this post was submitted on 05 Jun 2021
16 points (100.0% liked)
Open Source
32381 readers
959 users here now
All about open source! Feel free to ask questions, and share news, and interesting stuff!
Useful Links
- Open Source Initiative
- Free Software Foundation
- Electronic Frontier Foundation
- Software Freedom Conservancy
- It's FOSS
- Android FOSS Apps Megathread
Rules
- Posts must be relevant to the open source ideology
- No NSFW content
- No hate speech, bigotry, etc
Related Communities
Community icon from opensource.org, but we are not affiliated with them.
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
You can also grab a build from KDE's build server, if you don't want to use the Windows Store.
The problem are auto-upgrades.
Would be preferable using a GNU/Linux system if wanted to avoid Woe shit.
Obviously, Linux would be better for avoiding Microsoft, yeah, but if that's not preferable for other reasons, then Windows without a Microsoft account is still massively better than Windows with it.
And honestly, I don't feel like auto-upgrades are that important in a niche PDF reader. The chance that someone targets Windows malware against Okular or libpoppler is pretty much 0. So, just grabbing a new version every year or so, is probably fine.
The thing was not specific vulnerabilities but improvements and fixes.
There could be some performance issues in some documents, crash under undetermined conditions and ofc general vulnerabilities not dependent on this tool could be taken into account.
Okular is not just document-library + own code. There are other libraries involved and Qt is a big framework with wide use and surface.
Yeah, alright, Qt is a fair point. That might actually get targeted by an attacker.
Personally, I would still deem a Microsoft account a bigger security risk than only updating Qt every few months (if you set yourself a reminder to e.g. grab the newest version every 3 months).
But yeah, that's where it starts to become subjective and not something one can give as general advice.