Calling Components Safely

Clicking on a hypertext link while viewing a PDF file shouldn't be a security problem as long as you trust the viewer it invokes. But users of xpdf version 0.90 discovered that this assumption was an extremely bad one. When an xpdf user clicked on a hypertext link, xpdf started up a viewer (Netscape by default) and sent the URL to the viewer. So far, so good. But the xpdf developers decided to start up the viewer by using the system() call. That was the bad idea..

Opera Browser Beta Adds Voice, More

According to an article at DesktopLinux.com, the first public beta of Opera 8 is available for free download. It adds voice input/output and a host of other niceties. Key new features include improved RSS handling, fit to window or paper width, a start-bar for easy access to the most commonly used functions, and automatic update checks. The beta release supports Windows only, but a general release is scheduled for early 2005.