02.11.2014 Views

untangling_the_web

untangling_the_web

untangling_the_web

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

DOCID: 4046925<br />

UNCLASSIFIEDfiF6R 6FFl61J8cL l:JSE et.LY<br />

Convert with Caution<br />

As part of its initiative to enhance software security and share this information with<br />

users, <strong>the</strong> National Security Agency's Information Assurance Directorate published a<br />

new guide in December 2005: "Redacting with Confidence: How to Safely Publish<br />

Sanitized Reports Converted from Word to PDF." This is a very important issue<br />

because failure to redact documents properly-whe<strong>the</strong>r <strong>the</strong>y are declassified<br />

government documents, court records, proprietary company documents-can lead<br />

not just to embarrassment but also to very serious security violations and potential<br />

risks to individuals. I call your attention to <strong>the</strong> very sad case in May 2005 in which an<br />

improperly prepared PDF document about <strong>the</strong> killing of <strong>the</strong> Italian intelligence agent<br />

Nicola Galipari in Iraq was quickly discovered and exploited by <strong>the</strong> press worldwide.<br />

Not only was classified information leaked to <strong>the</strong> world, but <strong>the</strong> lives of those whose<br />

identities were revealed were also put in jeopardy by <strong>the</strong> improper method of<br />

removing data from a MS Word file and converting it to PDF. This is an important<br />

guide and I urge you to keep a copy for yourself and your organization.<br />

"Redacting with Confidence: How to Safely Publish Sanitized Reports Converted<br />

from Word to PDF"<br />

Architectures and Applications Division of <strong>the</strong> Systems and Network Attack Genter<br />

(SNAG)<br />

Information Assurance Directorate, National Security Agency<br />

last updated 2 February 2006<br />

http://www.nsa.gov/snac/index.cfm?MenuID=scg10.3.1<br />

For details on <strong>the</strong> Calipari incident and <strong>the</strong> ensuing disclosure of classified<br />

information, I recommend an article from <strong>the</strong> Times Online (UK).230<br />

230 Simon Freeman, "Italy Releases Report into Death of Security Agent," Times Online, 2 May 2005,<br />

(14 November 2006).<br />

UNCLASSIFIEDf,'F6R 6FFl61AL l:J6E 9~JbY 603

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!