Major Security Issues Already Found In Outlook For iOS And Android

Status
Not open for further replies.

GMDS44

Reputable
Apr 16, 2014
90
0
4,660
and here I was about to install the APP into my work android phone.
I guess I will keep using gmail 5.1 for my exchange needs. It works just fine anyway.
 

wirefire99

Honorable
Jun 20, 2013
16
0
10,520
People who think ANY data is secure are fooling themselves. It is just about how easy it is got someone else got get it. This is overall pretty poor but if businesses continue to push for cloud based services, especially small businesses, they need to realize that their information, no longer belongs to them.
 

crikey2

Distinguished
Feb 15, 2009
19
0
18,510
Yes, stick with gmail - cause gmail definitely doesn't store your email and attachments on Google's servers :p
 

GMDS44

Reputable
Apr 16, 2014
90
0
4,660


I trust Google more than Microsoft when it comes to this matter.
Anyway, using an APP from the day it is realeased is just a bad IDEA overall. Wait a couple of months (yes months) before a decent/stable/secure version goes out.

 

JorgTheElder

Reputable
Jan 30, 2015
2
0
4,510
I would not consider any of this a problem if the app warned you up front that is what is was doing. If I was using it with Office 365, I would have not problem with Microsoft storing my credentials. :)

However that fact that it provisioned such a cloud-based user-agent on my behalf is terrible. Almost as terrible as the fact that they provide no interface to de-provisions your account. Delete the client from all your devices and the cloud-based agent will continue accessing your email account about once a minute for some unknown amount of time.

I finally reset my password and deleted the device partnership to kill its access to my account.
 

JorgTheElder

Reputable
Jan 30, 2015
2
0
4,510


They are not really flaws, they are design decisions and it actually works the same way other products do. However, other products tell you how they are working, and let you make some intelligent decisions.

I have no problem using the app as it is with an Office 365 account as I would not have an Office 365 account if I did not trust MS with my data. That said, the company I work for does not trust Microsoft with their data, and I think the app should have done a much better job letting me know what it intended to do with that data. It should also make it very easy for me to clean up the data when I am done with the service.

For now, they get a pass because I used prerelease software without reading the documentation. I would be much angrier if it was a shipping product.
 

FirstNameKevin

Reputable
Jan 31, 2015
1
0
4,510
And the fourth unmentioned security issue is the applications disregard for ActiveSync securotdevice security policies. Users who log in with the app are not required to have a pin or password on their device and the program does not allow for remote device wipe in the event if a lost or stolen device because they don't install a device administrator. I've already taken action to block the app from connecting to my company's Exchange server.
 

alextheblue

Distinguished
And you were surprised that a Microsoft product had security flaws out the Wazoo?
I figured it out the other day. It's M$' new anti piracy strategy.

Make everything so $h!t that nobody would even bother stealing it.
Except it's not truly an MS product at this point. They JUST bought it. It definitely needs a major overhaul, but where was this stink and outcry when it was being used by tons of people before MS bought them?
 

freiheitner

Distinguished
May 7, 2008
66
0
18,630
Any time a person inputs their username and password into any portion of an application, the developer of that app technically has access to that username and password. You don't know how they're using it behind the scenes.
 

mrmez

Splendid
Make everything so $h!t that nobody would even bother stealing it.[/quote]
Except it's not truly an MS product at this point. They JUST bought it. It definitely needs a major overhaul, but where was this stink and outcry when it was being used by tons of people before MS bought them?
[/quotemsg]

That makes M$ even MORE stupid!

"Hey guys, let's buy this company, and rebrand all their software to M$!"

"Great idea, Jenkins. Do you think we should check the software thoroughly, to, you know... make sure we're not putting our precious company name on a hot steaming turd?"

"Well... we've redesigned the icons, is that enough?"

 
Status
Not open for further replies.