Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

How NOT to redact a PDF - Nuclear submarine secrets spilled
Sophos IT Security Blog ^ | April 18, 2011 | Graham Cluley

Posted on 04/18/2011 12:25:07 PM PDT by Still Thinking

If you're an organisation that is making public an internal document, you best make sure that you have deleted or blacked out any personal, confidential or actionable information.

The act of obscuring the sensitive information is known as "redaction", and - for obvious reasons - needs to be done properly if you care about privacy and avoiding a potentially damaging data leak.

In the old days - before PDFs and Word documents - you might have redacted a document with a thick black marker pen, ensuring that anyone who made a photocopy of the document wouldn't be able to see the censored words. Things are different with electronic media, of course.

Unfortunately, time and time again we've seen sloppy security procedures make it far too easy for unauthorised parties to view information in electronic documents that should have been properly redacted.

The last example which has made numerous newspaper headlines, involves the British Ministry of Defence, which was found to have published a PDF document online, unintentionally revealing information about nuclear submarine security.

The PDF, entitled "SUCCESSOR SSBN - SAFETY REGULATORS' ADVICE ON THE SELECTION OF THE PROPULSION PLANT IN SUPPORT OF THE FUTURE DETERRENT REVIEW NOTE", was published on the parliamentary website following requests under the Freedom of Information Act. However, although sections were supposed to be protected through redaction - it was possible to copy-and-paste the blacked-out text straight out of it.

As the Daily Star explained:

The bunglers turned the text background black - making the words unreadable - but crucially left them in place. That meant anyone wanting to read the censored sections just had to copy the text.

This was a real school-boy error to make - as anyone with even an ­elementary knowledge of computers would know how to read the "redacted" content.

If you want to learn how to properly redact Adobe PDF files, here's a great guide describing how to do it with Acrobat X Pro.

Good luck, and remember that simply marking text will not actually remove it from your sensitive PDFs. You also have to apply redactions!


TOPICS: Government; Miscellaneous; News/Current Events; United Kingdom
KEYWORDS: acrobat; adobe; foia; informationsecurity; pdf; redaction
Navigation: use the links below to view more comments.
first previous 1-2021-29 last
To: HiTech RedNeck

How can these guys be trusted with a nuclear submarine if they can’t even use acrobat properly?


21 posted on 04/18/2011 1:37:17 PM PDT by DarrellZero
[ Post Reply | Private Reply | To 20 | View Replies]

To: Still Thinking; ShadowAce

It’s a FR bug. Happened to me for a long time with one of my ping lists. (Only happened when I posed from my Android phone.)


22 posted on 04/18/2011 1:46:44 PM PDT by BuckeyeTexan (There are those that break and bend. I'm the other kind. *4192*)
[ Post Reply | Private Reply | To 9 | View Replies]

To: DarrellZero

Well, the nuke boat isn’t always trying to talk to other people and “upgrade” itself without your permission.


23 posted on 04/18/2011 1:53:49 PM PDT by Still Thinking (Freedom is NOT a loophole!)
[ Post Reply | Private Reply | To 21 | View Replies]

To: Still Thinking

The british navy has secrets??


24 posted on 04/18/2011 2:12:27 PM PDT by Hardraade (I want gigaton warheads now!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Still Thinking

Oh, trust me, I’m not defending Adobe and their crapware.

Acrobat was once an solid product, but not anymore.


25 posted on 04/18/2011 3:51:10 PM PDT by DarrellZero
[ Post Reply | Private Reply | To 23 | View Replies]

To: DarrellZero

“How can these guys be trusted with a nuclear submarine if they can’t even use acrobat properly?”

You could ask the identical question about entrusting them with the nation’s health care system.


26 posted on 04/18/2011 4:00:30 PM PDT by DrC
[ Post Reply | Private Reply | To 21 | View Replies]

To: Hardraade
The british navy has secrets??

I don't know, they won't tell me.

27 posted on 04/18/2011 4:27:14 PM PDT by Still Thinking (Freedom is NOT a loophole!)
[ Post Reply | Private Reply | To 24 | View Replies]

To: DarrellZero
Oh, trust me, I’m not defending Adobe and their crapware.

Although I actually do dislike those "features" of Acrobat, my post was mostly intended in fun.

28 posted on 04/18/2011 4:28:33 PM PDT by Still Thinking (Freedom is NOT a loophole!)
[ Post Reply | Private Reply | To 25 | View Replies]

To: Still Thinking

This is stupid. Classification requirements include rules for declassifying information, and that would include methods of scanning documents for classified information if the documents were not pure text.

The simplest way to accomplish correct redaction is to print out the document, redact it, and scan it back in.


29 posted on 04/18/2011 6:39:55 PM PDT by CharlesWayneCT
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-29 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson