Are there huge drawbacks to using an excel 2010 document for password management

encryptionmicrosoft excelpassword

At my old job, we used an open-source, (IMO) secure method for managing network infrastructure, and other important hosts' passwords [with Keepass]. At my new job however, it seems like they're using password-protected excel spreadsheets.

Before I made a fuzz about password security, I browsed the interwebs and found that Microsoft has been getting better at implementing encryption features to their office products.

Main questions:

  • How safe is MS Excel/office 2010's password encryption feature? I've been thinking this was an insecure way of dealing with passwords, is this not the case any more?
  • Are there many drawbacks to using an excel 2010 document for password management?

Best Answer

I wouldn't recommend it. There ARE still methods of cracking these quite easily. I personally recommend a Truecrypt volume that contains a Keepass database. It servers me well and is extremely portable. And I'm using it in an environment with thousands of passwords.

EDIT: And Keepass is already well laid out for password management. With a nice GUI(i.e., easy to see what password is which type) and built-in password generators...can't go wrong.