Reducing the risk of having Adobe Reader installed

mikeymikec

Lifer
May 19, 2011
18,062
10,248
136
I'm working solely with Adobe Reader 11.x on Windows 64-bit systems for the purposes of this discussion.

As far as I'm aware, the two most serious attack vectors are attacks on Adobe Reader's browser plug-in, and attacks involving malicious PDFs.

My current configuration of Adobe Reader for the average user involves updating it to the latest revision (IIRC 11.0.9) using its auto-update system, and making a few changes in Edit > Preferences:

1 - Under 'Internet', I disable 'fast web view' and 'allow speculative downloading in the background'. I think 'fast web view' is the clincher here, I think it removes the browser plug-in from browsers such as IE and Firefox.

2 - Under 'JavaScript', I disable 'Acrobat JavaScript'. I'm sure that this will break some PDF functionality for someone at some point, but for all the other users who require a basic PDF reader most of the time (but form filling in the PDF appears to be becoming more common and I don't think SumatraPDF can do this), it should be a benefit rather than an obstacle.

I'm happier about having Adobe Reader on customers' systems since the current version doesn't reinstate default settings after every update (which would undo any security enhancements I hope to make).

PS - I have in the past switched between recommending Adobe Reader, Foxit Reader and SumatraPDF. SumatraPDF's printing support appears to be shaky, I've seen printing problems on several systems, more commonly with HP printers. I wasn't happy with Foxit Reader for a while because they turned their auto-update system into (effectively) a product install procedure complete with reconfiguration to get rid of the browser plugin, and I'm currently not happy with its default overly-complicated ribbon interface (it's a PDF reader, how complicated does a PDF reader's interface really need to be?).

Hopefully Adobe will completely fix their auto update system at some point so Reader 11 users will automatically be updated to version 12 when it is released. The 10 to 11 auto update sometimes happens as one might expect.

I guess the reason why I'm posting this thread is to ask for suggestions for ways to tighten Adobe Reader's security without creating problems for common uses of it.
 
Last edited:

balloonshark

Diamond Member
Jun 5, 2008
6,407
2,845
136
It probably won't help your customers but I use Sandboxie to sandbox my browser. When I'm browsing and click on pdf it automatically opens Foxit reader sandboxed. Since I have the paid version of Sbie I can even 'force' Foxit to always start sandboxed. This method is mainly good at protecting your machine while reading random suspect pdfs.
 

KeithP

Diamond Member
Jun 15, 2000
5,660
198
106
I have Acrobat Pro, not Reader, but I assume the following is the same...

Under "Trust Manager" I would deselect "Allow opening of non-PDF file attachments with external applications."

-KeithP
 

mikeymikec

Lifer
May 19, 2011
18,062
10,248
136
I have Acrobat Pro, not Reader, but I assume the following is the same...

Under "Trust Manager" I would deselect "Allow opening of non-PDF file attachments with external applications."

Yikes. Good catch!
 

ringtail

Golden Member
Mar 10, 2012
1,030
34
91

It doesn't work with forms for the US Government. The USG sites I interact with require uploads that you're entering with them MUST to be converted to pdf,

but not only that....

it's gotta be the ADOBE brand of pdf.

If the pdf is created in a different brand that's not Adobe, the USG web site rejects it. No format except pdf can be entered, but you simply can not enter your pdf, except if it was prepared using Adobe.

They obviously fiter file metadadata to accept ONLY Adobe brand.

I really hate pdf.

Many years ago I used Foxit for a long time, but they mucked it up too much with changes, so I quit Foxit about 6 or 8 years ago and upgraded to PDF-X (Tracker). It's GUI visually is sort of clunky ugly, but when you go using it you discover it has more functionality than Foxit. Tried Sumatra, CutePDF, quite a few others..... briefly....= inadequate.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |