The Long, Strange History of PDF (In)Security – And the Arrest That Made It Personal👁🗨
PDF has a reputation as the boring, dependable file format – the one you reach for when you need a document to look exactly the same on every computer, forever. What gets forgotten is that PDF’s security model has been shaky since version 1.0, and its history includes an FBI arrest, a federal jury trial that helped define how the DMCA actually works, and – twenty years later – a fake GIF that hid a tiny working computer inside an image compression stream.
This is that story, roughly in order, including the part where we were personally on the receiving end of it.
❓Where it all started: Adobe’s eBook experiment
Back in 1999–2001, Adobe was chasing the “eBook” market with the Acrobat eBook Reader (originally the GlassBook Reader) and a back-end called the Adobe Content Server. Publishers could lock a book down with any of several plug-in “security handlers” – Adobe’s own PDF Merchant and EBX, plus third-party schemes like FileOpen and SoftLock – restricting printing, copying, lending, or text-to-speech.
All of them shared the same underlying weakness, and it wasn’t really about key length…
More information at the link📎
Post #633
214
