In our daily life, we often think of PDF documents as static and immutable. This mental model is wrong.
In this presentation, we give a brief overview of PDF (in-)security and describe a novel kind of attack where a malicious PDF document can
* change its displayed content with time (while the file stays the same)
* display different content to different people
We publish details and a proof of concept at https://github.com/vlkl-sap/perfidy-deception-fraud
Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn23/talk/G7FMP3/