View Single Post
Old 08-05-2010, 05:38 PM   #21
Maggie Leung
Wizard
Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.
 
Posts: 1,449
Karma: 58383
Join Date: Jul 2009
Device: Kindle, iPad
Quote:
Originally Posted by toddos View Post
Almost, but not quite. That's true if you're physically opening PDFs, but the hack is that PDFs can be loaded automatically. You navigate to shady site X, and that site automatically loads a hacked PDF with malicious payload. If done correctly, you'll never even know that the site just hacked you.

That's why you need to install the PDF Loading Warner (which can only be done after jailbreaking), to stop Safari from automatically and silently opening PDFs. You can still be hacked even after that, since the warner doesn't fix the whole. It just lets you know that, "Hey, this site here just tried to open a PDF. That could be dangerous. You sure you want to do that?" and allows you to stop the load before it's dangerous. If you allow it through anyway, you can still be hacked.
Yeesh. So without jailbreaking, you're pretty much stuck hoping that you don't stumble into some creepy site? Because it seems pretty easy to read something online, like on this forum, follow a link and end up somewhere that you don't know is trustworthy.

How long do you think it will take for Apple to patch this?

Let's say take your iPad back to factory settings, and reload all your stuff from iTunes. Would that work to stop whatever unseen hacking might be already at work on your iPad? I ask because someone posted earlier that it's hard to tell whether you've been hacked. Even if you jailbreak now and load the PDF warner, the hackers could already have access, it sounds like. And it doesn't sound as if the jailbreaking and PDF warner could help if that were the case.
Maggie Leung is offline   Reply With Quote