3 ms·
Modern versions of Office use stronger encryption methods. Office 2013 and 2016 by default use SHA-512 with AES-256-CBC. Given the constraints when the scheme
by sheetjs 9y ago
Modern versions of Office use stronger encryption methods. Office 2013 and 2016 by default use SHA-512 with AES-256-CBC.
Given the constraints when the schemes were first devised, 40-bit represented a reasonable tradeoff given the computing power and understanding at the time.
- lvh 9y agoIn case anyone was confused as to how they use SHA-512, it appears they use it for password stretching. (I was unable to find anything about authentication tags, although I guess it's hard to get a chosen ciphertext oracle out of Excel files unless you find a computer consuming them?)
- blattimwind 9y agoI'm not so sure about that, since Excel files are not that unusual to exchange data and some web applications seem to process them automatically on some Windows server. However: these are never encrypted anyway.
- lvh 9y agoYes, hence "unless you find a computer consuming them" :-)
- 13of40 9y agoIIRC, by default the "agile" encryption scheme in office defaults to producing a key from a password with 100,000 rounds of SHA-512, with each iteration salted with an incrementing integer to prevent loops. It takes about 800ms to compute one key on a newish machine.
- btown 9y agoThis is really interesting! https://msdn.microsoft.com/en-us/library/dd924776(v=office.12).aspx https://msdn.microsoft.com/en-us/library/dd924776(v=office.1... seems to be the spec for this. Though I wonder if any vulnerabilities to this type of password stretching scheme have been discovered in the years since.
- blattimwind 9y agoThat's pretty much just PBKDF1.