You do not need a clever exploit to recover some badly redacted PDFs. You need a text editor and copy and paste.
That sounds too simple for a serious leak. It has happened in military reports, airport-security documents and court filings.
2005: the Calipari report
The US Army published a report about the incident in Iraq in which Italian intelligence officer Nicola Calipari was killed. Parts of the PDF appeared blacked out, but the underlying text remained recoverable.
The preserved report on Wikisource records the failed redaction. The useful lesson is about the file, not its subject: content can be invisible on a rendered page and still exist in the document.
A reviewer looking only at the page could miss that distinction.
2009: TSA screening procedures
A TSA screening-procedures document posted on a federal procurement site contained improperly redacted sensitive security information. The incident prompted a Department of Homeland Security inspector general review.
The document was meant to be shared in a limited form. Covering portions of it did not make that form safe to publish.
This is why a workflow needs a check on the exported file, not just a check that someone marked the right paragraphs.
2019: a Manafort court filing
A filing by Paul Manafort’s lawyers displayed black rectangles over passages that were still accessible through copying and pasting. The American Bar Association’s account explains how text transferred into a separate document became readable.
The filing was later replaced, but replacement cannot make already downloaded copies disappear.
You do not need to repeat the exposed material to learn from the failure. The publication check happened too late.
Same mistake, different offices
These incidents span fourteen years. They do not show that PDFs are impossible to redact. They show why appearance is the wrong success criterion.
A PDF can hold text, images and annotations as separate objects. Putting a solid shape over text changes what the reader sees. It does not necessarily remove the text object.
Using a real redaction feature matters. So does applying the redactions, exporting correctly and testing the result before it leaves your control.
A check you can add today
Open the exported file in another reader. Select across the covered region, copy and paste into a plain text editor. Search for distinctive words or numbers you intended to remove.
If they appear, stop sharing that export.
Passing this test is not a complete security proof. Inspect metadata, comments and attachments too. A scan may contain both an original image and an OCR layer, and either can preserve information. High-sensitivity material deserves a more thorough inspection than a quick visual pass.
I build hddn, a browser-based PDF redaction tool. My rule is the same regardless of the editor: check the file you are about to send. A page that looks right is only the beginning.
Adapted from hddn’s guide to redaction failures.
Top comments (0)