Live data from Hacker News

Microsoft lays hands on login data: Beware of the new Outlook

heise.de

81–90 of 119 posts

Re: Microsoft lays hands on login data: Beware of the new Outlook

#81
post #57

New Outlook on Mac is terrible - it lacks basic critical functionality such as tabular view (1 line per message) with column sorting by: From, To, Date received, Subject etc. Fortunately old Outlook is still available - I have to switch back after every update.

I hate this new “mvp” philosophy where they redo an existing product and leave our features. “Let’s get it working and add in future releases” makes sense for new products but is so dumb when it’s reworking existing products to make the crappier. Microsoft does this all the time. They also do stuff like decide that Teams won’t have wikis any more. Because, like, nobody wants wikis in their collab suite.

This is a result of promo-driven culture. But promotions are the carrot you need to dangle for many managers and engineers.

That's not why I got into software. I got into software to build useful products that delight the user. Products that make them more powerful and capable.

I feel very alone in this industry.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#82
post #59

There's something strangely ominous about a lengthy, full screen German-language popup.

Could it be the cookie prompt?

The page has 15+ trackers on it, so it must definitely ask for consent, and it shows as a big dialog with 3 buttons at the bottom.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#83
post #2

The free new Outlook replaces Mail in Windows, and later also the classic Outlook. It sends secret credentials to Microsoft servers.

I wonder how long this will work? If I was Google, I'd think about banning IMAP logins from the Azure servers that are doing this syncing.

The already call IMAP an inscure, outdated service. So when you enable it, they will disable it for you after so many days whether you want them to or not.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#84
post #30

Good thing I'm still running Office 2013!!!! (and I only had to upgrade due to .pst size limits of past versions if I remember correctly - it's been a while since I moved to the brand-new-at-the-time-2013!)(and I got Windows Firewall Control, still on v.4.9.x.x version - before it became 'free' after its acquisition and move to v.5)

Long long ago, Outlook Express was all I ever needed. Simpler and fast. Not sure what happened to it

It was so full of security holes though. Someone could just send you an email, and without you even opening it, it would send more email to your other contacts. It was really bad.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#85

> Although TLS-protected, the data is sent to Microsoft in plain text within the tunnel. Although encrypted, the data is unencrypted when you decrypt it! They should at least add double ROT-13... Did whoever wrote this realize you need to be able to recover the cleartext for this to even work?

It's to distinguish this behavior from password managers. Here, the message is sent to Microsoft in an encrypted form, but Microsoft can decrypt it to access the underlying password. For password managers, the remote server receives a password in an encrypted form, and cannot decrypt it to access the underlying password.

It could have been phrased better, but the clear message is that Microsoft has pilfered access to unencrypted passwords, regardless of any transportation-level encryption.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#87

Is this an Outlook (app) issue or Outlook (email platform) issue?

Most of the issues I've seen have been in the Outlook client app.

Ya I would never use that crap. Like if you have it setup in an alternative client, is that alright?

Re: Microsoft lays hands on login data: Beware of the new Outlook

#88

Earlier quoted context omitted.

I dislike Outlook as a client for sure, but I must grudgingly admit that Outlook + Exchange is the single best, most usable, most seamless group calendaring & meeting tool I've ever used (and I've used a LOT). For that reason, I end up keeping my corporate mail in TWO clients: True desktop Outlook in a Win VM, and also in my Mac's Mail.app. 99% of my mail I handle on the Mac side (for one thing, search is WAY WAY WAY…

"new outlook" is just the webmail, you can see it at outlook.office365.com if you want. It has a couple benefits. The search is better since it isn't limited to your local cache, and your scheduled emails don't require that you have outlook running on the desktop at go time. I try not to use it otherwise.

Search is the one thing that's been absolutely horrendous - I can be staring at an email, search for a phrase or similar from that email, and it can't find it.

And good luck searching for calendar items.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#89

Earlier quoted context omitted.

The problem is Microsoft using its servers as the middle man, without fair warning. Not what you mentioned.

You're right it's totally different when Google does the same thing with Gmail.

The difference between Gmail's IMAP setup and this new Outlook IMAP behavior is the same difference between borrowing a friend's car and stealing a friend's car. In both cases, you're driving a car that doesn't belong to you. The difference is whether you have permission to be driving that car.

Both Gmail and Outlook are receiving passwords, then using those to perform IMAP requests from their servers. The difference is that Gmail had permission to do so, while Outlook did not.

Re: Microsoft lays hands on login data: Beware of the new Outlook

#90
post #2

The free new Outlook replaces Mail in Windows, and later also the classic Outlook. It sends secret credentials to Microsoft servers.

I really love how they made a slick and fast mail app for windows, even if it it didn't support everything. but it did its job of being a fast email client.

Then they decided not anymore and replaced it with a bloated one...

Post reply on HN