Greenfrog Computing

Call Us: 01246 520000

sales@greenfrogcomputing.co.uk

  • REMOTE SUPPORT
  • Team
  • Support
  • Security
  • Solutions
  • Infrastructure
  • Industry
  • More
    • About Us
    • Referral Program
    • 3CX
    • Web Design and Development
    • OpenText GroupWise
    • OpenText Filr
    • OpenText Open Enterprise Server
    • Cyber Essentials
    • Testimonials
    • Blog
  • Menu Menu

Tech Insight : Why Solid Black Bars May Be Best For Redacted Text

February 23, 2022/in Technology News/by Greenfrog Computing

In this insight, we look at how to best to avoid redacted text from being ‘unredacted’ by certain software tools, and we look at what researchers advise based on recent experiments. 

The Problem 

For businesses and organisations, the increased need for data sharing and/or making some data public can mean that certain (sensitive) parts of documents need to be obscured/obfuscated/censored for legal or security purposes (and to stop data leaks and fines). There are several different methods for achieving this in a document, including blurring, swirling, or pixelating letters and images. The issue is that some of these methods may not be effective enough and could, possibly, lead to the text being recovered/de-obfuscated using certain tools and methods e.g., the Depix tool or the ‘Unredacter’ tool. A python program like Depix, for example, is designed to recover censored text to a readable format via a simple command, and this type of tool in the wrong hand could potentially lead to a security breach. 

Challenge Issued 

The challenge of testing the level of security of pixelated text is something that researchers have focused on for some time. For example, researchers at a company called Jumpsec tested the Depix tool to see if it could recover text that has been pixelated. The results broadly showed that: 

– Using the supplied examples, text redaction with Depix was possible to a reasonable degree. 

– Using original content (not the author’s supplied example), and after taking a long time, Depix failed to recover the obfuscated text. 

It was concluded that The Depix tool poses minimal risk to security at present, as it requires specific criteria to be met to be effective BUT there is a small chance that users can depixelate images using the tool. 

Jumpsec then issued (2021) an Internet challenge for someone to develop a tool that could effectively recover censored text to a readable format. 

Bishop Fox Research

The challenge was accepted by Dan Petro, Lead Researcher at US security company Bishop Fox. Mr Petro built his own ‘Unredacter’ tool and tested it in a similar way to the Depix tool.  

Mr Petro noted that pixelation tools use an algorithm to divide an image into a grid of a given block size (e.g. 8×8) and, for each block, the redacted image’s colour is set to be equal to the average colour of the original for that same area. This “smears” the information of the image out across each block and, although it can work, it has several problems. These include characters not lining up with the blocks and bleeding over, problems with white spacing, and problems with variable-width fonts, and font inconsistency. 

The ‘Unredacter’ Tool 

The ‘Unredacter’ Tool created by the Bishop Fox researchers, however, solved many of the problems that the Depix tool had encountered, and was able to recover the text in a test image to a reasonable degree. 

The Conclusions 

The conclusions of both the Jumpsec Labs and the Bishop Fox text recovery tool experiments were the same. Both advise that, when redacting text, only use black bars covering the whole text. Never use other methods such as pixelisation, blurring, fuzzing, or swirling, and edit the text as an image. Bishop Fox’s Mr Petro also advises that using black background with black text in a Word document means that the text can still be read that just by highlighting it. This means that is not a secure method and could lead to the accidental leak of sensitive information because of an insecure redaction technique. 

What Does This Mean For Your Business? 

There are now so many ways that a data security breach could happen and although using an insecure redaction technique may seem like a more unusual one, the result could be just as devastating as other more popular types of breaches. The lessons for businesses resulting from this research are that software could possibly be used to uncover redacted text and that relying upon fast methods such as using a black background with black text is ineffective and very risky. The research shows that businesses can best protect themselves from this threat by editing the text as an image and by only using black bars covering the whole text.

Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on Pinterest
  • Share on LinkedIn
https://www.greenfrogcomputing.co.uk/wp-content/uploads/2022/02/photo-4-3.jpg 375 500 Greenfrog Computing https://www.greenfrogcomputing.co.uk/wp-content/uploads/2022/08/greenfrog-computing-logo-22-1.png Greenfrog Computing2022-02-23 00:03:182022-02-23 00:03:19Tech Insight : Why Solid Black Bars May Be Best For Redacted Text

Recent Comments

    © Copyright - Greenfrog | Registered in England 04653352 | VAT No. GB 813 689800 | Legal - T&Cs | Cookies & Privacy Policy
    • Link to LinkedIn
    • Link to Facebook
    Link to: Tech News : Ex School IT Technician Jailed For Cyber Attack Link to: Tech News : Ex School IT Technician Jailed For Cyber Attack Tech News : Ex School IT Technician Jailed For Cyber Attack Link to: Tech News : Damage Caused While Wearing VR Headsets Results in 31% Increase Insurance Claims Link to: Tech News : Damage Caused While Wearing VR Headsets Results in 31% Increase Insurance Claims Tech News : Damage Caused While Wearing VR Headsets Results in 31% Increase...
    Scroll to top Scroll to top Scroll to top

    We are using cookies to give you the best experience on our website.

    You can change your consent by clicking Settings.

    Greenfrog Computing
    Privacy Overview

    This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

    Strictly Necessary Cookies

    Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

    3rd Party Cookies

    This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

    Keeping this cookie enabled helps us to improve our website.