Corporate, Personal Secrets Revealed In Online Word Docs

from the what-have-you-written-lately? dept

A researcher from AT&T Labs is demonstrating just how easy it is to find confidential (either corporate or personal) information online with a simple test. He did some random online searches for word documents, downloaded them, and then looked at what data had been "deleted", but which the document still had hidden. Basically, the problem here is that most people don't realize just how much extra and "deleted" information programs like Word store. Microsoft claims that in the next version of Office they're going to have tools to help prevent this sort of thing.

2 Comments | Leave a Comment..

 

Reader Comments (rss)

(Flattened / Threaded)

  1. No Subject Given

    by Ed Halley - Aug 15th, 2003 @ 10:56am

    In such cases, the applications save very simplified "dumps" of their internal data structures including the recent revision history and other elements. They do this for two reasons: it's faster, and having editing records enable neat "group" work flow concepts.

    Two ideas come to mind:

    (1) disable the fast-and-historical save options until the user specifically chooses to enable them; the oblivious user should be protected.

    (2) when you save historical information, save it encrypted by default. The worst case is when the user can't unlock their own hidden historical data, which isn't all that bad. Encrypt to a machine+user specific metric, which automatically unlocks when opened by the same detected machine+user, or offer a more complete encryption path that encrypts according to a provided pki or simple password. Even WEAK encryption would be a big win here, but there are plenty of much stronger crypto standards *built into everyday operating systems*.

    (reply to this comment) (link to this comment)

  2. here are the Microsoft articles on this

    by Anonymous Coward - Aug 16th, 2003 @ 11:48pm

    Here are the Microsoft articles on this
    http://support.microsoft.com/default.aspx?scid=kb;EN-US;211209
    http://support.microsoft.com/defau lt.aspx?scid=kb;EN-US;197978

    (reply to this comment) (link to this comment)

Add Your Comment

Get Techdirt’s Daily Email
Plain Text HTML Save me a cookie
  • Plain Text: A CRLF will be replaced by break <br> tag, all other allowable HTML is intact
  • HTML: No formatting of any kind is done without explicitly being written in
  • Allowed HTML Tags: <b> <i> <p> <a> <em> <br> <strong> <blockquote> <hr> <tt>
Close
Get Techdirt’s Daily Email
Plain Text HTML Save me a cookie
Search Techdirt
And now, a word from our Sponsors..
Subscribe to Techdirt's Daily Email Newsletter

Techdirt's Daily Email Newsletter

Related Stories
Close
E-mail It