D
djbaxter
Guest
Adobe Reader and Acrobat Security Initiative
by Brad Arkin, Director of Product Security and Privacy, Adobe
May 20, 2009
...more
The amazing thing to me about this announcement is that the author seems proud of it.
Seriously - quarterly updates to security vulnerabilities that can take down someone's computer? That's nothing to boast about. That's npot even an adequate response.
But what it does succeed in doing is delivering the message loud and clear that nobody, absolutely nobody, should be counting on Adobe products for security.
Ditch Adobe Acrobat Reader now and replace it with Foxit Reader!
by Brad Arkin, Director of Product Security and Privacy, Adobe
May 20, 2009
The recent JBIG2 vulnerability (CVE-2009-0658), the associated exploits, and Adobe?s response (APSB09-04) were the subject of much discussion in the security community in February and March. The JBIG2 issue also sparked a lot of conversation internally at Adobe from executives to testers and developers. What started out as a routine incident response expanded to a broader effort by Adobe Reader and Acrobat engineers, culminating in permanent changes to our software security approach for those products.
Since February, Adobe Reader and Acrobat engineers have been executing a major project focused on software security. Everything from our security team?s communications during an incident to our security update process to the code itself has been carefully reviewed. Security is an ongoing process, so while we believe our plan will eliminate or mitigate many potential security risks, we are also working to enhance our ability to respond to externally found vulnerabilities in Adobe Reader and Acrobat in the future.
...
Regular Security Updates ? Starting this summer with the initial output of our security code hardening effort, we plan to release security updates for all major supported versions and platforms of Adobe Reader and Acrobat on a quarterly basis.
...more
The amazing thing to me about this announcement is that the author seems proud of it.
Seriously - quarterly updates to security vulnerabilities that can take down someone's computer? That's nothing to boast about. That's npot even an adequate response.
But what it does succeed in doing is delivering the message loud and clear that nobody, absolutely nobody, should be counting on Adobe products for security.
Ditch Adobe Acrobat Reader now and replace it with Foxit Reader!