Microsoft lays hands on login data: Beware of the new Outlook
heise.de
heise.de
But it least it calls the password string a “Secret” in the JSON payload so you can REST assured knowing the Shadow Service agents will handle this data appropriately.
So in a work environment it probably can never be used? I'm willing to bet that it won't make a single bit of difference.
There is the one trap-word. I am practicing a firewall-hygiene from the good-old ZoneAlarm days. If I don't need the software to 'get out', it is blocked. I only allow my Outlook to 'talk' to my mailbox carrier to bring in the emails. All other target IPs are blocked. So it can't 'phone home'. But again I'm on Office 2013 (and it still tries to phone-home).
For most services email is the master key to reset your password. By getting access to someone's email account a lot of other accounts can be breached easily. I try to disable password reset via email wherever possible. But most services don't provide this option.
I think it would be time for IMAP to get a standardized way to log in via OAuth2/OIDC. And maybe an update to the email standard to mark a recovery links or codes as secret, that require 2FA every time to read.
Especially dangerous are servers that still allow using IMAP without TLS, that's just asking for trouble.
Microsoft stores an OAuth2 access token for these accounts, which is still unnecessary compared to the locally synced version of Outlook we're all used to, but the user can revoke it through Google account settings at any time, just like any other OAuth2 access token.
Then they decided not anymore and replaced it with a bloated one...
I've been running the O365 Outlook version at my company and they broke simple things. I want to search for an email, so I select the folder, then click search and start typing.
In the new Outlook, the moment I press the first key for my search query, the focus moves off of the search bar, for no reason whatsoever, so every. single. fucking. goddamn. time. I want to search, I select the folder, click into the search box, type 1 character, move my hand off the keyboard, over to the mouse, to re-click into the goddamn search box, then continue typing.
That's Microsoft "improving" a product.
Man, I fucking hate these people.
For that reason, I end up keeping my corporate mail in TWO clients: True desktop Outlook in a Win VM, and also in my Mac's Mail.app. 99% of my mail I handle on the Mac side (for one thing, search is WAY WAY WAY BETTER). But scheduling? True Outlook every time. It's just better.
I haven't seen or used the "new Outlook," but it sounds like another example of MSFT calling multiple products by the same name to muddy distinctions for marketing reasons (e.g., "SQL Sever" and "Azure SQL"). "New Outlook" definitely doesn't sound like something I could or would ever use.
It has a couple benefits. The search is better since it isn't limited to your local cache, and your scheduled emails don't require that you have outlook running on the desktop at go time. I try not to use it otherwise.
And good luck searching for calendar items.
Search in the native Mac Mail client? Crazy good. Very reliable. Never let me down.
Mail clients are kind of all terrible, because right now my favorite one is just the one that does the things that really OUGHT to be the bare minimum:
* Reliably send and receive mail
* Support IMAP and Exchange
* Have the option for local storage of some or all of the mail corpus on any given account
* Have fast, accurate, reliable search
* Have a rules/filters function (though honestly this is usually something better done server-side)
* Have a well-designed, coherent interface that makes rapid work possible
* Be at least halfway attractive to look at
“Let’s get it working and add in future releases” makes sense for new products but is so dumb when it’s reworking existing products to make the crappier.
Microsoft does this all the time. They also do stuff like decide that Teams won’t have wikis any more. Because, like, nobody wants wikis in their collab suite.
That's not why I got into software. I got into software to build useful products that delight the user. Products that make them more powerful and capable.
I feel very alone in this industry.
https://old.reddit.com/r/sysadmin/comments/13lo7u6/list_of_n...
Then I got rid of it entirely when the top unread email was an ad instead of actual emails. The fuck?
Only reason I could think of: some very specialized extensions that are only available for Outlook.
I'm really happy that Thunderbird recently got some updates, I think it's the only good free desktop mail client that is still around. Evolution looks really dated nowadays.
Personally I can recommend eM Client for Windows users as an Outlook replacement (and they have a macOS version too). It's commercial, but there is a free version for private use. It does CardDAV/CalDav quite well, and supports PGP/S/MIME.
Thunderbird needs to get to the 21st century before general public starts swapping out MS or Google mail, calendaring, and contact solutions. As it is, the GUIs on need a Jacob Nielsen-style usability revamp.
Thunderbird still has a long way to go, but made already a huge step forward, away from the ~20 year old UI they were keeping and cherishing.
I think they also need to get rid of tabs ASAP (at least disable them by default). The concept of tabs just doesn't feel right for an email client.
I'm asking, because I can understand wanting functionality (eg. decent calendar integration). I don't understand UI complaints but am willing to imagine "it could be better" (eg. UI-complaints of Gimp)... except I've used Thunderbird, and the UI does its job fine.
Sure, maybe with some MS ribbon-alike thingy it would work better for some, and maybe I'm a dinosaur, but most UI changes in programs I've used the last decade were either shrug or a bad idea. So I've become very hesitant about overhauling UIs simply because they come across outdated to some.
I've got Office 365 for Business for my personal email. Comes with OneDrive for Business (built on SharePoint) with 1TB storage, all the Office apps, Bing Chat(GPT) for Enterprise, Outlook app on Android/iOS etc. etc. Integrates perfectly on Windows.
The email service is great, works as expected and emails don't go undelivered with great spam filtering.
Can't think of a better provider. I used to be with Google Workspace but after transferring my Google account it's irreversible and can't go back to a 'personal' account while losing access to many Google services like (I know it's dead now) Stadia. Had to create a new 'personal' Google account and transfer everything over manually after doing a takeout - lost a few things like my old YouTube account and Google Play purchases.
The only way I can create a new email is: 1. Hit reply on an existing email and delete to; subject; and body; or 2. Go to contacts, select a person, and click email to, and then modify the "to" field to insert the correct address.
WTF?
-Microsoft probably.
More discussion: https://news.ycombinator.com/item?id=38212453
> The German Federal Commissioner for Data Protection and Freedom of Information, Ulrich Kelber, is also alarmed: On the social media network Mastodon, he described the data collection as "alarming" and announced his intention to pursue the issue at European level through the data protection authorities as early as next Tuesday.
One of my pet peeves against Microsoft is, precisely, how they bundled a mail client with their office suite, and one hostile to standards at that. A mail client that, somehow, only worked properly with other Office elements, and, at some point, it created interoperability issues if sender, receiver, and mail server, weren't all running Microsoft software.
Only available on Windows 12 devices with Microsoft-approved software.
Only €99 the first 20 months, then triples. Bundled with Microsoft Oven, Microsoft Fridge, Microsoft Wave, Microsoft Printer, Microsoft TV, Microsoft Sofa.
Never worry with virus again!
the bundle is not guaranteed to work with non-Microsoft Partners, such as Netflix, Steam, Android; companies need to submit for certification their hardware drivers; you can check the Compatibility DB available on the website. You may be downgraded to grayscale 360p if hardware is not verified with the cert level NBBcert 5 stars or another aproved Microsoft partner.
Availability in your country depends on your country subscription to Microsoft DRM-center, plan AA, and adherence to snoop-your-neighbor mutual agreement act 5000. China relations must be at level 304 or inferior, per mututal agreement 497.
To be eligible for support, you have to buy Microsoft Insurance Pack, and only network devices approved by Liberty Party or its subsidiaries are eligible. You must register at all times the current invitees at your house. If more than 2 invitees, you must apply, with 7-day precendence, for a license fun-at-home. The accuracy of your submission may be validated using Wifi sensors, per patent USPTO20130, and others. Patent Pending. Camera validation may be used if your credit score is under 200. If Microsoft agents knock at your door, failure to open the door will result in all subscribed pack being reduced to a plafond of 30 mins per day until Microsoft Corp and its partners are satisfied your way of life and current invitees are in the agreement of Microsoft, Oracle and Google tricorporation shared agreement.
They may have made their software more standard compliant, and when they gained enough market share, they tried locking competitors out of their environment.
They have precedent for this. Word (app), Word (Teams), Word (online office 365 thing). All slightly incompatible.
Gmail (email service) and Gmail (app).
Apple TV (device), Apple TV (iOS app), Apple TV (Mac app), Apple TV (Apple TV app) and Apple TV+ (streaming service).
This is accurate and Apple is mystify given that they are very focused on image and advertising. However I tolerate that more than Microsoft, as fixing formatting in my job is actual hell, people are tying to get work done and the tools are objectively broken and word is a de facto standard.
Although encrypted, the data is unencrypted when you decrypt it!
They should at least add double ROT-13...
Did whoever wrote this realize you need to be able to recover the cleartext for this to even work?
Both Gmail and Outlook are receiving passwords, then using those to perform IMAP requests from their servers. The difference is that Gmail had permission to do so, while Outlook did not.
Now, I know the answer is so that you can have push notifications sent to your mobile phone with every IMAP poll Microsoft does on your behalf, but that’s because the architecture of the new Outlook app likely borrows features of the Accompli mobile app they bought and maintained as Outlook mobile. That the desktop app re-uses the same APIs as the mobile app rather than process mail locally makes sense from a code reuse and efficiency standpoint, but really only because your accounts can seamlessly carry over to all your devices.
It’s arguable that the distinction between keeping your password in the cloud and keeping your password local is a security risk. However, if you previously used Outlook.com to check your IMAP email, and maybe this is where the feature derives from, then you already provided your IMAP password to Microsoft on the web. Likewise Google for importing IMAP to Gmail. We do this because it is nicer to get one inbox and one push notification across multiple accounts - when we want cloud providers checking emails for us.
It is less clear why a desktop app would do this unless you opted in to fancier service of some kind - e.g. viewing emails on the web when not at this device, or push notifications to your mobile phone, etc.
If Microsoft wanted to read your emails even with a locally stored and never shared IMAP password, they could still send telemetry derived from the local client to build an advertising profile based on local emails, or to display targeted ads. They don’t technically need your password to read your emails if you are using their email client.
It would be fine if Outlook was backing up encrypted data and then not sending the decryption key to Microsoft servers.
This is not a translation error either. The same mistake can be found in the German original.
> Did whoever write this realize you need to be able to recover the cleartext for this to even work?
The first author of the article has a degree in 'commercial information technology' and has worked as a sysadmin, so I assume they do understand that this is necessary, they may just have done a bad job of expressing that.
An article in a technical outlet should still do better in such regards.
It could have been phrased better, but the clear message is that Microsoft has pilfered access to unencrypted passwords, regardless of any transportation-level encryption.
iOS mail app allows it and all that data is synced to iCloud for most people. We just trust Apple isn't snooping.
Some run locally in the browser.
Many don’t send the credentials to be saved cloud-side.
I do think this is a big deal, certainly my expectation was that the New Outlook work alot like the old Mail app.
The page has 15+ trackers on it, so it must definitely ask for consent, and it shows as a big dialog with 3 buttons at the bottom.
It may be a regulatory requirement to display the info. It's my opinion doing it in such a disruptive and unintuitive manner is a good way to increase the bounce rate on a given site, especially when I've already got multiple browser settings enabled indicating my preference.