Feeds

French MoD questions OpenOffice security

Quit your sniggering Microsoft

Intelligent flash storage arrays

The French Ministry of Defense has reportedly raised a red flag on OpenOffice, saying the open source desktop suite is less secure than Microsoft's product.

A classified report by the ministry into OpenOffice has apparently concluded the suite is more susceptible to attack from macros than Microsoft Office.

Details of the report are scarce, but one sticking point appears to be the fact OpenOffice - unlike Microsoft's Office - does not bombard the end-user with warnings before opening a macro. At least one vulnerability uncovered in OpenOffice - fixed in a patch released this month - saw some macros invoked even after the end-user had disabled the function.

Publication of the report comes as OpenOffice sees growing use in government circles across Europe as an alternative to Microsoft's Office. Recent converts in France include the Direction Generale des Impots - rolling out OpenOffice to 80,000 clients ripping out Office 97 - and the French gendarmerie with 104,275 personnel.

The report is unlikely to dampen enthusiasm for OpenOffice and will no-doubt be brushed aside by supporters of the suite as something the community can fix. Indeed, the MoD is expected to present its findings to OpenOffice.org.

Supporters will also, rightly, point to the shameful security record of Microsoft Office. Malware writers have gone beyond just Outlook to crack open Word, Excel and PowerPoint as a means to gain control of users' PCs.

That said, you can be sure the existence of the report will be seized upon by critics of OpenOffice and open source as proof "we told you so." Furthermore, you can expect a slow uptick in numbers of exploits. The Stardust poof of concept virus was recently written to exploit macros in Sun Microsystems's StarOffice, anchored on OpenOffice, but can be modified for OpenOffice 2.0.®

Remote control for virtualized desktops

More from The Register

next story
Euro Parliament VOTES to BREAK UP GOOGLE. Er, OK then
It CANNA do it, captain.They DON'T have the POWER!
Download alert: Nearly ALL top 100 Android, iOS paid apps hacked
Attack of the Clones? Yeah, but much, much scarier – report
NSA SOURCE CODE LEAK: Information slurp tools to appear online
Now you can run your own intelligence agency
Post-Microsoft, post-PC programming: The portable REVOLUTION
Code jockeys: count up and grab your fabulous tablets
Twitter App Graph exposes smartphone spyware feature
You don't want everyone to compile app lists from your fondleware? BAD LUCK
Microsoft adds video offering to Office 365. Oh NOES, you'll need Adobe Flash
Lovely presentations... but not on your Flash-hating mobe
prev story

Whitepapers

Driving business with continuous operational intelligence
Introducing an innovative approach offered by ExtraHop for producing continuous operational intelligence.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Internet Security Threat Report 2014
An overview and analysis of the year in global threat activity: identify, analyze, and provide commentary on emerging trends in the dynamic threat landscape.