Live data from Hacker News

Microsoft lays hands on login data: Beware of the new Outlook

heise.de

71–80 of 119 posts

Re: Microsoft lays hands on login data: Beware of the new Outlook

#71

Is this an Outlook (app) issue or Outlook (email platform) issue?

Oh god. They have precedent for this. Word (app), Word (Teams), Word (online office 365 thing). All slightly incompatible.

All the big tech companies do this kind of thing to varying degrees.

Gmail (email service) and Gmail (app).

Apple TV (device), Apple TV (iOS app), Apple TV (Mac app), Apple TV (Apple TV app) and Apple TV+ (streaming service).

Re: Microsoft lays hands on login data: Beware of the new Outlook

#72
post #59

There's something strangely ominous about a lengthy, full screen German-language popup.

Don't know why you're getting downvoted. I couldn't figure out how to get past it, but it looked like the article is in English.

Yes that was the bizarre part. I recognize it's a .de domain but the URL and content seemed to be in English. I didn't know how to get past the (what is presumably) cookie dialogue though, so I guess I'll never know.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#73
post #30

Good thing I'm still running Office 2013!!!! (and I only had to upgrade due to .pst size limits of past versions if I remember correctly - it's been a while since I moved to the brand-new-at-the-time-2013!)(and I got Windows Firewall Control, still on v.4.9.x.x version - before it became 'free' after its acquisition and move to v.5)

Long long ago, Outlook Express was all I ever needed. Simpler and fast. Not sure what happened to it

I think it went like: Outlook Express -> Windows Live Mail -> Windows 8/10/11 Mail app -> ‘new’ Outlook

Re: Microsoft lays hands on login data: Beware of the new Outlook

#74
post #2

The free new Outlook replaces Mail in Windows, and later also the classic Outlook. It sends secret credentials to Microsoft servers.

I wonder how long this will work? If I was Google, I'd think about banning IMAP logins from the Azure servers that are doing this syncing.

That's rich, considering Google invented email credential harvesting.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#75

Earlier quoted context omitted.

They didn't get away with bundling the browser, but practically, that went nowhere, and they still keep pushing Edge at every turn. One of my pet peeves against Microsoft is, precisely, how they bundled a mail client with their office suite, and one hostile to standards at that. A mail client that, somehow, only worked properly with other Office elements, and, at some point, it created interoperability issues if send…

In their defense, Outlook and Exchange were created to compete with Lotus Notes. As much as Office interacted poorly with open standards, it was that it interacted with them at all that made it more successful than the other commercial office software in the 90s.

I don't see it as a defense, as much as it was a strategy.

They may have made their software more standard compliant, and when they gained enough market share, they tried locking competitors out of their environment.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#76
Oh wow, it posts your cleartext email credentials to an API endpoint called “/ows/beta/ShadowService/getShadowToken”.

But it least it calls the password string a “Secret” in the JSON payload so you can REST assured knowing the Shadow Service agents will handle this data appropriately.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#79

Earlier quoted context omitted.

Oh god. They have precedent for this. Word (app), Word (Teams), Word (online office 365 thing). All slightly incompatible.

All the big tech companies do this kind of thing to varying degrees. Gmail (email service) and Gmail (app). Apple TV (device), Apple TV (iOS app), Apple TV (Mac app), Apple TV (Apple TV app) and Apple TV+ (streaming service).

This is the and Apple is mystify given that they are very focused on image and advertising. However I tolerate that more, as fixing formatting in my job is actual hell, people are tying to get work done and the tools are objectively broken and it’s a de facto standard.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#80
post #2

The free new Outlook replaces Mail in Windows, and later also the classic Outlook. It sends secret credentials to Microsoft servers.

I wonder how long this will work? If I was Google, I'd think about banning IMAP logins from the Azure servers that are doing this syncing.

Google won't let you backup any parts of your phone without sending them your private wifi key.
Post reply on HN