Contract killer: Certified PDFs can be secretly tampered with during the signing process, boffins find

Jonathon Green

Those aren’t bugs they’re features.

Admittedly not features any sane person would want, need, or consider adding to a secure document exchange format, but then PDF was never meant to be that, and nobody who’d spent more than half-a-day or so examining the spec[1] would ever think it was appropriate to use it for that purpose…

[1] And for my sins I’ve spent a lot more time than that with it…

