MS Office encryption flaw uncovered

MS Office encryption flaw uncovered
by bmitchell at 5:38 pm EST, Jan 19, 2005

The problem relates to the way Microsoft implements the 128-bit RC4 encryption algorithm when re-saving documents after their initial creation. In this situation it appears that the programs use the same password key and initialization vectors to encrypt different versions of the same document. Normally where the same password key is being used, different vectors should be used.

