Live data from Hacker News

Microsoft mishandling example.com

tinyapps.org

91–93 of 93 posts

Re: Microsoft mishandling example.com

#91
post #25

Earlier quoted context omitted.

It's more common than you might think. I know of at least one popular email client that stores your credentials on their servers to enable features like multi-account sync and scheduled sending.

Do you mean Spark? I get why they need to do it that way but I also hate that they have to do it that way because it sucks for privacy.

Yeah, Spark. Shame because I really liked their client, but I refused to use it anymore after I realized what they were doing.

Re: Microsoft mishandling example.com

#92
post #13

>Microsoft's Autodiscover service misconfiguration can be confirmed via curl -v -u "email@example.com:password" " https://prod.autodetect.outlook.cloud.microsoft/autodetect/d... ": Hold up, does this mean outlook sends your full credentials to Microsoft when you try to set up an outlook account? I'm sure they pinky promise they keep your credentials secure, but this feels like it breaks all sorts of security/privacy…

> Hold up, does this mean outlook sends your full credentials to Microsoft when you try to set up an outlook account? Not just an “outlook account” - any account in outlook, with default settings at least. I run a mail server, mainly for me but a couple of friends have accounts on there too, and a while ago one friend reported apparently being locked out and it turned out that it was due to them switching Outlook ver…

I might be misremembering but i think it even copies all of your mails to their servers.

Re: Microsoft mishandling example.com

#93

Now that example.com is hidden behind Cloudflare, how does the public know who is controlling the origin servers The IPv4 for example.com used to be 93.184.216.34 Was there an announcement somewhere

The old nameservers for example.com still have not updated their zone files

   dq a example.com 199.43.135.53
Post reply on HN