Does the woot16-paper RMS whitepaper still apply to Sensitivity labels?

Jonas 1 Reputation point
2021-04-01T22:17:03.657+00:00

A user sent in https://www.usenix.org/system/files/conference/woot16/woot16-paper-grothe.pdf regarding our new sensitivity labels.

Is there a CVE for this specific incident and does that apply to the sensitivity labels encryption on files?

Azure Information Protection
Azure Information Protection
An Azure service that is used to control and help secure email, documents, and sensitive data that are shared outside the company.
516 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Martin Rublik 316 Reputation points
    2021-04-08T07:30:51.953+00:00

    I believe that the attack will be still sucessful, since the protection mechanism has not changed. Anyway, the attack will be sucessful only if you have some rights on the content e.g. you can request a use license.

    Some information is also available on the researchers web site https://web-in-security.blogspot.com/2016/07/how-to-break-microsoft-rights.html

    Martin

    1 person found this answer helpful.
    0 comments No comments

  2. JamesTran-MSFT 36,371 Reputation points Microsoft Employee
    2021-04-07T20:08:43.667+00:00

    @JonasSysadmin
    Thank you for the quick response! For the MSRC case, I'd recommend reaching out to our Microsoft Security Response Center via their webpage.

    When it comes to sensitivity labels, it's recommended to Migrate from AD RMS to Azure Information Protection(AIP). With AIP, you must be the owner of the file to remove protection, or been granted permissions to remove protection (the Rights Management permission of Export or Full Control). For more info. Lastly, with the Unified labeling client, labeling and protection actions aren't supported. However, for an AD RMS deployment, the viewer can open protected documents when you use the Active Directory Rights Management Services Mobile Device Extension.

    I hope this helps!
    Thank you for your time and patience throughout this issue.

    ----------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments