write files?
Who sandboxes the sandboxers?
These are my friends, See how they glisten. See this one shine, how he smiles in the light.
No, don't worry. Because of how bloated Acrobat Reader already is, Adobe was able to fit a re-skinned copy of virtualbox, containing a minimal linux image running Evince, in a package smaller than the prior download.
This is how they managed to get a "sandboxed" PDF reader out in less than the usual absolutely glacial Adobe development timeframe...
YEAH! And Microsoft WORD should only let you use WORDS...not crappy images and all that.
Don't take life so seriously. No one makes it out alive.
Genie is here Bottle is here
| |
| |
V V
X X
(This example brought to you by the fact that drawing a little man locking a stable door with a horse already running outside is too hard to draw without triggering Slashdots ASCII art filter)
Sandbox A will be put inside Sandbox B, and Sandbox B will be put inside Sandbox A. Problem solved!
Corruption is convincing someone that the selfless ideal is the same as their selfish ideal.