Live data from Hacker News

Microsoft lays hands on login data: Beware of the new Outlook

heise.de

51–60 of 119 posts

Re: Microsoft lays hands on login data: Beware of the new Outlook

#52

Earlier quoted context omitted.

Well, you often can do that. Gmail supports adding IMAP accounts, for example. iOS mail app allows it and all that data is synced to iCloud for most people. We just trust Apple isn't snooping.

Does the iOS mail app do that? Every time I get a new Apple device I have to set fastmail back up from scratch with a new app password, even if I restore the device from a backup of an older device.

It’s an option, if you turn on iCloud Mail Syncing. Off by default, I think.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#53

So, like every other webmail then?

Except disguised such that people think it is not webmail. They are replacing a desktop IMAP client (which stored data locally) with a webapp that (it sounds like) copies all of your Google Mail to a Microsoft server.

I do think this is a big deal, certainly my expectation was that the New Outlook work alot like the old Mail app.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#54
post #2

The free new Outlook replaces Mail in Windows, and later also the classic Outlook. It sends secret credentials to Microsoft servers.

I wonder how long this will work? If I was Google, I'd think about banning IMAP logins from the Azure servers that are doing this syncing.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#55
post #44

> Although TLS-protected, the data is sent to Microsoft in plain text within the tunnel. Although encrypted, the data is unencrypted when you decrypt it! They should at least add double ROT-13... Did whoever wrote this realize you need to be able to recover the cleartext for this to even work?

It is conceivable that they wanted to express "although encrypted in transit, it is not hashed and Microsoft can recover the full password". However, you'd have to be very charitable to interpret the articale like that. This is not a translation error either. The same mistake can be found in the German original. > Did whoever write this realize you need to be able to recover the cleartext for this to even work? The f…

Wait till they find out credit card numbers are not hashed and salted before being transmitted to a merchant over TLS.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#56
post #33

I only have a local user on Windows 11, but have started wondering when MS will create a shadow profile for me and upload all the data. So kind of them.

Storing all of your data in a server that you have no control over and no option to not be a part of, exposing you to more attack vectors, solely for Microsoft to generate revenue from you...is for your protection!

-Microsoft probably.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#57

New Outlook on Mac is terrible - it lacks basic critical functionality such as tabular view (1 line per message) with column sorting by: From, To, Date received, Subject etc. Fortunately old Outlook is still available - I have to switch back after every update.

I hate this new “mvp” philosophy where they redo an existing product and leave our features.

“Let’s get it working and add in future releases” makes sense for new products but is so dumb when it’s reworking existing products to make the crappier.

Microsoft does this all the time. They also do stuff like decide that Teams won’t have wikis any more. Because, like, nobody wants wikis in their collab suite.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#58

New Outlook on Mac is terrible - it lacks basic critical functionality such as tabular view (1 line per message) with column sorting by: From, To, Date received, Subject etc. Fortunately old Outlook is still available - I have to switch back after every update.

Outlook is terrible, period. I've been running the O365 Outlook version at my company and they broke simple things. I want to search for an email, so I select the folder, then click search and start typing. In the new Outlook, the moment I press the first key for my search query, the focus moves off of the search bar, for no reason whatsoever, so every. single. fucking. goddamn. time. I want to search, I select the f…

I dislike Outlook as a client for sure, but I must grudgingly admit that Outlook + Exchange is the single best, most usable, most seamless group calendaring & meeting tool I've ever used (and I've used a LOT).

For that reason, I end up keeping my corporate mail in TWO clients: True desktop Outlook in a Win VM, and also in my Mac's Mail.app. 99% of my mail I handle on the Mac side (for one thing, search is WAY WAY WAY BETTER). But scheduling? True Outlook every time. It's just better.

I haven't seen or used the "new Outlook," but it sounds like another example of MSFT calling multiple products by the same name to muddy distinctions for marketing reasons (e.g., "SQL Sever" and "Azure SQL"). "New Outlook" definitely doesn't sound like something I could or would ever use.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#60
post #51

So, like every other webmail then?

This isn’t even true for every webmail. Some run locally in the browser. Many don’t send the credentials to be saved cloud-side.

Realistically, how many widely used webmails work this way?
Post reply on HN