I’ve never encountered malicious content in book form. Avoid PDFs if you are worried.

I’d love to hear more about why PDFs might be riskier than, say, azw or epub. Is it something inherent in the pdf format, or are pdfs so comparatively common they’re a more attractive vector of attack?

@cmc@discuss.tchncs.de
link
fedilink
English
1414d

Arbitrary files can be embedded inside a PDF (by design), such as malicious code files. Many PDF readers have security issues allowing for PDFs to automatically allow for code execution of those embedded files, or prompt the user for a click to execute the files.

Just search for something like “executable code inside PDF” and browse through the many results of examples, issues, and tutorials to see.

@sga@lemmings.world
link
fedilink
English
10
edit-2
14d

to add to it, you “can” add anything arbitrary, but it is not same as downloading a executable. Due to some really weird reasons, many parties were interested in using pdfs like interactive forms, for example some government forms, where you can fill a field, and you can add scripting to execute upon input and convey back. It is somewhat like javascript for pdfs, and then the onus is on the pdf readers to be compliant enough to execute such scripts, and provide enough access to your system. Many minimal pdf viewers do not implement these features, or for example pdf viewer in firefox has the option to execute, but disabled by default.

@sga@lemmings.world
link
fedilink
English
1014d

epubs are effectively self contained html files, but the scripting is not there (afaik)

@black0ut@pawb.social
link
fedilink
English
7
edit-2
14d

There is scripting on them, and afaik it’s actually javascript. It’s a limited version of it (the actual specification was supposed to allow for data sending and receiving, and complete arbitrary code), but it’s enough to run code. A madlad has ported doom and linux to PDF, and you can fully run them on a compliant enough pdf viewer.

LinuxPDF
DoomPDF

(My bad, I wanted to reply to a higher post, but I’m gonna leave this here cuz federation is sometimes weird with deleted comments)

@ertai@programming.dev
link
fedilink
English
313d

I believe pdfs can load remote images, which pings a server. There are other reasons, I haven’t got sufficient knowledge. Some pdf readers will offer a sandboxed mode improving security. I think zathura has this for instance.

SybilVane
link
fedilink
English
1014d

I’ve never encountered one and I download from there a lot!

Sirence
link
fedilink
English
212d

I’ve had one children’s book that Gmail flagged as a virus when I tried to send it to my nieces eBook Reader via Mail, so I deleted that and just got another instead. I didn’t bother opening the book because I didn’t not care much so it might just have been a false positive. I don’t remember which format.
It was the only one out of about 200 books that got flagged.

Chewy
link
fedilink
English
3
edit-2
15d

I haven’t seen anything except the safe pdfs, epub etc formats. Similarly to movies there shouldn’t be a risk to downloading malware unless you execute the files (e.g. double click).

AnimalsDream
link
fedilink
English
614d

Nothing malicious that I know of. 🙃

The emulation community has Redump and No-Intro for verifying the integrity of roms. Maybe we need the same for books?

Tired Board of Wood
link
fedilink
English
513d

I think I downloaded a recipe book once that turned out to be a different book about woodworking… But nothing explicitly malicious, no

Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ
!piracy@lemmy.dbzer0.com
Create a post
⚓ Dedicated to the discussion of digital piracy, including ethical problems and legal advancements.

Rules • Full Version

1. Posts must be related to the discussion of digital piracy

2. Don’t request invites, trade, sell, or self-promote

3. Don’t request or link to specific pirated titles, including DMs

4. Don’t submit low-quality posts, be entitled, or harass others



Loot, Pillage, & Plunder

📜 c/Piracy Wiki (Community Edition):

🏴‍☠️ Other communities

Torrenting:

  • !seedboxes@lemmy.dbzer0.com
  • !trackers@lemmy.dbzer0.com
  • !qbittorrent@lemmy.dbzer0.com
  • !libretorrent@lemmy.dbzer0.com

Gaming:

  • !steamdeckpirates@lemmy.dbzer0.com
  • !newyuzupiracy@lemmy.dbzer0.com
  • !switchpirates@lemmy.dbzer0.com
  • !3dspiracy@lemmy.dbzer0.com
  • !retropirates@lemmy.dbzer0.com

💰 Please help cover server costs.

Ko-Fi Liberapay
Ko-fi Liberapay

  • 1 user online
  • 78 users / day
  • 496 users / week
  • 1.16K users / month
  • 3.38K users / 6 months
  • 1 subscriber
  • 3.79K Posts
  • 89.4K Comments
  • Modlog