Live data from Hacker News

Hackers could read non-corporate Outlook.com, Hotmail for six months

arstechnica.com

41–50 of 59 posts

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#41

Earlier quoted context omitted.

I've built systems which required "helpdesk" type access and had auditing, but the problem is where do think "audit summary report" is on the TODO pile for the people getting those summaries? I'm guessing it's between "Delete unread" and "I really ought to get around to it but I'm too busy so I never do". Even when it comes to third party audit, those are ring binder driven processes. Does the audit report get genera…

I wonder how fastmail is in this regard. Makes me want to reopen my protonmail account honestly

They definitely have access to at least some things. Not sure how it's audited or managed, etc on the backend. I had a problem with something, and what they said seemed to indicate the person I messaged looked at my stored information.

I do like that they have customer service though.

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#42
post #33

I am sure glad I switched to ProtonMail.

Not sure why you were downvoted. Protonmail stores all your emails encrypted, with the encryption dependent on your password, so something like this couldn't happen there.

Seems like if ProtonMail can encrypt them automatically, then they can potentially be decrypted by someone at ProtonMail.

Reasoning:

Are emails automatically encrypted with a hash of the user password when they are received?

If the user forgets the password, how do password resets work?

Are the emails before the password reset "lost", or does ProtonMail keep a copy of the hashed password (which I suppose would be needed to log in with in the first place) to unencrypt the older emails, and re-encrypt with the newer password?

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#43
post #33

Earlier quoted context omitted.

Not sure why you were downvoted. Protonmail stores all your emails encrypted, with the encryption dependent on your password, so something like this couldn't happen there.

Seems like if ProtonMail can encrypt them automatically, then they can potentially be decrypted by someone at ProtonMail. Reasoning: Are emails automatically encrypted with a hash of the user password when they are received? If the user forgets the password, how do password resets work? Are the emails before the password reset "lost", or does ProtonMail keep a copy of the hashed password (which I suppose would be nee…

Yes, you lose your old emails if you reset password on ProtonMail.

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#44
post #2

This is totally insane. I'm totally baffled by the idea that Microsoft considers it okay for anyone except the owner to have any level of access to personal email accounts.

Having the 'owner' of the e-mail address have the only access is a better extreme than having everyone have access, but I don't think that's feasible. People within Microsoft will always have the ability to access e-mail accounts, the question is if they are the right people and how big that group of people should ever be.

If you are talking about secure e-mail cryptography philosophy along the lines of PGP, ProtonMail, et cetera, sure you can achieve that through those means. Otherwise it's a pipe dream with a product like Outlook that's built for businesses and having AD style control.

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#45
post #43

Earlier quoted context omitted.

Seems like if ProtonMail can encrypt them automatically, then they can potentially be decrypted by someone at ProtonMail. Reasoning: Are emails automatically encrypted with a hash of the user password when they are received? If the user forgets the password, how do password resets work? Are the emails before the password reset "lost", or does ProtonMail keep a copy of the hashed password (which I suppose would be nee…

Yes, you lose your old emails if you reset password on ProtonMail.

Really? are there any docs I can read related to this?

It certainly is something that users should probably be aware of. At least I would...

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#46
post #45
post #43

Earlier quoted context omitted.

Yes, you lose your old emails if you reset password on ProtonMail.

Really? are there any docs I can read related to this? It certainly is something that users should probably be aware of. At least I would...

https://protonmail.com/support/knowledge-base/reset-password...

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#47
post #33

Earlier quoted context omitted.

Not sure why you were downvoted. Protonmail stores all your emails encrypted, with the encryption dependent on your password, so something like this couldn't happen there.

Seems like if ProtonMail can encrypt them automatically, then they can potentially be decrypted by someone at ProtonMail. Reasoning: Are emails automatically encrypted with a hash of the user password when they are received? If the user forgets the password, how do password resets work? Are the emails before the password reset "lost", or does ProtonMail keep a copy of the hashed password (which I suppose would be nee…

They are not encrypted using the user's password. They are encrypted using a standard PGP public key.

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#48
post #8

Storytime! When I worked for MSN/Hotmail around 2000-2003, there were dozens of helpdesk folks who had access to an admin panel to easily view any email and could view/edit PII for anyone with very little (if not zero) accounting or auditing. It was protected by plaintext auth and open to the internet. One employee told me that he caught his wife cheating by reading her mail. Another used it to recover their own stol…

Imagine how security and oversight is at the typical startup company with millions of users today? Probably not much different.

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#49
post #2

This is totally insane. I'm totally baffled by the idea that Microsoft considers it okay for anyone except the owner to have any level of access to personal email accounts.

Of course there has to be a way to access email- how would they troubleshoot or fulfill legal investigations?

The problem is that an attacker can follow the "legitimate" path - and such attacks should be audited and detected, which is what obviously failed here.

Makes you wonder how vulnerable less mature services are...

Re: Hackers could read non-corporate Outlook.com, Hotmail for six months

#50
post #33

I am sure glad I switched to ProtonMail.

Not sure why you were downvoted. Protonmail stores all your emails encrypted, with the encryption dependent on your password, so something like this couldn't happen there.

If they really use your password to encrypt, they can also decrypt your emails. I doubt they would advertise this as encryption... I'm not sure what they do technically, but using the password doesnt sound like a good mechanism.
Post reply on HN