Tracking PDF document use by "phoning home"

by Volker Weber

Joe Brockmeyer reports on unexpected features in Acrobat 7:

By default, Adobe Reader 7 turns on JavaScript, so the "tagged" document is able to "phone home" without the user's awareness.

It appears that you can include Javascript code into PDF documents, that Adobe Reader executes. In this incident the code called a predefined hostname that tracked the usage of the document.

If you are concerned with your privcay you may want to switch off Javascript in Adobe Reader 7.

[Thanks, Detlev]

Comments

To switch Javascriping OFF: Just go to Edit - Preferences... Select Category "Javascript" and disable the check box "Enable Acrobat Javascript" - Quite easy!

Wolfgang Schwerber, 2005-05-31 21:22

This is not new to Acrobat 7, nor the Acrobat family of PDF viewers - it has been a part of the PDF specification for some time. It is, in fact, an essential component for the workflow in some PDF scenarios. PDF files can contain almost any multmedia format, as well, and are thus subject to the security of the format player.

Everyone who is concerned with security on their computer should have an interactive utility to monitor and selectively block outbound TCP/IP traffic (Little Snitch, Zone Alarm, or something similar). This functionality should be part of every operating system.

Most users think either e-mail or html in reference to the internet, but this is a dangerously simplistic assumption.

David Richardson, 2005-06-01 02:10

Annoying experience: After switching off Javascript each time Acrobat 7.0 asks for again activating Javascript when closing a PDF! No "Don't ask me again" checkbox... ;-(

Wolfgang Schwerber, 2005-06-01 09:59

Post a comment











Shall I remember this for you?




Use your full name and a working email address. Unless you want your comment to be removed. No kidding.



Ceci n'est pas un blog

vowe.net is a personal website published by Volker Weber a.k.a. vowe. I am an author, consultant and systems architect based in Darmstadt, Germany.

rss Click here to subscribe

Hello

About me
Contact
Publications
Certificates
Frequently asked questions

Twitter Updates

More >

Poll

Can you bring a camera phone to work?

Getting poll results. Please wait...

Local time is 21:09

visitors.gif
205 visitors online

News

Other sources of news, imported into my own format to make them more accessible:

Heise Online
Schlagzeilen
Weather

Archives

As most of my articles roll off the front page rather quickly, I am making an archive of previous posts available here. You can also use the handy search box at the top of the page if you are looking for something particular.

Last 30 days
More archives

Got the T-shirt?

Got the T-shirt?
Are you buying from the US?

Systems Architecture

This site runs on an Apache web server on top of the Linux operating system. The content is managed with MovableType which is implemented in Perl. Last but not least the HTML code your browser sees is put together with PHP.

© 1992-2008 Volker Weber.
All Rights Reserved.

Impressum