Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>Our corporate IT is hammering pretty hard on the notion that .docx and .pdf (but especially .docx and .xlsx) are unsafe.

why is pdf unsafe?

What format is safe then?



The take-home message from IT is basically "never open an e-mail attachment from unknown sender".


Adobe added embedded javascript to pdfs. Its an option to turn it off but its enabled by default. I turned mine off a long time back and never notice any problems but I don't use a lot of pdfs with interactive forms.


I have yet to see an exploit that can be performed with a .txt file. PDF files can have all sorts of interactive junk and nested files embedded in them - you can get really crazy in that format.


This is it. You can load a .txt as a skill too.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: