[ View menu ]

Monthly Archive March, 2010

Exploiting PDFs

This PoC from Didier Stevens clearly shows how stupid is to allow PDFs to start new processes. We’ll end up creating bloated monsters like the current browsers to deal with these files. Can someone please “strip down” the PDF format to something that makes sense again???   I wonder what happened to “pure data” formats; [...]

The new school and black swans

I’m currently re-reading “The Black Swan”, by Nassim Taleb, in a moment when most information security planning and decision-making techniques look like just plain bullshit to me. So, my mood for accepting absolute truths on this fields is becoming even worse than before. I was reading a post from the “New School of Information Security” blog, [...]