On TV.com: THE GIRLS NEXT DOOR photos
BNET Business Network:
BNET
TechRepublic
ZDNet

By Munir Kotadia
Posted on ZDNet News: Jan 7, 2004 7:26:00 PM

Microsoft has hit back at critics of Word's password-protect feature, which the company has admitted is not safe from hackers.

The tool is intended to make collaboration easier, Microsoft told ZDNet UK, explaining that users should invest in digital signatures or an Adobe Acrobat-type application if they want security.

A set of relatively simple instructions on how to bypass the security of a password-protected Word document was published on the Internet on Friday. Thorsten Delbrouck, chief information officer of German security company Guardeonic Solutions, informed Microsoft about the vulnerability in November 2003. A week later, Microsoft updated its Knowledge Base to warn users that the feature should not be used for security purposes.

David Bennie, Microsoft UK's Office product marketing manager, told ZDNet UK that although Word's password protection is useful for collaborating with colleagues, it is not a security feature and should not be relied upon as such.

"If [users] are using it as a security feature then that is not correct," said Bennie. He agreed that if a company wanted to transport documents securely, they should either use digital certificates or an application like Adobe Acrobat that can "lock down" the document.

"If you are looking for secure encryption you should not be using this feature. We have lots of customers out there using password protection, but the reason they are doing that is to stop general users changing the text or whatever--and it works perfectly well for that," said Bennie.

However, Delbrouck believes Microsoft is attempting to play down the problem because it cannot be fixed. "I doubt there is much they can do about it, because they have to be backwards-compatible with their file format, which keeps changing," he said. "I think the only possible solution for them was to play down the problem."

  • Talkback
  • Most Recent of 32 Talkback(s)
Come on!!!
Secure to who?

Security is a myth. There is no such thing as a truly secure product or system.
To me, my network is secure. I have firewalls & SPI & NAT's & AV's & MessageLabs & Backups, bu... (Read the rest)
Posted by: SteveHoot Posted on: 01/20/04 You are currently: Logged In as: a Guest  | Login | Terms of Use
Passwords aren't for security!  prime21 | 01/07/04
Actually, this one ain't so bad ...  coffeenite | 01/07/04
Right! So M$ KNOWINGLY misrepresented the security of "passwords!"  dicktaurus@... | 01/07/04
Nah ....  coffeenite | 01/07/04
features!  stephen732@... | 01/07/04
That was a good post! (grins)  coffeenite | 01/08/04
The problem though...  msdead | 01/08/04
True ...  coffeenite | 01/08/04
sniff  vdraken | 01/07/04
Lets be real  Suicida| | 01/07/04
My point is that the average user is unaware the password is useless...  dicktaurus@... | 01/08/04
Someone thought they were for security?  ac2_z | 01/08/04
A False Sense of Security?!?  coffeenite | 01/08/04
Come on!!!  SteveHoot | 01/20/04
Wor d Doc security  Domb2 | 01/07/04
Let's be fair people  KeithRisler | 01/07/04
Cant be fixed?  vdraken | 01/07/04
ms admits security bad in word  JWatson77 | 01/07/04
M$ is always lying to its customers...  cdturri | 01/07/04
Use OpenOffice.org  jeffpow | 01/07/04
locking down forms  yucantrak | 01/07/04
Password not for security  theo_durcan | 01/07/04
Your comment...  msdead | 01/08/04
Come on!  peggy.j.settel@... | 01/08/04
Right Track . . .  Misterecs | 01/08/04
GIVE 'EM A BREAK!  Misterecs | 01/08/04
Perspective  CAJonesIT | 01/10/04
The real problem  trd_z | 01/08/04
The real problem  trd_z | 01/08/04
Does this really work?  support@... | 01/09/04
same experience here  agbags | 01/10/04
Really?  chunt | 01/09/04

What do you think?

Storage Virtualization

  • In virtual environments, storage matters. It influences everything from application availability and disaster readiness to power consumption and TCO. Bottom line: Don’t defeat the purpose of your consolidation by skimping on storage.
  • From our sponsors
  • EMC Corporation
  • ESG applauds new CX4 in analyst report According to ESG, it's hard to find much missing in the new CLARiiON CX4. Read the report to learn more »
advertisement
Click Here