Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not for clearing out djvu, but it sure is frustrating when a PDF isn't available.

It's not just about laziness preventing one from installing the more obscure ebook readers which support djvu. It's about security: I only trust PDFs when I create them myself with TeX or similar, otherwise I need to use the Chromium PDF reader to be (relatively) safe. I don't trust the readers that support Djvu to be robust enough against maliciously malformed djvu files, as I'm guessing the readers are implemented in some ancient dialect of C or C++ and I doubt they're getting much if any scrutiny in the way of security.



It's super easy to convert a DJVU file to PDF though. There's an increase in filesize but it's not the end of the world.

And since you're creating the PDF yourself seems like you can trust it? Since nothing malicious could survive the DJVU to PDF conversion since it's just "dumb" bitmap-based.


DjVu also contains text.

If your DjVu file contains an exploit for your DjVu decoder, even if you run it in a bombproof container, it could still conceivably inject malicious code into the resulting PDF file. That sounds far-fetched because the exploit payload would need to recognize that a PDF conversion was going on and respond by generating the PDF, but I remember when people thought exploiting buffer overflows was implausible, and this is not the same level of rocket science.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: