Live data from Hacker News

Microsoft lays hands on login data: Beware of the new Outlook

heise.de

21–30 of 119 posts

Re: Microsoft lays hands on login data: Beware of the new Outlook

#21

> Although TLS-protected, the data is sent to Microsoft in plain text within the tunnel. Although encrypted, the data is unencrypted when you decrypt it! They should at least add double ROT-13... Did whoever wrote this realize you need to be able to recover the cleartext for this to even work?

The problem is Microsoft using its servers as the middle man, without fair warning. Not what you mentioned.

You're right it's totally different when Google does the same thing with Gmail.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#22
post #2

The free new Outlook replaces Mail in Windows, and later also the classic Outlook. It sends secret credentials to Microsoft servers.

Is this new Outlook part of that new age Metro Interface or Windows Store apps? That's one of the first things I recommend everyone to get rid of as part of the windows de-bloat process.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#23
New Outlook on Mac is terrible - it lacks basic critical functionality such as tabular view (1 line per message) with column sorting by: From, To, Date received, Subject etc. Fortunately old Outlook is still available - I have to switch back after every update.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#24

So, like every other webmail then?

Do you use web based clients to access third party accounts?

Many people do exactly this and it was one of the original touted features of Gmail and it's unified inbox.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#25

Earlier quoted context omitted.

The problem is Microsoft using its servers as the middle man, without fair warning. Not what you mentioned.

You're right it's totally different when Google does the same thing with Gmail.

For GMail people set that up deliberately Outlook pretends to be a desktop app.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#26

So, like every other webmail then?

Do you use web based clients to access third party accounts?

Well, you often can do that. Gmail supports adding IMAP accounts, for example.

iOS mail app allows it and all that data is synced to iCloud for most people. We just trust Apple isn't snooping.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#27

> Although TLS-protected, the data is sent to Microsoft in plain text within the tunnel. Although encrypted, the data is unencrypted when you decrypt it! They should at least add double ROT-13... Did whoever wrote this realize you need to be able to recover the cleartext for this to even work?

“If you are trying to login to IMAP hosted by Google or Fastmail, why should Microsoft need to be contacted let alone given the password?” is how I read the article…

Now, I know the answer is so that you can have push notifications sent to your mobile phone with every IMAP poll Microsoft does on your behalf, but that’s because the architecture of the new Outlook app likely borrows features of the Accompli mobile app they bought and maintained as Outlook mobile. That the desktop app re-uses the same APIs as the mobile app rather than process mail locally makes sense from a code reuse and efficiency standpoint, but really only because your accounts can seamlessly carry over to all your devices.

It’s arguable that the distinction between keeping your password in the cloud and keeping your password local is a security risk. However, if you previously used Outlook.com to check your IMAP email, and maybe this is where the feature derives from, then you already provided your IMAP password to Microsoft on the web. Likewise Google for importing IMAP to Gmail. We do this because it is nicer to get one inbox and one push notification across multiple accounts - when we want cloud providers checking emails for us.

It is less clear why a desktop app would do this unless you opted in to fancier service of some kind - e.g. viewing emails on the web when not at this device, or push notifications to your mobile phone, etc.

If Microsoft wanted to read your emails even with a locally stored and never shared IMAP password, they could still send telemetry derived from the local client to build an advertising profile based on local emails, or to display targeted ads. They don’t technically need your password to read your emails if you are using their email client.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#28
post #25

Earlier quoted context omitted.

You're right it's totally different when Google does the same thing with Gmail.

For GMail people set that up deliberately Outlook pretends to be a desktop app.

The kids call these Progressive Web Apps and half the posters here were complicit in developing the technology.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#29
post #4

https://xkcd.com/1118/

They didn't get away with bundling the browser, but practically, that went nowhere, and they still keep pushing Edge at every turn. One of my pet peeves against Microsoft is, precisely, how they bundled a mail client with their office suite, and one hostile to standards at that. A mail client that, somehow, only worked properly with other Office elements, and, at some point, it created interoperability issues if send…

Secure Mail (tm).

Only available on Windows 12 devices with Microsoft-approved software.

Only €99 the first 20 months, then triples. Bundled with Microsoft Oven, Microsoft Fridge, Microsoft Wave, Microsoft Printer, Microsoft TV, Microsoft Sofa.

Never worry with virus again!

the bundle is not guaranteed to work with non-Microsoft Partners, such as Netflix, Steam, Android; companies need to submit for certification their hardware drivers; you can check the Compatibility DB available on the website. You may be downgraded to grayscale 360p if hardware is not verified with the cert level NBBcert 5 stars or another aproved Microsoft partner.

Availability in your country depends on your country subscription to Microsoft DRM-center, plan AA, and adherence to snoop-your-neighbor mutual agreement act 5000. China relations must be at level 304 or inferior, per mututal agreement 497.

To be eligible for support, you have to buy Microsoft Insurance Pack, and only network devices approved by Liberty Party or its subsidiaries are eligible. You must register at all times the current invitees at your house. If more than 2 invitees, you must apply, with 7-day precendence, for a license fun-at-home. The accuracy of your submission may be validated using Wifi sensors, per patent USPTO20130, and others. Patent Pending. Camera validation may be used if your credit score is under 200. If Microsoft agents knock at your door, failure to open the door will result in all subscribed pack being reduced to a plafond of 30 mins per day until Microsoft Corp and its partners are satisfied your way of life and current invitees are in the agreement of Microsoft, Oracle and Google tricorporation shared agreement.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#30

Good thing I'm still running Office 2013!!!! (and I only had to upgrade due to .pst size limits of past versions if I remember correctly - it's been a while since I moved to the brand-new-at-the-time-2013!)(and I got Windows Firewall Control, still on v.4.9.x.x version - before it became 'free' after its acquisition and move to v.5)

Long long ago, Outlook Express was all I ever needed. Simpler and fast. Not sure what happened to it
Post reply on HN