Live data from Hacker News

Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

usenix.org

1–10 of 158 posts

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#4

I can’t find a date for this paper, there is nothing on the web page or PDF

October 4th 2022, according to the PDF date (and according to the "We have not received any feedback from OnlyOffice as of October 4th, 2022" in the PDF).

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#5

I can’t find a date for this paper, there is nothing on the web page or PDF

The PDF ("sec23summer...") has metadata creation/modification timestamp of 20221004165319Z (October 2022). So presumably the paper was written last October and released for Usenix 2023.

(Reference [12] is from Usenix July 2022. See "Prior work" in the introduction).

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#6

I can’t find a date for this paper, there is nothing on the web page or PDF

One of the authors lists the paper as 2023 on their homepage [1], and the naming of a preprint [2] suggests summer 2023.

It's a recent paper.

[1] https://casa.rub.de/en/research/publications/detail/every-si...

[2] https://www.usenix.org/system/files/sec23summer_235-rohlmann...

Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

#10
post #8

I've heard the same for Windows code signing certs - that's it possible to modify the payload and have the signature still apply.

https://news.ycombinator.com/item?id=8203164

> These attributes are not part of the signedAttributes which is used to actually authenticate the signature

https://learn.microsoft.com/en-us/archive/blogs/ieinternals/...

> unverified data within the PKCS #7 blob itself which will not be taken into account when verifying the Authenticode signature

Post reply on HN