Networking: Not-so-secret documents

February 6, 2006

Last fall a controversy erupted when the details of the assassination of former Lebanese Prime Minister Rafik Hariri were revealed in a United Nations report -- after a cunning reader spotted a "track changes" mistake in the layout of the document. That political controversy is one of the latest tempests to emerge over "metadata," or data about data, contained in Microsoft Word and Adobe PDF documents, easily accessible by millions of readers over public networks like the Internet, experts tell United Press International's Networking.

By clicking on the "track changes" feature in Word, readers can see who wrote a particular document, when it was written, what edits were made and comments made by editors and redactors -- something government officials, working with official secrets, or confidential information, most definitely don't want released for review in the court of public opinion. By deleting text blocks -- used to blacken out information in PDF files -- readers can see what was originally written there.

There is also a danger that computer-savvy terrorists could use the "track changes" feature of the word-processing software and other techniques to access data the U.S. government doesn't want them to see -- such as negotiating options discussed in earlier drafts of government documents, troop-deployment schedules or other top-secret information.

The National Security Agency, the government's electronic eavesdropping agency, worried about these, and other, digital document threats, recently issued guidance to federal agencies about how to properly "sanitize" Word and PDF documents about to be sent out over networks. It is up to each federal agency, however, to implement the suggestions, experts said.

The government isn't the only one concerned about metadata problems -- companies are too.

"The specific concern that lawyers have had -- and that I believe NSA is concerned about -- is text remains with the document when it is saved as a file and delivered to another party," Paul Dalton, an attorney with the Dallas-based law firm of Cowles & Thompson, P.C., told Networking. "Microsoft Word, in particular, stores information that has been deleted from a document within the document file itself. That's how the 'undo' and 'redo' features -- which we all find helpful -- are able to bring back several levels of prior text as one edits a document."

Another vulnerability is the "comments" feature in Word, Dalton said. "Those comments normally are hidden from view until the user turns them on using the 'show' feature under 'track changes.' If one creates a document and sends it to someone else for review, that person adds his thoughts using the 'comments' feature, and the document goes out without those comments having been affirmatively removed, a subsequent reader would be able to see all of the initial reviewer's recorded observations."

Finding that hidden text could be very embarrassing to a lawyer who represents the facts and the law one way to one group of people, then writes another, completely contradictory view in a document draft, and then, lastly, changes what is written there for public consumption in the final draft of the document.

Computer experts have known about metadata problems for years, but the problem is just now coming to public attention, especially as communicating over the Internet and private networks has become the norm.

"The action by the NSA, however, starts the ball rolling on another issue -- standards of care for the people and enterprises that are delivering the electronic document," Dan Venglarik, an attorney with the law firm of Davis Munck Butrus, P.C., told Networking. "But with the U.S. government now having defined specific procedures for ensuring that confidential information is not inadvertently 'leaked,' a definite threshold is apparently set for negligence purposes. Damages on such negligence claims are likely to be difficult to prove in most cases, but I would not be surprised to see some cases starting to be brought over the next few years."

These problems with metadata are more than a mere "formatting glitch," said Joe Fantuzzi, chief executive officer of Workshare Technology Inc., a developer of document-management technology with offices in London and San Francisco. "There are serious security concerns with the major document formats that businesses and the government use every day," said Fantuzzi. "And if these problems can happen at the White House and large companies like Merck, they can happen anywhere."

Copyright 2006 by United Press International


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 4.3 /5 (8 votes)


February 6, 2006 all stories

Comments: 0

4.3 /5 (8 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • UK: Millions of customer records sold
    created Nov 17, 2009 | popularity not rated yet | comments 0
  • Vietnam Internet users fear Facebook blackout
    created Nov 17, 2009 | popularity not rated yet | comments 0
  • Community education and evacuation planning saved lives in Sept. 29 Samoan tsunami
    created Nov 05, 2009 | popularity not rated yet | comments 0
  • Genetic tests for UK asylum seekers draw criticism
    created Nov 05, 2009 | popularity not rated yet | comments 0
  • Microsoft raises cloud computing concerns
    created Nov 05, 2009 | popularity not rated yet | comments 0


Other News

Selling chip makers on optical computing

Selling chip makers on optical computing

Technology / Semiconductors

created 12 hours ago | popularity 4.8 / 5 (6) | comments 1

(PhysOrg.com) -- Computer chips that transmit data with light instead of electricity consume much less power than conventional chips, but so far, they've remained laboratory curiosities. Professors Vladimir ...


Software takes a hard look at traffic fatalities

Technology / Software

created 4 hours ago | popularity not rated yet | comments 0

Bergen County Police and a Hackensack, N.J., drug treatment center are among a growing number of agencies using a software program to identify dangerous intersections, spot teen driving trends and reduce accident fatalities.


Taking the drudgery out of software development

Taking the drudgery out of software development

Technology / Software

created 9 hours ago | popularity 3.3 / 5 (4) | comments 2

(PhysOrg.com) -- Software developers will no longer have to reinvent the wheel when writing new programs and applications thanks to a clever new set of tools and a central repository of 'building blocks'.


Facebook creates dual-class structure, but no IPO (AP)

Facebook creates dual-class structure, but no IPO

Technology / Business

created 8 hours ago | popularity 1 / 5 (1) | comments 0

(AP) -- Facebook has created a dual-class stock structure designed to give founder Mark Zuckerberg and other existing shareholders control over the company.


Google, Yahoo zero in on Internet 'freedom' bill

Technology / Internet

created 6 hours ago | popularity 4 / 5 (1) | comments 0

Google Inc. and other Internet companies have zeroed in on a resilient effort by a Republican lawmaker to pass legislation that could restrict their ability to take a nuanced approach to operating in "repressive" foreign ...