Wednesday, December 9, 2009

Viewing decrypted files - vulnerability

I use Cyptainer LE to encrypt some of my sensitive files. Since they are .doc or .xls files once decrypted I use Open Office to read them. Recently my PC crashed while viewing one of those files. After a quick restart I loaded Open Office to write a document. Open Office alerted me to an unsaved file and asked if I wanted to recover it to which I said Yes. And guess what, my so called encrypted file popped up. With auto save feature on Open Office saved the file in cache.

Wander how big of an issue this is? I wander if this makes my secure data completely unsecured? How long is the data held in cache?

I found this in a Open Office forum http://www.oooforum.org/forum/viewtopic.phtml?t=65016"... Delete the file Documents and settings/userName/Application data/Openoffice.org2/user/registry/data/org/openoffice/Office/Recovery.xcu
Beware, it resets the settings for Autosave in the Tools>Options>Load/Save>General dialog. ..."