ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Office applications Toolkit

Don't be undone by hidden information

Published: 25 Jan 2006 16:10 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Several years ago, I read a story about how authorities exposed a spy and later convicted him of espionage with evidence recovered from a used typewriter ribbon. Of course, simple typewriter ribbon imprints are nothing compared to the hidden information littered in application data files.

Regardless of whether recovered information is incriminating, any information leakage is a security threat. Any application that tracks changes to files has the potential to leak information when users share that file with someone else.

While Microsoft Word is one application that's capable of tracking changes, countless others exist — and it isn't a new problem. But it's important to note that tracking changes to data files is itself not a bad thing.

Being able to track changes, undo mistakes and collaborate on document creation are essential features for business. The concept of groupware wouldn't even exist without features to track changes.

But these very features can often lead to the exposure of confidential information or reveal private thoughts or intentions. Microsoft even warns users of this issue.

Remember: the fault lies not with the ability to track changes but with the users' lack of understanding of the functionality. Tracking changes during the editing process can be important, but a final document should be completely free of all changes and hidden information, particularly if it's a public document or one that will travel outside of the company in some way.

Of course, emailing Word documents is a common practice for many organisations, so how can companies avoid this problem?

The first step is education. Few companies I asked even knew that Word tracks changes to documents. Both large and small companies unwittingly pass this hidden information in documents because they don't realise the tracking occurs.

Don't blame Microsoft — tracking changes is essential to collaboration, and this feature is a benefit. Instead, consider using a "working" document and a "final" document.

When you're ready to finalise a document, use a different format, such as a PDF or even plain text. PDFs are quite useful for high-resolution, unalterable Web documents, and I recommend them as an alternative to Word for final document creation for this reason.

How do people find this hidden application data? First, they can simply tell Word to display all changes. In addition, there are tools that can reveal changes and other hidden information. Tools such as Antiword and Catdoc can reveal hidden application data in Word files, and they're popular because they allow UNIX users to view Word documents.

I'm not encouraging people to actively seek out hidden information in public or private Word documents, but it's important that organisations realise that these tools exist and that other people are using them.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
26 out of 57 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

ERP Project Manager 38k-42k Peterborough Manufacturing

Intermediate to advanced skills in MS Excel, MS Word and MS PowerPoint required. Track, organize, design and lead the ERP project and associated ...

Asset Reporting Manager

Skills, knowledge & experience - Vendor management and or asset tracking reporting and software license management. Note that this does not extend to ...

Business Analyst / Requirements Analyst - Hampshire

You will be have a track record of working with clients to extract and document business requirements, using formal methods. You will be assisting in ...

Featured Talkback

Why do so many (virtually all) software packages think that they are so important that they have to be started automatically every time the computer boots? What is the largest number of "speed access", "update check", "camera download" and whatever other background programs you have ever seen running? Of those, how many did you really need?

By: J.A. Watson

Read full story:
Annoying software: a rogues' gallery

Discussions

AdamW AdamW

Linux, Laptops and Dual Displays

Saturday 26 July 2008, 6:34 PM

2 comments
keithmv keithmv

Password Deadlock

Saturday 26 July 2008, 12:02 PM

2 comments

Vista Upgrade Blog

Microsoft's pre-modern message puts a...

Over at ZDNet.com, Ed Bott reports a first sighting of Microsoft's eagerly awaited $300 million ad campaign. Already the cause of much speculation, the consensus is that this will be... More

8 comments

A $40 CONSUMER-class router has create...

Believe it or not I don't work in IT, haven't for 7 years. Yes I work with Microsoft's Windows XP Embedded and as a result I have to know a lot about the OS, the kernal, Win API calls... More

Post a comment

Sick Puppy Redo

I generally follow a dispassionate investigative process when trying to discern what happened when a project goes bad. Although its a low priority item, it gets done simply because... More

Post a comment