Bug 121703 - Recuva found image which in document that opened by libreoffice
Summary: Recuva found image which in document that opened by libreoffice
Status: RESOLVED WONTFIX
Alias: None
Product: LibreOffice
Classification: Unclassified
Component: Writer (show other bugs)
Version:
(earliest affected)
6.0.7.3 release
Hardware: All Windows (All)
: medium normal
Assignee: Not Assigned
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-11-25 13:47 UTC by AccountHasBeenClosed
Modified: 2019-05-25 15:07 UTC (History)
3 users (show)

See Also:
Crash report or crash signature:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description AccountHasBeenClosed 2018-11-25 13:47:27 UTC
Description:
i found this disturbing since my document have password...but since this happened it make me feel the password if useless if someone can see image of opened document using recuva...i would like this get fixed regardless the document have password or not...i set this report to libreoffice instead of writer because i not sure if it happened to other component too...hopefully not.

Steps to Reproduce:
1.make a document(let say put 30 image) and save it then close it.
2.run recuva(portable version if you dont want to install) > choose pictures > location c:?(where i assume you have your libreoffice installation and temp set) > enable deep scan > you dont need to wait till it fully complete just press cancel when calculating time left start showing timer > bam! found your image named [00000X].png there(use thumbnail view for more easy search).
3.btw the only way to make them disappear so far is by running ccleaner wipe free space until it done, which is taking 3-4 hour on my 500gb hdd(100gb used 400gb free).

Actual Results:
its all recoverable

Expected Results:
i expected it doesnt even show up there, i mean even a browser such as firefox or chrome doesnt leave such thing there, yea i know libreoffice isnt a browser but thats really make me feel uneasy somehow...i found this very disturbing


Reproducible: Always


User Profile Reset: No


OpenGL enabled: Yes

Additional Info:
Comment 1 AccountHasBeenClosed 2018-11-25 13:52:45 UTC
if the 1st step doesnt work try save with password then close it and then open and scroll through all the image and close it again and continue to step 2...

if you remember me i'm the one with broken english reporting about image read error before.im using windows 7 32-bit and always libreoffice still...waiting that fixed version of 6.1 to go into still branch(last time i try portable version its seem okay and the problem seems to be fixed).
Comment 2 AccountHasBeenClosed 2018-11-25 14:38:13 UTC
apparently i just try a bit more testing...saving also cause image to appear in recuva result.
Comment 3 AccountHasBeenClosed 2018-12-08 06:18:36 UTC
tested with a new doc(document doesnt have password) using msword 2007(it cannot open passworded odt?just simple one time test btw and im not sure about latest version of msoffice).

the result was image opened/saved in document using msoffice 2007 didnt even show up in recuva result while document opened/saved in lo, be it have password or not, show up in recuva result list.

please reply, its been 2 week already since this report was made.tq.
Comment 4 Timur 2018-12-10 16:13:53 UTC
I'm not sure if this is about document thumbnail or image itself. I didn't reproduce saving in clear other drive. 
Whatever, LO is not a security but office product. 
For dubious user case, unlikely that LO image handling will be changed to avoid something like this. 
So I close as WontFix.
Comment 5 AccountHasBeenClosed 2018-12-10 17:12:41 UTC
(In reply to Timur from comment #4)
> I'm not sure if this is about document thumbnail or image itself. I didn't
> reproduce saving in clear other drive. 
> Whatever, LO is not a security but office product. 
> For dubious user case, unlikely that LO image handling will be changed to
> avoid something like this. 
> So I close as WontFix.

image itself...whenever the image was loaded/saved then you closed the document, you can find them in recuva list in format of png...im actually fine if they dont find it in those png format like let just say tmp format and its unopenable but its in .png format with preview of full image and recoverable, did you use ssd?trim function might kick in before you could reproduce those...

yes lo not security product...but this seriously make me uneasy considering msword 2007 didnt trigger this...and i didnt test with 6.1/2 branch yet(those version come with the new memory image handling right?).

change component to writer since im lazy to test other component...reopened since you might misunderstand what im trying to say since my english pretty crappy.
Comment 6 Timur 2018-12-11 13:23:14 UTC
I already made a decision as a member of QA. Please don't reopen yourself. 
You may add someone else from LO project to change this, though.
Comment 7 AccountHasBeenClosed 2018-12-11 16:04:32 UTC
(In reply to Timur from comment #6)
> I already made a decision as a member of QA. Please don't reopen yourself. 
> You may add someone else from LO project to change this, though.

so there nothing can be done then?ok...sorry about reopen though, im more of forum guy than bugzilla,bugzilla is confusing...how can i add someone from lo project?i dont know anyone and what is qa member?
Comment 8 Telesto 2018-12-11 17:19:54 UTC
@Buovjaga and/or Xisco
Only for verification:
I agree that leaving traces (of images) after document close has potential for leaking sensitive of information; for example when using shared pc. 
But I have no clue how other applications handle this (or not). And also no idea if this can be prevented
Comment 9 AccountHasBeenClosed 2018-12-16 02:17:27 UTC
ok last night i test again...i set lo temporary folder path to usb,its get a bit weirder here instead of being .png in recuva list the image actually took the .tmp format but still being an image as i can see the image in thumbnail view...moreover i was pretty sure the .tmp filename was that random alphabet and number generated by lo that was in the temp folder.then i run ccleaner wipe mft free space but not complete, just mft not when ccleaner start wiping free space, then i run recuva again...the .tmp gone but the .png now appear, the filename now also random number like mention above.

just in case someone want to try test with ssd/equivalent...try look .tmp if there no .png(yet?)...also i now confuse because of this result, i dont know anymore when this is happened, its either during the document opened/saved/closed(but i'm leaning to close for now since telesto said so).might want to test recuva while the document still opened vs closed...
Comment 10 AccountHasBeenClosed 2019-05-25 15:07:18 UTC
@Buovjaga @todventtu @xiscofauli ...
is this bug really not that important & no one care about this(if they know about it)?
i need an answer to stop asking...tq