Quantcast
PC World: Technology Advice You Can Trust
Find a Review
Free Newsletters
Receive the latest reviews, how-to's, news, and more.
Security & Privacy
Tech-Savvy Business
Weekly Brief
WiFi Finder
Locate wireless services by a specific address, city, state, country, airport, or zip code.
RSS Feeds
Get our latest content via convenient RSS feeds.
Latest News
Today @ PC World
Become a PCW Member
Join the community and start enjoying the benefits:
  • Get tech advice from thousands of PC World Members
  • Rate and recommend the latest tech products
  • Share your thoughts in blog and article comments
  • Get free excerpts and exclusive discounts on Super Guides
Read More About: Current Events

Exposing Excel's Dirty Little Secret

Spreadsheet could potentially reveal confidential data, but Microsoft says the problem is only one of perception.

John Fontana, Network World

Monday, December 17, 2001 7:00 AM PST
Recommend this story?

Microsoft Excel, the predominant spreadsheet in use today, contains a feature that could expose sensitive corporate data once the document is distributed within a company or among trading partners.

That feature is drawing an increased level of attention from researchers and Excel users alike as its implications become more fully understood. One expert calls it "as potentially damaging" as many of the most recent viruses.

Excel has features that allow spreadsheet creators to hide, lock, and/or password-protect data and mathematical calculations used in original documents. These features seemingly provide a measure of data security to conceal specified data from prying eyes.

In reality, that data can be exposed by any end user who can execute a simple copy-and-paste procedure. It takes fewer steps to reverse the security than it does to set it up.

When Excel data is copied using the "copy all" command and pasted into a new spreadsheet, it exposes the hidden and password-protected cells, which may contain data such as employee salaries, return-on-investment or expense report calculations, or request-for-proposal formulas. Excel users must execute an "unhide" command in Excel before they see the previously protected data in the spreadsheet copy, but in non-Microsoft spreadsheets the hidden cells are automatically revealed.

Only an Illusion

Unless access to the document is locked down, Excel cannot protect any information, although the program gives the illusion that it can, critics say.

The result for large corporations is that millions of Excel documents shared between co-workers and business partners could become a security breach for confidential data.

"I thought there was some security. I had no idea," says Jeff Ostroff, the owner of a Web site that offers car-buying tips and free spreadsheets designed to calculate deals. Ostroff's site states that password protection is used on Excel so viewers cannot manipulate or hijack his formulas. "I'm surprised it is that easy to expose the data," he adds.

Ostroff believes that 99 percent of users don't know the secret. "We get requests for the passwords all the time from people who want to change the formulas."

Some say the issue creates a major security concern.

"The method of password-protecting data in Excel is something companies around the world rely on," says Rick Sturm, president of Enterprise Management Associates, a consulting and research firm that encountered the security hole when it was creating spreadsheets to share with clients. "This is like putting a password on a document while also supplying a Post-It Note revealing the password. It's as potentially damaging as some of these recent viruses that have spread around the world."

A simple example, according to EMA researchers, is that a user could copy and paste an expense report to another spreadsheet as a way to expose a password-protected mileage calculation formula. The mileage reimbursement figure could be increased from .31 to .81. The user would then save the document with the same name as the original and send it back, even password-protecting the new formula.

Display Only

Microsoft officials say the ability to password-protect and hide data is not a "security" feature but a "display" feature. That means that while creators of spreadsheets can hide data from display, or protect it from manipulation on the original document, they cannot safeguard or secure it from view or manipulation if another user copies and pastes the data

Experts say perception is the critical factor.

"The key question is what does the typical Excel user expect," says Richard Smith, an independent Internet security and privacy consultant and former chief technology officer of the Privacy Foundation.

"The user is led to believe you get some level of security," Smith says. "People's expectations of the feature are different from Microsoft's. It's a classic overselling of a feature and when issues are revealed Microsoft backtracks. How are customers supposed to read Microsoft's mind?"

Many have not, but Microsoft officials say Excel is no way to safeguard data.

"If you give someone read access to an unencrypted file, there is really no way to protect the data," says Jeanne Sheldon, director of engineering services for Microsoft Office. "If you are trying to protect data this is not the way to do it."

Microsoft suggests a relational database for that level of security. However, Sheldon says Microsoft will clarify the intended use and limitations of hidden and password features in the next version of Excel, which likely won't ship until 2003.


For more information about enterprise networking, go to NetworkWorld. Story copyright 2008 Network World Inc. All rights reserved.


Recommend this story?
Related Searches: microsoft excel spreadsheet security flaw
HP Ink Center
Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...
CDW Solution Center
Deliver speed and scalability in your storage systems. Find out how at the CDW Solution Center.
Asus Notebook Center
Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more at the Asus Resource Center.
Intel Processor Technology
Which Intel Processor is Right for You?Centrino, Core 2 Duo, Core 2 Quad, Core 2 Extreme? Check out the Intel Technology Center for more info...
Are you a gamer?Visit the Intel's Gaming section for the latest downloads, hottest gaming events and to learn about Intel & Gaming.
See what Intel can do for Vista...Discover how Windows Vista technology work in the benchmarks with Intel Centrino processor technology.
VoIP Web Demo
Join Altigen for a Live Web Demo and learn how VoIP technology can improve your business communications.
The Future Sales Force - A Consultative Approach
This white paper discusses the challenges of selling complex products and services, and the new skill sets sales professionals must employ.
Latest News
File-sharing sites are still doing brisk business, but few users see reason to go legit. 17-May-2008
Microsoft says its software conversion tools to enable Macs to read Open XML files will ship in June. 17-May-2008
The One Laptop Per Child effort cuts a deal with Microsoft to run its OS. 17-May-2008
Besides avoiding Vista, developers are still writing for the older version of Microsoft Office. 17-May-2008
A survey finds that almost a third of households get along fine without Internet access. 17-May-2008
Nortel surveys gadget-users in search of "hyperconnected" workers. 17-May-2008
The Guinness Book of Records confirms Grand Theft Auto IV takes the crown for debut entertainment sales. 17-May-2008
The malware continues to grow, hitting the dubious distinction of biggest spammer. 17-May-2008
A strong showing in April means Nintendo's console will likely surpass Xbox 360 sales sooner than expected. 17-May-2008
Hewlett-Packard's acquisition of Electronic Data Systems won't hurt Dell in the next few years, but it could affect Dell's... 16-May-2008

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)