By continuing to use this site, you agree to our use of cookies. Find out more
Forum sponsored by:
Forum sponsored by Forum House Ad Zone

pdf's increasingly flagged as 'dangerous'

..what are the risks?

All Topics | Latest Posts

Search for:  in Thread Title in  
DiogenesII26/10/2021 09:00:18
859 forum posts
268 photos

I'm noticing an increasing number of pdf's are being flagged up by Firefox as 'dangerous' - apparently arising from an 'insecure connection and at risk of being tampered with', etc., with a subsequent refusal to open them.

I wondered whether this is because they represent a real, actual danger to the security of my device, or simply because of some more generic industry perception of the risk, say, that they are hosted on an 'http:' address rather than an 'https:' one?

The items are not (ever) things that one might consider carry any risk - it's prosaic stuff like the Blackgates catalogue, or 'how-to-make-piston-rings' from an American MES, that kind of thing..

PS I see that I can override the refusal to open them, and now have another copy of the Blackgates Catalogue - I can still see how more careful forum members might be put-off though, and I'd still like to know what the real risk is, if anyone has a view...

Edited By DiogenesII on 26/10/2021 09:02:57

Frances IoM26/10/2021 09:07:27
1395 forum posts
30 photos
most I think are because they are http rather than the latest https - for those on landlines it is highly unlikely that the link will be tampered with (ie be insecure) but for those using mobile phones via base stations in cafes etc that will not be the case - Firefox has become much more link security conscious recently
Nick Clarke 326/10/2021 09:08:05
avatar
1607 forum posts
69 photos

PDFs can include Javascript and a hacker can add malicious code to this without affecting the look of the documents, so if you are uncertain of the source you may need to pay attention to Firefox.

Confusingly, in my personal experience, there can be false positives as well.

Edited By Nick Clarke 3 on 26/10/2021 09:08:21

Michael Gilligan26/10/2021 09:11:11
avatar
23121 forum posts
1360 photos

Years ago, there was an insistence by some Government departments that Contractual bids would only be submitted in PDF … because it was ‘incorruptible’ and could be considered a definitive document.

This is drivel.

PDFs can be edited and can carry a payload.

Most PDFs are innocent … but the bad guys are very clever, and the risk is real.

MichaelG.

DiogenesII26/10/2021 09:15:06
859 forum posts
268 photos

Gosh, you lot are quick this morning!

I will exercise some judgement and circumspection yes

SillyOldDuffer26/10/2021 10:17:37
10668 forum posts
2415 photos
Posted by Frances IoM on 26/10/2021 09:07:27:
most I think are because they are http rather than the latest https - for those on landlines it is highly unlikely that the link will be tampered with (ie be insecure) but for those using mobile phones via base stations in cafes etc that will not be the case - Firefox has become much more link security conscious recently

All true but I hope no-one assumes landlines are safe!

HTTP is a clear signal to hackers that a website is vulnerable. HTTP indicates laziness, incompetence or shortage of cash, leading to outdated software and a history of poor maintenance. Hackers take close interest in such sites because they often have multiple security weaknesses that can be used to deliver a wide variety of nastiness to end users. Although landline links can't be tampered with the source could already be compromised.

PDFs are just one of many web content containers that can be got at by the bad guys. Firefox are warning that the whole website could be untrustworthy. Who owns the website and why is it still using HTTP?

Good security relies on vigilant users as well as technology. My advice, don't ignore warnings unless the risk is understood. In particular never spend money or give private details to an HTTP website.

Dave

Ady126/10/2021 13:54:54
avatar
6137 forum posts
893 photos

As mentioned its the http https things

I have downloaded around 2 Terrabytes of PDFs and never had a problem

DiogenesII26/10/2021 15:24:05
859 forum posts
268 photos
Posted by Ady1 on 26/10/2021 13:54:54:

As mentioned its the http https things

I have downloaded around 2 Terrabytes of PDFs and never had a problem

Well, yes, likewise - but now I'm getting red-letters from Firefox telling me a personal e-armageddon awaits if I do, from some sites, I was just wondering whether it was a real thing, or no..

..it's surprising some of the 'names' that we all use, that still use not-secure sites..

Oldiron26/10/2021 17:54:58
1193 forum posts
59 photos

I use FF and get the occasional warning. I download the PDF's as they are all scanned by Malwarebytes and Windows Security Essentials. All so far have been clean. I realise that there could be a threat with http so only download from known sources when I can. FF gives warnings on quite a few sites these days especially if you are looking for drivers or free software. I downloaded a BIOS update last week and got a warning that the site was potentialy dangerous. The site was Asus,com which is one of the leading OEM pc parts manufacturers. It pays to be mindfull at all times.

regards

All Topics | Latest Posts

Please login to post a reply.

Magazine Locator

Want the latest issue of Model Engineer or Model Engineers' Workshop? Use our magazine locator links to find your nearest stockist!

Find Model Engineer & Model Engineers' Workshop

Sign up to our Newsletter

Sign up to our newsletter and get a free digital issue.

You can unsubscribe at anytime. View our privacy policy at www.mortons.co.uk/privacy

Latest Forum Posts
Support Our Partners
cowells
Sarik
MERIDIENNE EXHIBITIONS LTD
Subscription Offer

Latest "For Sale" Ads
Latest "Wanted" Ads
Get In Touch!

Do you want to contact the Model Engineer and Model Engineers' Workshop team?

You can contact us by phone, mail or email about the magazines including becoming a contributor, submitting reader's letters or making queries about articles. You can also get in touch about this website, advertising or other general issues.

Click THIS LINK for full contact details.

For subscription issues please see THIS LINK.

Digital Back Issues

Social Media online

'Like' us on Facebook
Follow us on Facebook

Follow us on Twitter
 Twitter Logo

Pin us on Pinterest

 

Donate

donate