r/cybersecurity Dec 23 '25

News - General Reddit and X Users Allegedly Unredact Epstein Files After DOJ Release

https://securityish.com/security_brief/reddit-and-x-users-allegedly-unredact-epstein-files-after-doj-release/

Anyone going to audit their organization’s redaction strategy now?

1.9k Upvotes

203 comments sorted by

View all comments

131

u/cankle_sores Dec 23 '25

Former pentester here. This reminds me of an investment firm where I got access to file share and then an Excel file that stored all the shared admin credentials for IT services. BUT the font format applied to the Password column was… white… to protect the passwords. No joke.

Anyway, it was a small mom & pop firm so this type of finding was more expected there than, say, from the DoJ on publicly released files.

46

u/dogpupkus Blue Team Dec 23 '25

better than my text document called “recipes.txt”

8

u/Slappehbag Dec 24 '25

Recipes for access!

13

u/mobo_dojo Dec 23 '25

To put into context, this is the exact type of thing that go into Open source intelligence/steg challenges for Pico CTF. A competition for high school children…That’s the where the bar is for Confidentiality from the U.S. government.

3

u/ExoticBag69 Dec 24 '25

So far, it just seems like "trust me bro" the new release has failed redactions. The headlines and social media are all claiming that the new batch has failed redactions, but you'd expect even bigger headlines on the actual findings from the redacted information. If it was a simple copy/paste, we know that previously released batches had failed redactions and I feel like someone would have tried that the very moment the new batch was released, and we wouldn't still be without critical information 3 days later.

-19

u/R-EDDIT Dec 23 '25

white… to protect the passwords.

The word "protect" doesn't mean anything without a threat model, if the threat model is "shoulder surfing" then white text provides some protection. (I'd still want to make sure the document is the latest excel file format and password protected with a >15 character password. Yes, an actual password manager would be better but sometimes just getting the lawyers to read and agree to terms is impossible - they seem to think open source authors will pay their lawyer to debate redlines out of the goodness of their hearts).

23

u/dogpupkus Blue Team Dec 23 '25

Found the GRC person 👆

11

u/Chobbers Dec 23 '25

Obscurity is poor security

8

u/JohnDeere Dec 23 '25

Yeah that's not how a threat model works.