US military security defeated by copy and paste

Experts have warned users to be careful with document management procedures after a serious breach of US military security when classified information was revealed by a simple copy and paste of a document from a PDF format.

The document was a report written after an investigation into the death of Italian citizen Nicola Calipari at a checkpoint in Iraq. The document contains both classified and unclassified information about what happened at the traffic control points in Baghdad on 4 March, the day of the incident. The US military has since removed the offending document from the Internet, but not before it had been copied and republished on several Web sites.

The military made an error when it chose to simply black-out certain words and paragraphs from the original classified document instead of removing the actual information. This means that if the document was read or printed, the 'censored' information would be safe. However, by selecting the document text and using the copy and paste function, the document could easily be reproduced in its entirety on any word processing application.

Samia Rauf, director at document security specialists Workshare in Asia Pacific, said this kind of mistake was common -- the information was hidden but not removed.

"[The US military] had blacked out the text but not protected the document at the perimeter level. Just PDF-ing a document on its own does not hide sensitive information. It needs to be stripped out at the core level," said Rauf.

According to Rauf, the problems associated with hidden data is not restricted to the PDF format. She said it is actually far more common for people to make this type of mistake when using an application like Microsoft Word.

"Every single Word document contains metadata but the scary thing is that 90 percent of the population don't know it exists. Metadata has a useful purpose. If a document crashes you can do an auto-recover and it will bring everything back for you. Anyone can make this mistake - we heard a story about a law firm losing its clients because documents went out with 'track changes' enabled," said Rauf.

The document is available in its original version here.

Advertisement

Talkback 1 comments

    I found this article an intere ...Anonymous -- 09/05/05

    I found this article an interesting & effective reminder of the double-edged nature of using the internet to promulgate official information.
    However, I was utterly appalled to find that you offer readers a hotlink to the un-sanitised cl****ified document itself. Have you no conscience? Some of the info which was blacked out was hidden to protect the lives of soldiers serving in Iraq right now. I am certain that if the editor's son or daughter was serving in Baghdad, you would not be so quick to put kids' lives on the line to boost your own ratings/profits.

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Love me, tender
    Considering how expensive and drawn-out tender processes can be to solve problems that might be very immediate, it's little wonder that the Victorian Police IT department tried to work the tender exemptions system.
  • Array 2009 funding drought rolls on
    For Australian start-ups looking for venture capital, 2009 was a very bad year. 2010 may be no better.
  • Array Can not-so-smart meters help the NBN?
    It was interesting to witness Conroy's recent enthusiasm to spruik the NBN's role in supporting the Smart Grid, Smart City initiative. What a pity that Conroy hadn't yet seen the damning report from the Victorian auditor-general about that state's smart-meter roll-out.
  • More blogs »

Tags

Back to top

Featured