Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I am kinda hesitant to download and open a PDF file coming out of Black Hat 2016.

EDIT: See child comment, GitHub preview is fantastic! Slides have a ton of great info.



GitHub will actually render a full preview on the website, no download required.

https://github.com/ionescu007/lxss/blob/master/The%20Linux%2...


Github uses pdf.js for that, so it's not more or less secure than viewing it with Firefox's built-in viewer.


There have been serious security issues with the integration of pdf.js into Firefox in the past, so it may actually be more secure than Firefox's built-in PDF viewer.


Ah, that's quite pleasant. And it doesn't even appear to use the browser's PDF renderer or anything.


Guys, how do you think Black Hat 2017 is going to be funded if you dont download and open the PDF ? ;)


If they're not able to make it silently download and execute remotely without me interacting or being aware, I feel they're not doing their jobs as black hats.


The people who know how to do that are pulling down the big bucks on the Windows 10 team at Microsoft.


Well, it uses Firefox' PDF renderer - they just copied the code into the page itself.



I try to use "copy" in an inflationary way, to remove the negative stigma associated with it.

Our entire floss community is based on forking an existing project, improving, and sometimes merging again, and the entire history of innovation has been based on this copy-transform-combine cycle, too.


It says "This file is too big to show. Sorry!"

Edit: Nevermind, switch to desktop version and it works.


It's not "coming out of Black Hat". It's coming from Alex Ionescu, via his GitHub account. You have an identifiable person with a known reputation here, not some unidentifiable person hiding behind a pseudonym.

The problems that you have are quite different ones:

* Demonstrating that the Alex Ionescu of http://www.alex-ionescu.com/ and of https://microsoftpressstore.com/authors/bio.aspx?a=07cda0ad-... is the Alex Ionescu of https://twitter.com/aionescu/status/710477975288827904 and of https://github.com/ionescu007 . It's difficult to show a connection in that direction. The Alex Ionescu of https://alexionescu.net/#contact lets people connect the dots — a different set of dots, mind you.

* Knowing that https://github.com/ is the real GitHub. If this is a problem for you, then you have more serious and urgent problems than viewing a PDF document. (-:


You shouldn't be. The speakers are paid, the conference concentrates on professionals, and it would be extremely bad form for a presenter to hack participants. The people who run these conferences would take such a threat extremely seriously and you can bet law enforcement would be notified and very well informed.

To the point that I would trust a PDF from BlackHat _more_ than I would trust one from any other scientific or professional conference.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: