Google Desktop indexes Password protected Office Documents
Just discovered a rather nasty security flaw of Google Desktop, it seems it
gets a bit overzealous in its search to index documents
Create a password protected word or excel document and save it. Give it a
few minutes and then search for the file name or contents. Google desktop
appears to be able to open the file and display the contents regardless of
the encryption. It also displays the 1st few lines of the encrypted file in
the search results and if you click on the "cached" link it can display the
entire contents of the file.
I can only assume Google desktop has indexed the file when its open in Excel
or Word and it doesn't actually crack the encryption on it after its saved
to disk.
When you click on the filename returned in the search results you will get
prompted by word or excel to enter the password as usual.
My only advice is to specifically exclude the paths to any password
protected files. Also exclude paths to any encrypted PGPDisk or TrueCrypt
mapped drives as Google Desktop will also return results in these even when
not mounted.



0 Comments:
Post a Comment
<< Home