gadgeteer.co.za
These Microsoft Office security signatures are ‘practically worthless’: Turns out it’s easy to forge documents relying on OOXML
Five computer researchers from Ruhr University Bochum in Germany – Simon Rohlmann, Vladislav Mladenov, Christian Mainka, Daniel Hirschberger, and Jörg Schwenk – describe this sorry state of affairs in a paper titled: "Every Signature is Broken: On the Insecurity of Microsoft Office’s OOXML Signatures." They were able to identify five ways to attack vulnerable documents...