ZIP Blocking and Office 2007
|
Many gateway security products don't, by default, go through the performance burden of uncompressing ZIP files and scanning the inside contents. Expect this default to change soon, if it hasn't already on your products, because of Office 2007. Office 2007 files (Word, Excel and PowerPoint) have a new format based on XML. Of course a raw XML file expressing a complicated Word document would be immense, so the actual files are compressed using the well-understood ZIP format. I've already read about problems with gateways blocking Office 2007 files by default, but it seems the security companies are working on it. I figure in the medium term this will lead to hardware upgrades, especially for smaller companies that have small, solid-state gateway security devices that can't possibly do a good job on these files. |

Comments (1)
Good point; also tip of the iceberg:
1. Outlook 2003 can't recognize Office 2007 attachments - can't see them, let alone translate them. Yes, Microsoft offers a patch, if you even realize you have this problem. Many companies and most users haven't realized it yet.
2. Many corporate networks' security/antivirus walls won't permit an encrpypted file, a ZIP file, or a safe executable (say, a self-extracting zip file).
Granted encrypted files are going to be a problem. But banning zip & self-extracting zip files? Surely the network or security tools should learn to distinguish between a compressed text or Office file and something noxious.
Zip files seem the best workaround available if an unsophisticated user or backward business hasn't enabled a way to encrypt email, or accept encrypted files. We'll always have such users but I'm constantly amazed at the nature & size of businesses who still can't or won't accept encrypted files.
Query: is there an encryption system as easy for an unsophisticated user to use & set up as receiving self-extracting zip files? Is there one that could successfully cross most antivirus barriers? Are we condemned to waiting on an IT dept in another country to recognize the need, develop & implement internal solutions, train & launch them company-wide? We grow old waiting.
This business of developing secure communications vehicles for inter-company business despite internal IT barriers deserves your attention. Thanks.
Posted by jt | June 27, 2007 3:15 PM