Friday, May 19, 2006

 

PDF: Much ado about no security

There has been some concern lately over a so-called security failure in PDF. At least for a while, certain permissions set in PDF files, such as restrictions against printing, could be circumvented simply by opening the file through GMail.

But the truth is that these restrictions aren't, and never were, secure. They are "bozo bit restrictions"; certain bits are set to request that the software comply with the restriction, and that's all. Software that chooses to ignore them, or ignores them because it's buggy, can bypass them. It's also easy to write software that modifies these bits in a PDF document, so that Adobe Reader and other compliant readers will no longer refuse to perform the relevant operations. I don't personally know of such software, but I'm sure it exists. Calling these modifications "cracking" the documents gives them too much credit. The security of these features is like a sign on an unlocked door that says "please do not use this door."

There are actual security features in PDF, such as file encryption, which can't be easily broken. But setting these bits and imagining that they will stop any but the most casual users is wishful thinking.


Comments: Post a Comment

<< Home

This page is powered by Blogger. Isn't yours?

free hit counters
free hit counters
hits since 30-Oct-2006