SECURITY EXPERT Bruce Schneier claims that Microsoft's Word and Excel
security protection systems have amateurish flaws which makes them easy to

 On his blog here, the writer of 'Applied Cryptography' said that VoleWare
breaks one of the most important rules of stream ciphers. That is that you
don't use the same keystream to encrypt two different documents.

 "If someone does, you can break the encryption by XORing the two
ciphertext streams together. The keystream drops out, and you end up with
plaintext XORed with plaintext -- and you can easily recover the two
plaintexts using letter frequency analysis and other basic techniques," he

 Word and Excel both use this "amateur crypto mistake" Apparently Microsoft
made the same mistake in 1999 with RC4 in WinNT Syskey. Five years later,
Microsoft has the same flaw in other products, Schneier claims. µ


