The free new Outlook replaces Mail in Windows, and later also the classic Outlook. It sends secret credentials to Microsoft servers.
Is this the same company that once created remarkable technological innovations like Windows XP, .NET Framework, Visual Studio Express, etc? I really hope it still is!
Microsoft lays hands on login data: Beware of the new Outlook
31–40 of 119 posts
Re: Microsoft lays hands on login data: Beware of the new Outlook
#32> Although TLS-protected, the data is sent to Microsoft in plain text within the tunnel. Although encrypted, the data is unencrypted when you decrypt it! They should at least add double ROT-13... Did whoever wrote this realize you need to be able to recover the cleartext for this to even work?
It would be fine if Outlook was backing up encrypted data and then not sending the decryption key to Microsoft servers.
Re: Microsoft lays hands on login data: Beware of the new Outlook
#33Re: Microsoft lays hands on login data: Beware of the new Outlook
#34Earlier quoted context omitted.
You're right it's totally different when Google does the same thing with Gmail.
For GMail people set that up deliberately Outlook pretends to be a desktop app.
Re: Microsoft lays hands on login data: Beware of the new Outlook
#35> Although TLS-protected, the data is sent to Microsoft in plain text within the tunnel. Although encrypted, the data is unencrypted when you decrypt it! They should at least add double ROT-13... Did whoever wrote this realize you need to be able to recover the cleartext for this to even work?
Re: Microsoft lays hands on login data: Beware of the new Outlook
#36Earlier quoted context omitted.
Do you use web based clients to access third party accounts?
Well, you often can do that. Gmail supports adding IMAP accounts, for example. iOS mail app allows it and all that data is synced to iCloud for most people. We just trust Apple isn't snooping.
Re: Microsoft lays hands on login data: Beware of the new Outlook
#37Good thing I'm still running Office 2013!!!! (and I only had to upgrade due to .pst size limits of past versions if I remember correctly - it's been a while since I moved to the brand-new-at-the-time-2013!)(and I got Windows Firewall Control, still on v.4.9.x.x version - before it became 'free' after its acquisition and move to v.5)
Long long ago, Outlook Express was all I ever needed. Simpler and fast. Not sure what happened to it
Re: Microsoft lays hands on login data: Beware of the new Outlook
#38Earlier quoted context omitted.
Well, you often can do that. Gmail supports adding IMAP accounts, for example. iOS mail app allows it and all that data is synced to iCloud for most people. We just trust Apple isn't snooping.
Does the iOS mail app do that? Every time I get a new Apple device I have to set fastmail back up from scratch with a new app password, even if I restore the device from a backup of an older device.
Re: Microsoft lays hands on login data: Beware of the new Outlook
#39> Although TLS-protected, the data is sent to Microsoft in plain text within the tunnel. Although encrypted, the data is unencrypted when you decrypt it! They should at least add double ROT-13... Did whoever wrote this realize you need to be able to recover the cleartext for this to even work?
“If you are trying to login to IMAP hosted by Google or Fastmail, why should Microsoft need to be contacted let alone given the password?” is how I read the article… Now, I know the answer is so that you can have push notifications sent to your mobile phone with every IMAP poll Microsoft does on your behalf, but that’s because the architecture of the new Outlook app likely borrows features of the Accompli mobile app…
Re: Microsoft lays hands on login data: Beware of the new Outlook
#40> Although TLS-protected, the data is sent to Microsoft in plain text within the tunnel. Although encrypted, the data is unencrypted when you decrypt it! They should at least add double ROT-13... Did whoever wrote this realize you need to be able to recover the cleartext for this to even work?