US military security defeated by copy and paste

Experts have warned users to be careful with document management procedures after a serious breach of US military security when classified information was revealed by a simple copy and paste of a document from a PDF format.

The document was a report written after an investigation into the death of Italian citizen Nicola Calipari at a checkpoint in Iraq. The document contains both classified and unclassified information about what happened at the traffic control points in Baghdad on 4 March, the day of the incident. The US military has since removed the offending document from the Internet, but not before it had been copied and republished on several Web sites.

The military made an error when it chose to simply black-out certain words and paragraphs from the original classified document instead of removing the actual information. This means that if the document was read or printed, the 'censored' information would be safe. However, by selecting the document text and using the copy and paste function, the document could easily be reproduced in its entirety on any word processing application.

Samia Rauf, director at document security specialists Workshare in Asia Pacific, said this kind of mistake was common -- the information was hidden but not removed.

"[The US military] had blacked out the text but not protected the document at the perimeter level. Just PDF-ing a document on its own does not hide sensitive information. It needs to be stripped out at the core level," said Rauf.

According to Rauf, the problems associated with hidden data is not restricted to the PDF format. She said it is actually far more common for people to make this type of mistake when using an application like Microsoft Word.

"Every single Word document contains metadata but the scary thing is that 90 percent of the population don't know it exists. Metadata has a useful purpose. If a document crashes you can do an auto-recover and it will bring everything back for you. Anyone can make this mistake - we heard a story about a law firm losing its clients because documents went out with 'track changes' enabled," said Rauf.

The document is available in its original version here.

Advertisement

Talkback 1 comments

    I found this article an intere ...Anonymous -- 09/05/05

    I found this article an interesting & effective reminder of the double-edged nature of using the internet to promulgate official information.
    However, I was utterly appalled to find that you offer readers a hotlink to the un-sanitised cl****ified document itself. Have you no conscience? Some of the info which was blacked out was hidden to protect the lives of soldiers serving in Iraq right now. I am certain that if the editor's son or daughter was serving in Baghdad, you would not be so quick to put kids' lives on the line to boost your own ratings/profits.

Latest Videos

Blogs

  • Darren Greenwood Telecom NZ savings damage prospects
    If Telecom NZ wants to have any of the NZ$1.5 billion the government intends to spend on its new broadband network, it had better think long and hard before offshoring 1500 jobs.
  • Array iiNet: The whys and what nows
    Last week the Federal Court ruled that internet service providers are not responsible for copyright violation by their customers. This is an important decision not just for iiNet, which spent around $4 million defending the case, but for all ISPs in Australia and, indeed, globally.
  • Array Govt, hurry up with releasing data
    A programmer scraped data from the My School website to make some really cool heat maps showing regions of smart schools — no thanks to the government, which didn't supply the data in any useful kind of format.
  • More blogs »

Tags

Back to top

Featured