Hacker News new | past | comments | ask | show | jobs | submit login

>it also provides a way to read the content of potentially-malicious sites without risk of browser vulnerabilities being exploited

PDFs have the same kind of vulnerabilities, they can even execute JS (JS is probably not contained in the ones generated by the author).

>and without revealing your IP address, User-Agent, etc.

Yep.

>> try downloading it, if it is a file smaller than 5 MiB;

>I found that even pages smaller than 5MB get rendered to PDF.

I believe the text is supposed to mean "if it's not a web page but a file [offered for download], it will download the file if it's less than 5MB".




Some PDF readers can execute JS which can be embedded in PDF files. Just use a reader which doesn't support embedded JS (or switch it off if it does support it) to avoid this whole class of vulnerabilities.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: