July 1st, 2024

Microsoft lays hands on login data: Beware of the new Outlook (2023)

Microsoft's new Outlook raises privacy concerns by sending login data to Microsoft servers. The program replaces Windows Mail and Calendar in 2024, prompting users to store email credentials with Microsoft, potentially compromising data privacy. The Federal Commissioner for Data Protection in Germany plans to investigate Microsoft's data practices. Users are warned about data security risks and unauthorized data transfers.

Read original articleLink Icon
Microsoft lays hands on login data: Beware of the new Outlook (2023)

Microsoft's new Outlook is causing concern as it sends login data to Microsoft servers, potentially compromising user privacy. The new Outlook, set to replace Windows Mail and Calendar in 2024, prompts users to switch and store their email credentials with Microsoft. This move allows Microsoft to access and analyze emails, raising data privacy issues. The program also synchronizes non-Microsoft accounts with the Microsoft cloud, giving the company full access to emails, calendars, and contacts. Concerns have been raised by the Federal Commissioner for Data Protection in Germany, who plans to request a report from the Irish Data Protection Commissioner regarding Microsoft's data practices. Users are advised to be cautious when trying out the new Outlook due to potential data security risks and unauthorized data transfers to Microsoft servers.

Related

Microsoft admits no guarantee of sovereignty for UK policing data

Microsoft admits no guarantee of sovereignty for UK policing data

Microsoft admits inability to guarantee UK policing data sovereignty on its public cloud, potentially breaching UK data protection laws. Concerns persist despite company's efforts to address issues, impacting all UK government users.

MSFT wants Local accounts gone after it erases its guide on how to create them

MSFT wants Local accounts gone after it erases its guide on how to create them

Microsoft has removed a guide on converting Microsoft accounts to Local accounts, emphasizing their preference for Microsoft sign-ins. Users may face challenges transitioning due to privacy concerns.

Windows: Insecure by Design

Windows: Insecure by Design

Ongoing security issues in Microsoft Windows include vulnerabilities like CVE-2024-30080 and CVE-2024-30078, criticized for potential remote code execution. Concerns raised about privacy with Recall feature, Windows 11 setup, and OneDrive integration. Advocacy for Linux desktops due to security and privacy frustrations.

Windows: Insecure by Design

Windows: Insecure by Design

The article discusses ongoing security issues with Microsoft Windows, including recent vulnerabilities exploited by a Chinese hacking group, criticism of continuous patch releases, concerns about privacy invasion with Recall feature, and frustrations with Windows 11 practices. It advocates for considering more secure alternatives like Linux.

Microsoft Alerts More Customers to Email Theft in Expanding

Microsoft Alerts More Customers to Email Theft in Expanding

Microsoft alerts more customers about email theft post-Midnight Blizzard hack by Russian government. Stolen emails accessed, shared with affected organizations for transparency. Ongoing attack used for planning further attacks. Assistance provided to mitigate risks.

Link Icon 5 comments
By @defrost - 4 months
Naturally we can trust Microsoft with our exfiltrated credentials though surely?

Microsoft tells yet more customers their emails have been stolen

    It took a while, but Microsoft has told customers that the Russian criminals who compromised its systems earlier this year made off with even more emails than it first admitted. 

    We've been aware for some time that the digital Russian break-in at the Windows maker saw Kremlin spies make off with source code, executive emails, and sensitive US government data. Reports last week revealed that the issue was even larger than initially believed and additional customers' data has been stolen. 
https://www.theregister.com/2024/07/01/infosec_in_brief/

Okay. Maybe not then.

By @stranded22 - 4 months
I couldn’t get my custom email domain on iCloud to send correctly without using alias / on behalf of. Tried many ways too.

So the new outlook is backwards tech for me

By @andersa - 4 months
New outlook is no longer useful for accounts that aren't already from Microsoft, and who knows how long we get to keep using the old one. Thunderbird says it's no longer maintained by Mozilla. Do we have anything better yet?
By @illnewsthat - 4 months
Missing (2023)