The Register® — Biting the hand that feeds IT

Feeds

French MoD questions OpenOffice security

Quit your sniggering Microsoft

Customer Success Testimonial: Recovery is Everything

The French Ministry of Defense has reportedly raised a red flag on OpenOffice, saying the open source desktop suite is less secure than Microsoft's product.

A classified report by the ministry into OpenOffice has apparently concluded the suite is more susceptible to attack from macros than Microsoft Office.

Details of the report are scarce, but one sticking point appears to be the fact OpenOffice - unlike Microsoft's Office - does not bombard the end-user with warnings before opening a macro. At least one vulnerability uncovered in OpenOffice - fixed in a patch released this month - saw some macros invoked even after the end-user had disabled the function.

Publication of the report comes as OpenOffice sees growing use in government circles across Europe as an alternative to Microsoft's Office. Recent converts in France include the Direction Generale des Impots - rolling out OpenOffice to 80,000 clients ripping out Office 97 - and the French gendarmerie with 104,275 personnel.

The report is unlikely to dampen enthusiasm for OpenOffice and will no-doubt be brushed aside by supporters of the suite as something the community can fix. Indeed, the MoD is expected to present its findings to OpenOffice.org.

Supporters will also, rightly, point to the shameful security record of Microsoft Office. Malware writers have gone beyond just Outlook to crack open Word, Excel and PowerPoint as a means to gain control of users' PCs.

That said, you can be sure the existence of the report will be seized upon by critics of OpenOffice and open source as proof "we told you so." Furthermore, you can expect a slow uptick in numbers of exploits. The Stardust poof of concept virus was recently written to exploit macros in Sun Microsystems's StarOffice, anchored on OpenOffice, but can be modified for OpenOffice 2.0.®

Customer Success Testimonial: Recovery is Everything

More from The Register

Bjarne Again: Hallelujah for C++
Plus: Now officially OK to admit you never used STL algorithms
Nuke plants to rely on PDP-11 code UNTIL 2050!
Programmers and their walking sticks converge in Canada
Interwebs taunt Sir Jony over Apple eye candy makeover
Hey Ive, Ive... add more unicorns, willya?
SCO vs. IBM battle resumes over ownership of Unix
Zombie lawsuit back and wants to suck the brains out of Linux
Red Hat to ditch MySQL for MariaDB in RHEL 7
So long, Oracle! Don't let the door hit you on the way out
Shy? Socially inadequate? Fiddling with your phone could help
App 'tells the brutal truth' about social inadequates' chatup lines
Java EE 7 melds HTML5 with enterprise apps
New release arrives with GlassFish, NetBeans support
 breaking news
'Office Facebook' firm Tibbr wants you to PAY for mobe-meetings app
Great idea. Punters won't cough for it though
 breaking news
The only Waze is Google: Ad giant tipped to gobble map app 'for $1.3bn'
Pac-Man-satnav-ish upstart in bidding war with Apple, Facebook
 breaking news
PM Cameron calls for modern, programmable computers! (We think)
IT education musings to G8 chiefs to mystify IT industry