Are Your PDFs Naked? (Windows Wednesday) [Tech Rest]

Boyinshock
Do you send PDF files to other people assuming that they are secure? I thought so too but it’s shocking how easy it is to change one.

No hacker tools needed. With Adobe Acrobat Standard 8.0 anyone can easily change most PDFs in such a way that you can’t tell it was changed.

How? All they have to do is choose Tools > Advanced Editing >Text Touchup. Then they can click in the document and replace any text that they want. Adobe even loads the correct fonts! If kids could use this for forging notes to the teacher, they’d never get caught.

What documents are affected? Any unsecured document that retains the underlying text. For instance, is you convert a Word document to a PDF it would be affected. On the other hand, most of the time when you scan a document, someone would not be able to easily change it.

The good news. It is easy to secure a PDF document. Using the same, Adobe Acrobat , select File > Document Properties and choose the Security tab. There you will find options to secure this with a password. Will this stop a hacker? No. Will this stop the average person? Yes.

More bad news. I was talking to a friend about this yesterday and she said, “You can just print the PDF, scan it back in, make whatever changes you want, and save it under the same file name.” She is absolutely right.

The moral of the story. The only way to make sure that a document you send has not been changed is to compare the original with what you receive back from them.

More good news. PDF is a good choice to avoid the potential problems with Metadata associated with Microsoft Word documents. Word retains much more information in metadata (e.g. Track Changes) than PDFs do.

I don’t recommend that you stop using PDFs. They are one of the most universal document formats around. Just be aware that someone could easily change them without your knowledge.

See also

Original post here: Craig Huggart

12 December 2007 | Adobe, Craig Huggart, PDF, Security, Windows | Comments

Comments:

  1.  
  2.  
  3.