The free new Outlook replaces Mail in Windows, and later also the classic Outlook. It sends secret credentials to Microsoft servers.
> It sends secret credentials to Microsoft servers So in a work environment it probably can never be used? I'm willing to bet that it won't make a single bit of difference.
Microsoft lays hands on login data: Beware of the new Outlook
11–20 of 119 posts
Re: Microsoft lays hands on login data: Beware of the new Outlook
#12Re: Microsoft lays hands on login data: Beware of the new Outlook
#13Although encrypted, the data is unencrypted when you decrypt it!
They should at least add double ROT-13...
Did whoever wrote this realize you need to be able to recover the cleartext for this to even work?
Re: Microsoft lays hands on login data: Beware of the new Outlook
#14Re: Microsoft lays hands on login data: Beware of the new Outlook
#15The free new Outlook replaces Mail in Windows, and later also the classic Outlook. It sends secret credentials to Microsoft servers.
Re: Microsoft lays hands on login data: Beware of the new Outlook
#16> Although TLS-protected, the data is sent to Microsoft in plain text within the tunnel. Although encrypted, the data is unencrypted when you decrypt it! They should at least add double ROT-13... Did whoever wrote this realize you need to be able to recover the cleartext for this to even work?
Re: Microsoft lays hands on login data: Beware of the new Outlook
#17So, like every other webmail then?
Re: Microsoft lays hands on login data: Beware of the new Outlook
#18Good thing I'm still running Office 2013!!!! (and I only had to upgrade due to .pst size limits of past versions if I remember correctly - it's been a while since I moved to the brand-new-at-the-time-2013!)(and I got Windows Firewall Control, still on v.4.9.x.x version - before it became 'free' after its acquisition and move to v.5)
Re: Microsoft lays hands on login data: Beware of the new Outlook
#19More discussion: https://news.ycombinator.com/item?id=38212453