Backdooring MS Office documents with secret master keys

Backdooring MS Office documents with secret master keys

Recent MS Office documents are normally encrypted very strongly, making them difficult to brute force. However, there are techniques an attacker can use to secretly backdoor these encrypted documents to make them trivial to decrypt. Cloud environments may be more dangerous than thought as it is not possible for users to confirm the security of their encryption and it would be easy for cloud providers (or advanced attackers with access to those cloud providers) to backdoor encryption in undetectable ways. I believe that this is a serious problem that the security industry needs to consider.

Presented by