Advertisement
Promo

Office applications Toolkit

When a security feature is no longer secure

Robert Vamosi CNET

Published: 04 Feb 2004

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Question: When is a security feature not a security feature? Answer: When it's the document-protection system in Microsoft Word.

It's called Protect Documents, and it allows the owner of a document to prevent its readers from tracking changes, making comments or changing the content in forms. It can be used, for instance, to make sure a customer can't alter a price quote before printing it out and signing it.

You can locate this feature by selecting Tools > Protect Document. It's different from the encryption security feature, which locks an entire document from modification. The latter is available by selecting Tools > Options > Security.

Even Microsoft admits that the Protect Document feature is not a true security feature. But the software giant hasn't gone out of its way to tell its customers. As a result, many businesses and individuals are unaware that 'protected' documents they send out are in fact susceptible to modification. I think that's just plain irresponsible.

The vulnerability of the Protect Document feature came to light recently, when Thorsten Delbrouck, chief information officer of security company Guardeonic Solutions, announced on the security newsgroup Bugtraq that he could make changes in a 'protected' document -- without the owner of the document having any proof he did so. Delbrouck says he notified Microsoft of this flaw in November 2003.

Microsoft knew about it

Turns out this isn't exactly breaking news. Back in 2001, at the Black Hat Win2k Security Briefing, members of Russian software company ElcomSoft demonstrated the relative insecurity of all the Microsoft Excel, Word, VBA and Outlook file-protection schemes. In fact, during the 2001 presentation, ElcomSoft suggested the same method that Mr Delbrouck outlined in his Bugtraq post.

According to the ElcomSoft presenters, the password-protection flaws exist in part because of the US export rules regarding high-end encryption. In other words, to provide a truly secure Word and Excel, Microsoft would have to sell two versions: a high-encryption version in the United States and a low-encryption version for the rest of the world.

What's unfortunate is that while Microsoft acknowledged ElcomSoft's claims in a March 2001 technical newsletter, the company didn't include this information in its online FAQ about securing Word and Excel.

Only after Delbrouck revived interest in the matter did Microsoft publish a new document that redefines the Protect Document feature as a collaboration tool. Needless to say, the average Office user isn't necessarily going to know about this new definition. And certainly the name -- Protect Document -- implies (to me at least) security more than collaboration.

Secure your documents

If you want to ensure that your documents won't be edited by their readers, I recommend using non-Microsoft software. You could save your files as Adobe PDF files, although now OCR software can open and even modify PDFs. Another option is to encrypt the document with PGP Personal for Windows 8.0, an industrial-strength encryption program that costs about £50 for the full version. A free version is also available. This application will make sure that only your intended recipients can read or modify your documents. I should mention that the latest Microsoft Office System includes digital-rights management systems for Word 2003, Excel 2003 and other applications, which provide better security for your documents. Of course, to get this protection, you'd need to invest in the new Office, which costs anywhere from £110 to £398 (inc. VAT). Given the software giant's uneven security reputation, I'd put my faith in a third-party solution instead.

Related articles

PGP Personal for Windows 8.0

Review PGP 8.0 is an industrial-strength encryption program with all the features necessary to protect your files and online communications. [22 Jan 2003]


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
58 out of 101 people found this useful


Full Talkback thread

0 comments

New Products

System Center Essentials 2010 Beta 1

System Center Essentials 2010 Beta 1

If you spend more time fighting fires than adding business value through IT, it's time to look at Microsoft's comprehensive management solution for medium-sized businesses.

Chrome OS: a first look

Chrome OS: a first look

Google has released source code for a preliminary version of its Linux-based operating system. Is it destined to dominate the netbook market? Here are our first impressions.

Office 2010 Beta: a first look

Office 2010 Beta: a first look

How does the first public beta of Microsoft's next productivity suite differ from the Technical Preview? We have a hands-on evaluation.

Microsoft Security Essentials

Microsoft Security Essentials

Security Essentials is recommended if you want 'set and forget' security. If you need more robust configuration choices, or don't want to contribute to the cloud, then look elsewhere.

View all Previews

Video icon

Video

Discussions

Tezzer Tezzer

Oops!

Wednesday 2 December 2009, 7:46 PM

5 comments
1000266930 1000266930

Tezzer, you misunderstand my comment

Wednesday 2 December 2009, 6:52 PM

5 comments
Tezzer Tezzer

Excuuuuuse me!

Wednesday 2 December 2009, 4:34 PM

5 comments
1000266930 1000266930

Typical dictatorial attitude from the...

Wednesday 2 December 2009, 12:22 PM

5 comments

Vista Upgrade Blog

This Crap Site

How utterly stupid - I am ranked #40 in the top 100 - as a member of this site..... I mean HOW utterly stupid.... I have done sweet FA, I have only rejoined this site after a 3 or... More

2 comments

Microsoft Security Update: November Pa...

Apologies for this late update to our core Patch Tuesday update. Here is a summary of the update .... The November Patch Tuesday update from Microsoft follows the largest patch and... More

Post a comment

Windows 7 pricing all over the shop..a...

I really think Microsoft have made a mess of Windows 7 pricing. They got the product right, yet there initial pricing of at around £44.95 for the full version of Windows 7 Home Premium... More

7 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters