Windows 11 Update 23H2 is stealing users' IMAP credentials
www-heise-de.translate.goog
www-heise-de.translate.goog
Apart from the security issues, it's also very annoying to have to explain that I can't actually troubleshoot any IMAP connectivity issues when your machine isn't the one thats actually making the connection.
Now we've been internally discussing whether we should just firewall off whatever Azure ranges are connecting to our IMAP backend servers and intentionally "break" the functionality. Not my first choice, but users keep seeing the "New" toggle and turning it on, causing all sorts of other uncontrolled chaos!
Cloud-first, in all the wrong ways. It's supposed to be a local app..
I am a bit puzzled that I have not been reading about this in any big US media, not even IT ones. How did you first learn about it?
This IS a big deal and should be a scandal people are educated about, and Microsoft should be forced to stop this immediately. It's interesting that Microsoft appears to have managed to stay under the radar with these deceptive tactics...
Imagine my surprise discovering that this little banner in their Outlook settings that said "Using Microsoft sync technology" actually means "This is no longer really a local IMAP client".
If Microsoft has the power to pay the EU for laws in its favour, i presume (i am actually sure see "die Welt") that paying some newspapers poses no big logistical problems.
All of them? Now you've announced that you've got something to hide and are trying to to pay off newspapers to hide it. One of them is going to decide that this story is too juicy not to publish.
Only those that find out some other way and ask for comment? Well, in this case Microsoft didn't reply to c't Magazin's request for comment before publication...
One side writes a piece, something like: "How the new Outlook saved my {insert protected class}", another one on the other side something like "New Microsoft Outlook uses your mail credentials to steal your DNA via nanosites because Bill Gates wants access to your children."
And then the rest of the media pick it up from there, spin it in their respective direction, receiving their generous donations from one of the numerous MS foundations that funnel money into these places, based on how damaging their puff pieces were.
Now nobody cares about the problem anymore because they are too busy fighting each other.
Even when you have solid competitors for individual components, the whole package is hard to resist. So they're stuck with MS for the moment, and slowly get absorbed in that ecosystem making it even more entrenched. But MS doesn't need to pay to get the law, they just have to let EU companies try out alternatives until they go back to being slowly boiled with MS. The EU is looking for excuses to excuse MS because everyone decided the price we all know now is worth paying to get access to a full ecosystem that fills all other needs.
Effectively the EU is "paying" MS to stay, not the other way around.
MS doesn't need to do anything. They don't need to pay anyone off. EU bureaucracy is extremely strongly wedded to MS products like Windows, Office, Teams, Outlook etc. As are all EU national bureaucracies and public institutions.
There are firm opinions by e.g. the BSI (German IT security office, comparable to something between NSA, mostly NIST, DHS and ANSI) and other equivalent European national offices that it is practically impossible to operate modern MS products securely. E.g. there are guidelines from BSI like "we know that in that exact version (which is years old, because the guideline took ages to write) you need to set the following registry keys to prevent data exfiltration. Btw. this won't help you, because you also HAVE to upgrade within a few weeks of each available update". There are firm opinions by multiple European data protection offices that basically say the same about GDPR compliance in MS products. Practically impossible to achieve, there might have been that one configuration, "Once upon a time of writing the report, with that specific version of Windows and Office, when firewalling off half of azure, setting those 300 registry keys, manually deleting the following files, illegal telemetry could no longer be observed. Also, you are obliged by GDPR to follow good practice and update regularly, so good luck with that...".
Basically it is illegal to process any personal data using MS products in the EU if the processing system has any kind of outgoing internet connection. All the bureaucracies ignore this systematically, citing the "impossibility" of working without said MS products. Migration plans away from those illegal processes are regularly cancelled, ignored or never completed. MS is free to do whatever it wants, they are never really investigated, fined or held to any laws.
Meanwhile, other big IT firms like Meta, Google, Twitter/X and lots of others are held to far higher standards. Where tons of your local government's data about you like tax report, criminal records, school records and similar things are subject to being exported to the US via Azure, MS telemetry and what not. With FAANG there is complaining about comparably laughable stuff like "well, that IP address that Google Fonts could observe...".
The problem, why this doesn't change, is that the local government institution is responsible for their data processing (according to GDPR and other laws), MS being only their contractor. And those government institutions are usually (in almost all EU states) free from GDPR and other penalties, and those penalties would be left-pocket-to-right-pocket anyways.
This is why MS gets a free pass on everything. Imho this must end.
Even so, a law that benefits MS will also benefit Google under these circumstances. Any law that locks out MS or Google (like GDPR which constantly sees "exceptions" carved out) will have some severe economic repercussions on EU companies, not to speak of the political/diplomatic ones with the US.
Microsoft is already taking so much data, I would have trouble to explain to the layperson, why this incident is worse, than all of the other shit they are doing.
Why would they? The users can do whatever the hell they want with their credentials
* Ideally they should be separated like through OAuth, but that isn't an option for an ancient standard like IMAP.
This will happen naturally as users change their credentials on server but not on outlook. Outlook proxy will try wrong password for 5 or so times and will get their IPs banned. This will affect many more users using the same server.
This will generate tickets for you and you will direct them to use plain local IMAP clients instead.
This whole idea at Microsoft was clearly forged by someone who has never served mail and is bound to fail as it trips standard security practices present for decades.
It's actually a really weird app. I have a windows PC I sometimes use at work, loaded with all the corporate crap, among which a full up-to-date installation of office 365. Since this machine isn't mission-critical, I sometimes like to check "what's new", so I've switched to the "new outlook".
Yesterday I got an email from someone with an attached Word doc. Usually, I just read those inside outlook, since I only need to skim them at best.
But this time, I clicked "open in word". The thing took ages. First it uploaded the doc somewhere on onedrive (didn't ask me anything). That took a good few seconds. Then it proceeded to open a browser window with a spinny thing doing whatever it is ms products do when they have you waiting around for no apparent reason. Then it finally opened the doc in word online. All the while having a perfectly good copy of word sitting on the same nvme drive as the freakin' attachment.
Now, this computer isn't the latest thousand core threadripper or nothing, but it was still the longest I've ever had to wait around for a 2 page text-only word doc to open.
In a corporate office environment, that’s one of its two jobs.
At least it doesn't crash. At one point, it used to just die on me. They've also fixed the window decorations and ramdom icons in the left toolbar, which used to become weird on mouse over.
There's also something else odd going on with the app. When I start it from the start menu, there's a very long lag between my pushing enter and the start menu going away. This happens every time I start outlook after a fresh boot, but doesn't happen with other shitty apps, like New Teams. For those, it disappears right away, even though the app doesn't start up instantly. It doesn't matter the order in which I start them, nor if I only start Outlook after the machine has been running for a while.
much better than nuOutlook
though often hard in most corporate environments...
that said, if I were in a more buttoned up IT environment, I'd just use the web client as it's sadly faster than the desktop client these days
I'd use the web client now except the version my company has is pretty bad and old still...
I'm not in a "buttoned up IT environment", but I still prefer the web client. It actually works great on Firefox on Linux and is way snappier than local outlook ever felt.
Point is, at least this specific gripe, for what it’s worth I can see some valid justification for. And if this is new behavior that they intend to stick with, I wouldn’t be surprised if they did improve it over time (although I also wouldn’t be surprised if it stayed as much of an annoyance as you described— bing search in windows remains an unchecked crime against humanity to this very day!)
I agree that changing an app from offline to online, without appropriate messaging is wrong. But, it is not different from how Gmail works as a mail client.
It's a shame, because like many Microsoft apps, the Outlook app isn't half bad if it weren't for the disgusting privacy violations.
Well, IMAP is already "cloud-first" by itself; so this is "cloud first and second", also known as MITM.
New Outlook lacks many, many features it predecessor has, like hot keys and viewing options. It doesn't support multiple languages, a must for someone who isn't American but works in a global company. And yet they push it as if it was an improvement.
Whoever made the decisions on this should rethink their career.
To be clear: this is for accounts not hosted on Microsoft servers. They likely copy all of your existing mails to their servers, and any future mails sent or received also run through their servers.
It quite probably will turn out to be fined.
Let's wait (for months or years).
Just think how would hell have broken loose if the same practice had been carried out by a Chinese company or even by a Russian one (such as Kaspersky, let's say).
The dark patterns pushing content to one drive from office apps and web access opening attachments and keeping them in one drive is another example of this data grab.
It’s an example of shareholder value trumping customer value, the primary purpose of cloud is to make you pay more without having to provide more in return.
While I agree with your other points, I'm not sure how this one works. If you're using Office365, you're already having your mail at least go through their servers. What difference does IMAP make to their snooping intentions?
Sure is good they're not an ad company then. /s
They're just trying to catch up with Google in any and every way they possibly can, users trust, privacy and security be damned.
You use all data, public and private, for your in-house skunkworks LLM-AI used by vetted, NDA-bound staff and execs.
Bing won't be able to answer questions like "What are the monthly active user counts for CoolService LLC?" or "What are the manufacturing processes used at Gadgetmaster International?" but maybe DarkBing will.
Even if LLMs aren't good enough to deliver those answers today, they might be in five or ten years, and in the meantime you want to fill the pool of data you're going to feed it.
Cynical speculation? Yes. Eventually possible? Maybe...
Except when it comes to AI, Google is the one playing catch-up to Microsoft/OpenAI.
I wouldn't be surprised if this is a ploy to offer users a 'migration' to a paid office 365 subscription later.
The old windows mail was ok even though it wasn't very full featured.
It's an amazing feeling when your OS isn't insisting left and right on behavior you don't want.
Yepp, I get this confirmed every so often when I need to boot/install Windows. I will not deny Linux has issues, but so far these issues could be solved or at least worked around. They can be frustrating at times, but at least they tickle the problem solving and learning part of my brain instead of the part reserved for unreasonable anger.
Literally only 2 things lacking right now is those 3 last game titles left which can’t run via Steam/Lutris and those corporate Windows apps which I prefer to run in a VM (virt-manager).
Edit: Looks like KDE could have this sorted soon: https://invent.kde.org/plasma/kwin/-/merge_requests/4589
If this is now simply a way to refresh the snagged IMAP credentials so they can ready your email, then it explains a few things.
https://www.scamp.de/stuff/heise_windows_outlook_stealing_im...
Some while ago, there was a bit of backlash over their re-design, but after actually using the more recent versions, I have to say that they did a good job - you can toggle the display density of the UI elements and it's still a good mail client with reasonable performance and usability.
I can even sign e-mails with OpenPGP and did you know that it also has a built in RSS feed reader (a bit clunky, but having news sites/blogs be a folder that's right next to my e-mail accounts works brilliantly well)? In addition, I have it both on my Windows and Linux machines, surprisingly consistent across the board.
Honestly, I couldn't be happier. Maybe also Roundcube hosted on VPSes for my own development mail servers when I don't feel like adding bunches of accounts to Thunderbird, but it's really nice that there's software like this out there in the first place!
Windows now directly offers OpenSSH and a decent modern terminal app, so while PuTTY still works it’s no longer necessary for accessing mutt over SSH from Windows. Also with WSL you can also run mutt locally on Windows within a userland Linux distro like Ubuntu or Debian.
There are solutions like the Owl extension for Thunderbird, but that’s for the adventurous ones who want to take risks.
I ultimately landed on keeping the desktop app open to reduce browser clutter and for the icon notification badge so I don’t miss any important emails.
https://www.claws-mail.org/downloads.php
There's a small command line tool around (can't recall the name, sorry) to convert message bases and contacts from Outlook format so that they can be imported into Claws Mail. I once did that at a workplace where they were having all sort of problems with Outlook and a fairly big mail archive and saw people dropping their jaws when looking at the difference in search speed. Give it a try.
[0] https://community.getmailspring.com/t/disappearing-emails-de...
E.g. Microsoft Edge on first launch can import bookmarks+stored passwords from Firefox (AFAIK without any user interaction, unless I clicked without thinking), and it also defaults to uploading this data to the Microsoft cloud (unless you're using a local account?).
I was utterly shocked to find Linux Desktop has more uptime than Windows. Windows forced updates caused so many issues dealing with autosaves, I was spending like 5-10 minutes per day reopening all my programs for work.
Those random linux annoyances you need the terminal for? I had like 1 or 2 of them during month 1, solved faster than a single Forced Windows Reboot. Fedora been flawless 5 months later.
The only terminal work I do is opening ports for my kid's games. It really is the year of the Linux Desktop. Its utterly shocking to me I'm saying it, I was a hater for so long.
Generally, if you want hardware that you don't have to fight, the only option is to buy computers with Linux preinstalled, with support. Modern computers are sufficiently complicated that they really only can support one OS. And, for consumer hardware, they even half-ass that.
I googled it, it was like copypasting 2 or 3 commands, then I could watch reddit videos.
I can't remember the other bug, it might have been an ID10T error.
Can't even blame Linux for that, I have to install way more stuff to make Windows work out of the box. Fedora weirdly has lots of stuff already installed.
I would say that "Generally", it's not a thing you need to worry about. If something isn't working, it's probably a configuration issue on your side. The easiest way to avoid that is to pick an immutable distro like Fedora Silverblue, Suse MicroOS, and soon Ubuntu Core Desktop. Combine that with Flatpaks, and you pretty much never have to touch a terminal or worry about a broken system.
Generally, at this point, most hardware lines are supported. If there are problems, they are with new state of the art GPUs, some weird new modems or fingerprint readers. Generally, your mom won't be requiring those. If you are buying for yourself, just pre-check if there are linux drivers for each of these.
Why does anyone use Windows at home anymore? I guess gaming is still an issue?
Something of an understatement
Er....no? Though i do spend an inordinate amount of time closing as many holes as possible. Unfortunately, windows is ok. The telemetry, ands and other bullshit is embarrassing but the software i run is on windows. Tried Linux, various ones, but I spent more time messing about that (software didn't cut it, drivers were an arse for audio, graphic setup was strange) it was a relief to go back. Linux reminds me of w3.1 and all that memory allocation bollocks just to run a game. I choose my lazy acceptance, combined with 'as much as I can do to protect myself', over beating my head over a whole operating system that doesn't cut it for what i require. I won't entertain macs as i trust apple even less (for being closed).
The disadvantages are that its paid (one time payment) and Windows only (no linux version).
Microsoft OS is reading your keyboard. If they did it once, they will do it again.
Wow, just wow
Not sure if it's apparent from the English version of the article, but Heise performed a successful MitM attack to extract the plain text password from the daa stream.
They would use the hashed password to login to the server, using something like XOAUTH2. That’s the point of the hashed password. It accomplishes nothing other than revocation, which can be done already by changing your password.
I don't understand how hashed passwords got into this discussion though. My point is that microsoft should have no way to authenticate as an outlook user against their third party mail provider without the user explicitly giving them permission to do so and what they do is strictly unnecessary to provide the functionality of an email client.
Just like this comment I am writing is literally encrypted when it is send to HN, and still everyone can read it.
And yes, the issue is obviously that it is send in a way that microsoft can (ab)use.
> [...] tunneling [through an encrypted channel] back to their servers in plain text
Seems pretty clear to me. The message that is send contains the password in plain text. Any encryption that is applied in transit is absolutely irrelevant and meaningless. Just microsoft receiving the credentials is only marginally better than anyone getting them. In both cases the account will be compromised.
• How long is mail data fetched from the non-Microsoft server retained? On 31st day of user inactivity we mark the account for removal. The account is soft deleted, and the data is purged within a week (approximately) after that.
• What happens with an account that is no longer being used? Does the service continue fetching and “enhancing” mail data or does it happen on demand when a user opens Outlook? - If the user is not signing into the 3rd party accounts using outlook mobile, Teams for life or Outlook for Mac. We stop syncing any data after 7 days and mark the account for deletion after 30 days.
• How do I know what data the service holds? - Service holds Mail, Calendar, contacts data and profile data for the user (User provides consent to collect this data during add account flow).
• How can I make sure data is no longer retained? (e.g., does logging out from Outlook delete the mail data and credentials?) - When removing the account in Mac you can choose to "Sign Out On All Devices" which deletes the mailbox from the Microsoft Cloud (Exchange-backed mailbox where the third-party account is being synced).
I also filed a complaint about not making it clear if data is required for processing (Article 13, Section 2(e) [1]) - but the supervisory authority ignored me on that one.
The fact that this is acceptable, in their narrow minds, is insane
https://heise.cloudimg.io/v7/_www-heise-de_/imgs/18/4/3/3/1/...
Once you've decided to send the actual password, whether wise or not, the best you can do is encrypt it, and TLS does that.
What else would you expect?
This is not at all comparable to other "store my passwords inside the cloud"-systems, where the passwords are encrypted and decrypted on the users' devices, without the encryption key going to the cloud provider - that's the way it's handled in Password Managers, Chrome Auto-Fill etc.
And I would expect Microsoft asking the user for explicit consent "May we take your IMAP password and transfer it and store it in our cloud?" in easy to understand wording so people understand the consequences (for example getting fired for having punched a gapping hole into your employers security policies like "Don't share this password with anyone")
That expectation would match the law in the EU.
And in addition, inside the EU it would also have to guarantee that the password will only be stored on servers inside the EU, and not end up, for example, with the NSA. And even then it still might not be legal.
And from a user's perspective: Certainly a big chunk of users that have been using email software for the last decades would assume that an email client installed on your PC is doing the IMAP access locally. There is no need for your IMAP credentials to go to Microsoft. Merging your local mail store from multiple sources inside the client is what email clients have been doing for the last 20 years. There is absolutely no need to move this to the cloud. Yes, my computer can handle merging email folders.
[1]: https://learn.microsoft.com/en-us/azure/key-vault/managed-hs...
But if they were to provide such a "service" I'd expect them to minimize exposure, including the steps I mentioned.
Still not a great solution but at least not passing the password around.
I would expect user credentials to not be uploaded without giving an extremely explicit explanation and receiving informed consent from the user.
This is actually standard security practice when you absolutely have to store a key in a way that you can use it later, such as a password or an API key.
Client certificates are supported by both Thunderbird and K9, would prevent this type of issues.
In the cloud first era, your value is derived from how much customer data is under your control. Not for resale primarily but for stickiness. It's like the dot com era, only for real this time.
How? Outlook could just ask you for your certificate (+ private key) and upload that.
But you haven't. Microsoft has decided that for you - without telling you.
The more I think about it - that's not even just a GDPR issue, it's blatant malware behavior.
I suppose they'd prefer it be not transferred at all, but if it were... to be bundled up safely [for storage] before exfiltration
I do understand the point that the article is making, but implying that TLS is equivalent to plaintext is just plain hyperbole. What else can Microsoft do (assuming they want to do this feature?). Encrypt it again on the client side, then put it in the TLS tunnel? It's just double encryption at that point. They need the password
FWIW the amount of users still using unencrypted IMAP is often pretty high in outlook or apple mail. Now that is a security issue. Try using a wifi packet analyzer at a large conference. I bet you'll see multiple or even dozens of plaintext IMAP passwords going thru the air.
2. Extend (New Outlook supports IMAP, but only in the sense that we copy all your stuff to our Cloud) <--- We are here
3. Extinguish (We are deprecating support for legacy e-mail protocols, but it's okay because all your old stuff is in M365 anyway)
The dream of decentralized e-mail based on open standards is dead.
It's because there are newer and better sharks out there, and you guys haven't caught up to the last 1-2 decades.
For example:
Recently, Biden's administration has started changing the federal tune on antitrust, formally rejecting the intellectually and morally bankrupt Chicago School interpretation that has hobbled all antitrust efforts for decades. That's why we're starting to see some real antitrust cases again.
Back in my day we just wrote Microsoft with a dollar sign for an S
So what exactly is the goal of their master plan? They stop using IMAP for their Hotmail and Outlook.com accounts? Big whoop. The mass of people on Gmail and icloud.com/me.com services will just download one of a dozen other apps. And then just slowly stop using the outlook required accounts; unless mandated by their companies/corporate offices, wherein they just run two clients.
EEE was a policy Microsoft had when it gained monopolistic position in a field. It's misguided and inaccurate to try to apply it here.
Privacy wise it's distasteful but it does work around a lot of IMAP's problems which still don't seem to have been fixed in the ~20 years that they've been known about...
It's just all political bullshit -- the same reason you can have decent IMAP clients on Android, but you can't on iOS (they have to resort to tricks like this), except if you're Apple.
Unless I'm misunderstanding the problem you're raising, it seems like a non-issue for the majority of people with multiple accounts (a work email, a Gmail, a hotmail; for instance).
As you say the problem is somewhat caused by Apple ~~and Google~~ forcing apps to use their proprietary notification systems so that e.g., mail can be checked while a phone is idling. But the end user does not care about the market abusing power of the monopolies--they wants instant notifications when they receive mail...
You can still perfectly have dozens of background TCP connections idling on Android with no issue. The only caution you need to take is to synchronize the keepalives (otherwise the radio may take stay on for too long, hitting your battery life), but this was solved back when Android was still Danger.
As evidenced by the power analysis of IM apps that was here on HN a couple weeks ago, there is no discernible advantage to using Google notifications versus just keeping your multiple TCP connections idling in the background: Conversations is a Jabber client which does the second and was practically the most power-friendly client of the entire Android ecosystem.
It's host<->host unique. So, assuming your email server allows enough keepalives, you're fine with multiple devices.
Where you might have an issue is if you have multiple accounts on the same server (not even the same service, necessarily; Gmail, hotmail, etc have a plethora of servers) and connect to them via the same device.
1. Remove it from schools so kids don't grow up used to it
2. Stop it being bundled with new PCs
3. Get companies to stop using Excel
4. Convince gaming companies to stop making first class support for games for Windows
5. Make all existing important software and games work just as well on Linux
6. Get NVIDIA to make Linux a first-class citizen
Libre Office is just... not there. Something is seriously wrong with it.
Anyway, Linux Desktop is ready for the mainstream. I can typically get away with Google's suite for Office. All of my workflows work fine with Linux, and I have hobbies from 3D printing to electronics to writing to creative work.
In fact, it may not be an exaggeration to say: the only plausible explanation why Linux isn’t dominant is corruption.
Anything less won’t move the needle, at least in the short term. People don’t like change and they don’t like thinking about their tools. You see this even with macOS, where switchers only put up with learning because there’s immediate tangible benefits like long battery life and reduced heat/fan noise acting as a carrot, and even then sometimes that’s not enough and they end up falling back to Windows.
Treat lobby as what it really is: corruption.
I'm a dreamer, i know.
if you write malware to steal passwords or steal files, you go to jail for computer crimes.
If Microsoft (or FAANG) does it, it is business as usual because they pay legislators and law enforcement to close their eyes.
Hopefully this doesn't apply to eg. Outlook365 as well.
This is exactly why I wouldn't want a MS account on my local system. Without that, this wouldn't even be possible.
Doesn't make this any better- but before you worry that MS has your Google account password, they don't.
The sole exception are tokens tied to a device's HSM (TPM, Secure Enclave, TrustZone, ...) - you can't clone these onto another device.
ETA: to expand a bit... passwords, SSL client certificates, JWTs, tokens generated after a SAML assertion, they are all fungible bearer tokens. A server has no way of verifying if what is presented to him is originating as an intentional act of a user, or if a malicious third party has duplicated the token somehow and is using it from somewhere else. An attacker can act just the same as the user themselves can. A HSM-backed token, i.e. having the server send a preflight challenge value, and the client HSM signing that challenge together with the token to send back with the actual request, at least proves that the request originated from the device expected to be in control of the user. However, such a scheme comes at a high cost - the user needs to be in possession of a capable device, the HSM needs to be secure, and doing preflight requests to obtain the challenge adds considerable latency.
But I had to click accept on the Google form requesting my permission to grant Outlook access. So I was informed when the app was connected.
I'm not sure how you would count "new device", since that token is going to be used by a random Microsoft cloud server, potentially different every time.
How are they supposed to access the emails without some sort of token?
You need a token to authenticate, but the client software (Microsoft here) doesn't ever need to send that data to themselves to successfully auth.
Sending themselves the auth credentials does allow them to then use it on their servers in ways that your client device may not want to (e.g., excessive battery drain) or can do (loss of network). But it then also allows them full access anytime they want and complete control of your data for whatever they want.
95% of people use webmails from Google, Microsoft or Yahoo. They already have complete control.
Sure, Microsoft should make it much more clear what is going on with the passwords and cloud email, but all things considered, nothing really changed for 95% of people.
And if you don't trust Microsoft with your email, but are using this Microsoft mail app on Microsoft Windows, well, that's again weird.
It is completely possible to have SMTP and IMAP be on internal networks and not on the internet (SMTP obviously needs a way to rely to a internet connected buddy).
I can't turn it off.
Now Microsoft wraps their web UI in a “native” app and everybody loses their mind.
It’s hardly unusual for an internet-connected app to be at least partially run in the cloud in 2023. Much less unusual when it’s something related to MS365 and AI (one of the banner features of this new release)
One is an explicit delegation, while the other is a man-in-the-middle attack.
If you are trying to add a "local" IMAP/SMTP account, there is short notice that Outlook needs to "synchronize" your IMAP account with the Microsoft cloud.
It does NOT explain that what this actually means is that it will send all your credentials including your passwords in clear text to Microsoft.
Microsoft's support document to this also only mentions:
"Syncing your account to the Microsoft Cloud means that a copy of your email, calendar, and contacts will be synchronized between your email provider and Microsoft data centers."
No word that it means that they are uploading your passwords.
This is evil. And at least in the EU, illegal.
I have not yet found any report on this in english-language IT media, and therefore have provided a Google Translate link to the report in German.
So here is the original page URL: https://www.heise.de/news/Microsoft-krallt-sich-Zugangsdaten...
And here is the picture that shows what they have captured is sent to Microsoft:
https://heise.cloudimg.io/v7/_www-heise-de_/imgs/18/4/3/3/1/...
https://heise.cloudimg.io/v7/_www-heise-de_/imgs/18/4/3/3/1/...
That dialog talks about sync but notably does not mention credentials at all.
Surely this is instance where informed consent is needed, with full disclosure of what's going to happen.
Something along the lines of: "this means your IMAP username and password will be passed to Microsoft where we will store it indefinitely so we can regularly log into your IMAP server to sync your messages".
Of course, users are less likely to consent if you explain exactly what's going to happen...
Unfortunately our legal system strongly disagrees with me but that’s my two cents
Explained in detail, here.
https://gdpr.eu/gdpr-consent-requirements/
Consent must be specific, informed, freely given and unambiguous. The user must be able to revoke consent at any time, as easy as it was providing the consent before.
Very clearly the Microsoft "consent" info does not tick any single one of those items.
Illegal.
There is much to criticize about the EU. But where the US has brought the world "By farting during installation of this software you consent to us stopping by and taking your first born child" kind of EULAs / "choices", EU's GDPR is forcing big tech to treat humans as humans again (instead of just data).
GPDR is good. So is CCPA, COPRA, etc. Meanwhile, both the EU and the US have plenty of predatory legislation that allows companies to do all kinds of fucked up things.
I agree that there's no room for home-team mentality here, but we should absolutely assign credit and blame where it's due, especially when those of us who don't live in a jurisdiction with such a law gain some halo-effect benefit.
But I am pretty impressed that in these days where most regulations for pretty much everything are defined by lobbyists, GDPR actually did happen, ended up to be a very reasonable set of rules, and actually gets enforced. It was written well, and unlike with other regulations it's not full of loop holes.
Laws and regulations created to the sole benefit of your general population is just something you can't take for granted these days anymore. Therefore, for me GDPR is kind of magic.
Not some arbitrary lines on the ground that also have terrible anti-legislation.
Also, at least according to several comments on nearly any story about movie piracy, it is not stealing because all they have done is made a copy.
The Outlook app for Android does the exact same thing, copying your email to the Microsoft cloud and then serving the emails to your phone from Microsoft's servers.
Is it really? The comments on the original Heise article mention that Heise actually misunderstood it and it's basically just a link to the web interface in the task bar so it's not a local app.
Looking at the Microsoft Store entry (https://apps.microsoft.com/detail/outlook-for-windows/9NRX63...) I don't really see any indication of it being a web app either.
Maybe they're hiding their web app Electron/Tauri style, but I would certainly expect it to be local-only based on the way it's advertised and designed.
If any mod wants to modify...
Original is: https://www.heise.de/news/Microsoft-krallt-sich-Zugangsdaten...
Deepl-Translated PDF version: https://www.scamp.de/stuff/heise_windows_outlook_stealing_im...