
According to CNet News.com, Gartner is warning that the advanced metadata functinality in Windows Vista, intended
to allow users to better organize their files,
could pose a security hazard. The leader on the story pretty much sums
it up: "Windows Vista will improve search functionality on a PC by letting users tag files with metadata, but
those tags could cause unwanted and embarrassing information disclosure." How's that? Well, to steal their
example, if you organize files with tags like "good customers" and "bad customers" then send a file
to such a customer the metadata would be sent with it and some snooping would reveal what you really think of them.
Vista will ship will a basic metadata removal tool, but the number of business users likely to use it (much less know
that it's there) is, I think we can safely assume, close to zero. The article cites Merc and SCO, both companies
who have been burned by sticky metadata in the past.
Tags: metadata, security, vista, windows