Researchers Break Digital Signatures For Most Desktop PDF Viewers (zdnet.com)
An anonymous reader quotes a report from ZDNet: A team of academics from the Ruhr-University Bochum in Germany say they've managed to break the digital signing system and create fake signatures on 21 of 22 desktop PDF viewer apps and five out of seven online PDF digital signing services. This includes apps such as Adobe Acrobat Reader, Foxit Reader, and LibreOffice, and online services like DocuSign and Evotrust --just to name the most recognizable names. The five-person research team has been working since early October 2018 together with experts from Germany's Computer Emergency Response Team (BSI-CERT) to notify impacted services. The team went public with their findings over the weekend after all affected app makers and commercial companies finished patching their products. In research published today, the Ruhr-University Bochum team described three vulnerabilities that they found in the digital signing process used by several desktop and web-based PDF signing services. Summarized, they are:
1. Universal Signature Forgery (USF) -- vulnerability lets attackers trick the signature verification process into showing users a fake panel/message that the signature is valid.
2. Incremental Saving Attack (ISA) -- vulnerability lets attackers add extra content to an already signed PDF document via the "incremental saving (incremental update)" mechanism, but without breaking the already-existing signature.
3. Signature Wrapping (SWA) -- vulnerability is similar to ISA, but the malicious code also contains extra logic to fool the signature validation process into "wrapping" around the attacker's extra content, effectively digitally signing the incremental update. Additional details about the three vulnerabilities are available in this PDF research paper [1, 2], this blog post, and this dedicated website.
1. Universal Signature Forgery (USF) -- vulnerability lets attackers trick the signature verification process into showing users a fake panel/message that the signature is valid.
2. Incremental Saving Attack (ISA) -- vulnerability lets attackers add extra content to an already signed PDF document via the "incremental saving (incremental update)" mechanism, but without breaking the already-existing signature.
3. Signature Wrapping (SWA) -- vulnerability is similar to ISA, but the malicious code also contains extra logic to fool the signature validation process into "wrapping" around the attacker's extra content, effectively digitally signing the incremental update. Additional details about the three vulnerabilities are available in this PDF research paper [1, 2], this blog post, and this dedicated website.
And how then we are supposed to know that this is really from these researchers??? :)
Paul B.
There is no digital security.
Didn't they bother to test it or was it not vulnerable?
(see previous post)
Signed PDF - huh? Does anyone even care about PDF or anything else from Adoobie Doo? Purveyors of Flash, the ultimate, long-surviving malware vector and pain-in-the-****. PDF "Reader" that is a heap of spyware under one roof, up to and including built-in mail-home "features", etc, etc.
"The reason why researchers were willing to wait months so all products would receive fixes is because of the importance of PDF digital signatures."
Very important.
Meanwhile, I didn't realize this feature existed. If I even see a PDF it's because someone else chose to obfuscate text using that particular format.
And I was wondering, why Ghostscript had two updates with so short timespan.
According to the article, Adobe 9 for Linux is the only secure reader. TLDR, don't run windows or mac!
Lawyers love PDF and bitmaps because you know, they are more secure. Rather than fire ff a word document - they bilk their clients and call it photocopy or electronic file fees, sometimes at $1 per page.
Demand your lawyer not PDF everything.
So, can somebody who RTFA or otherwise knows this topic, did they crack PGP or are we still good here?
How can i validate my class 3 digital signature online