Version: 2008
  • On The Insider: Britney's Bikini-Clad Top 10

January 20, 2005 3:48 PM PST

Flaw found in Office encryption

  • 9 comments
The data protection feature in Microsoft Word and Excel documents has a major flaw that could allow snoopers to decode password-protected files, a security researcher has warned.

The problem arises because Microsoft programmers did not implement the encryption correctly in its Office applications, Hongjun Wu, a cryptographer at the Institute of Infocomm Research in Singapore, wrote in a paper on the topic.

"A lot of information could be retrieved from those encrypted files," Wu said in the paper. "If anyone has used the encryption in Microsoft Office...then it is time for him/her to assess the damage that has been caused."

Microsoft said Thursday that it has begun investigating the flaw.

"Our early investigation indicates that this issue poses a very low threat for customers," Microsoft said in a statement sent to CNET News.com. "In some cases, an attacker may be able to read the contents of an encrypted file, if multiple versions of that file are available to the attacker. The attacker would need to have access to two distinct files with the same name that are protected by the same password in order to attempt to exploit the vulnerability."

In the world of cryptographers, encryption schemes that encode more than one message using the same key are seen as flawed. That's because a comparison of the information in the encrypted messages can significantly shorten the search for the correct key to unlock the messages.

The Microsoft Office flaw is the latest issue that Microsoft has had with implementing encryption in its products. Security researchers have taken the company to task repeatedly in the past for the weak passwords in previous versions of the Windows operating system. Moreover, the company was at the center of a debate in 1999 on whether the code keys central to Windows NT security were actually secure.

The current issue is almost identical to the weak system key issue in 1999, said Bruce Schneier, chief technology officer of Counterpane Internet Security and author of "Applied Cryptography."

"This is a kindergarten crypto mistake," Schneier said. "And to make it twice is worse."

Schneier, who wrote about the issue on his blog earlier this week, hammered at Microsoft for not learning from past mistakes.

The software maker said that it had not uncovered the newly reported vulnerability in its code reviews, but noted that the flaw appeared similar to a previous flaw.

Microsoft also said it would review the cryptographic code in Office. "Upon completion of this investigation, Microsoft will take the appropriate actions to protect customers, which may include providing a security update through our monthly release process," the company said.

See more CNET content tagged:
encryption, flaw, attacker, Microsoft Office, researcher

Add a Comment (Log in or register) (9 Comments)
  • prev
  • 1
  • next
Why any corporation would rely on MS ...
by ordaj January 20, 2005 2:28 PM PST
...for security is beyond me. How many examples do we need?
Reply to this comment
No idea
by January 20, 2005 4:40 PM PST
Maybe it is the reason that people defend their shoddy practices constantly.
Quit picking on Microsoft
by System Tyrant January 20, 2005 5:45 PM PST
It's the best they can do with the money they have. It's not like were talking about a multi-billion dollar company that can afford to secure their software.

You know for such a cheap software package what do you expect. It's not like those office tyrants like Wordperfect or Open office.

You guys just need to stop picking on Microsoft.
View all 2 replies
Office security
by 8r1ck January 21, 2005 8:43 AM PST
If you have a password protected Office doc, open it in Office 2003 and save it as XML, then edit the XML and turn the password protection off, ha!
Reply to this comment
What's your point?
by David Arbogast January 21, 2005 10:18 AM PST
If you are saving all your files as raw XML, you obviously don't rely on file security anyhow... This is not a flaw of any kind.
View all 2 replies
(9 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Microsoft (-0.30%) -0.09 29.54
Dow Jones Industrials (1.33%) 136.49 10,406.96
S&P 500 (1.45%) 15.82 1,109.30
NASDAQ (1.38%) 29.97 2,197.85
CNET TECH (0.88%) 14.01 1,601.19
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right