https://bz.apache.org/ooo/show_bug.cgi?id=125954

orcmid <[email protected]> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|UNCONFIRMED                 |CONFIRMED
     Ever confirmed|0                           |1

--- Comment #22 from orcmid <[email protected]> ---
ANALYSIS

 1. It is confirmed that hidden sections are removed from documents send
directly from Apache OpenOffice *and* LibreOffice.

 2. It is also confirmed that hidden section are not very secret, and that some
applications reveal them automatically.  That is true for the Microsoft Office
Word 2016 handling of ODT files.  (WordPad, on the other hand, does not show
the hidden section [;<).

OBSERVATIONS

 1. The removal of hidden information is intended to accomplish two things:
inadvertent disclosure and also protection of recipients from certain
document-security vulnerabilities involving covert content and silently mining
content on an user's computer.

 2. The removal of hidden information when "Send Document as E-mail ..." is
used is appropriate default behavior that protects casual users.  It is also
important that the behavior with Apache OpenOffice and LibreOffice are the
same.

 3. That does not mean there could not be an option to retain hidden content,
although that involves expert users able to understand the implications and to
accomplish their purposes despite the use of hidden sections not being designed
as a privacy mechanism.  The current default should be preserved.

-- 
You are receiving this mail because:
You are the assignee for the issue.

Reply via email to