Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Webhead
2125 posts

Uber Geek
+1 received by user: 691

Moderator
Trusted
Lifetime subscriber

Topic # 163236 2-Feb-2015 21:46
Send private message

Thought some of you might want to know about this incredible security hole, made possible by the new Outlook iOS and Android app.

In short: Microsoft stores usernames, passwords, emails and attachments for internal email systems when this service is used.

Microsoft Outlook app for iOS breaks your company security


If I was running a company email server I would block this system from accessing that server as quickly as possible.




Create new topic
597 posts

Ultimate Geek
+1 received by user: 132


  Reply # 1229060 2-Feb-2015 22:27
One person supports this post
Send private message

No less secure than having a Gmail account.

For most companies this isn't even an issue, for those with high security needs they'll just block it.

That article just looks like scaremongering.

Might just be another case of read the description of the app before you use it.




Regards
Stefan Andres Charsley

gzt

10264 posts

Uber Geek
+1 received by user: 1578


  Reply # 1230075 3-Feb-2015 00:45
Send private message

It is an interesting article. Yes it's not different from Google markedly, but Microsoft customers are different and Microsoft has lost a bit of trust with this freer approach.

1575 posts

Uber Geek
+1 received by user: 355


  Reply # 1230385 3-Feb-2015 11:47
2 people support this post
Send private message

If admins were TRUELY this concerned with security, they wouldnt be using Android anyway . Or laptops that users can take home/take offsite (& let there family & kids use)

4991 posts

Uber Geek
+1 received by user: 1325

Trusted
Microsoft

  Reply # 1230388 3-Feb-2015 11:48
Send private message

Outlook for iOS & Android incorporates cloud services to improve app performance and provide advanced functionality including predictive search, recent attachments view, large attachment handling and more.

At launch, these cloud services are not covered under the Office 365 Trust Center, which provides security, privacy and compliance Information for Office 365 customers.

We will be updating Outlook later this year to enable it to be covered by the Office 365 Trust Center.

5275 posts

Uber Geek
+1 received by user: 2290

Trusted
Lifetime subscriber

  Reply # 1230402 3-Feb-2015 11:58
Send private message

There reality is there are many exchange capable email clients out their that people could use and it would be the same issue.





Chorus has spent $1.4 billion on making their xDSL broadband network faster. If your still stuck on ADSL or VDSL, why not spend from $150 on a master filter install to make sure you are getting the most out of your connection?
I install - Naked DSL, DSL Master Splitters, VoIP, data cabling and general computer support for home and small business.
Rural Broadband RBI installer for Ultimate Broadband and Full Flavour

 

Need help in Auckland, Waikato or BoP? Click my email button, or email me direct: [my user name] at geekzonemail dot com


What does this tag do
976 posts

Ultimate Geek
+1 received by user: 203

Subscriber

  Reply # 1230457 3-Feb-2015 13:03
Send private message

Maybe an issue for some businesses, but could be a good thing for the high percentage of people out there who are currently connecting to POP accounts without using SSL :)

1640 posts

Uber Geek
+1 received by user: 419


  Reply # 1240486 16-Feb-2015 23:46
Send private message

I'm curious to know what happens when you perform a remote device wipe from your exchange account when the app is using one device id across multiple devices as the article states.

3415 posts

Uber Geek
+1 received by user: 405

Trusted

  Reply # 1240493 17-Feb-2015 00:31
Send private message

jnimmo: Maybe an issue for some businesses, but could be a good thing for the high percentage of people out there who are currently connecting to POP accounts without using SSL :)


Haha so true. I can't believe people are still using POP these days considering the whole calendar/contact and real time email sync that activesync supports....





2174 posts

Uber Geek
+1 received by user: 359


  Reply # 1240505 17-Feb-2015 07:03
Send private message

Our IT department blocked this app last week so am now using Gmail app as this is your only stock email option on Lollipop



MadEngineer: I'm curious to know what happens when you perform a remote device wipe from your exchange account when the app is using one device id across multiple devices as the article states.


At least on the Android app it doesn't require device manager rights to install so i guess it is not even an option to remote wipe device using Outlook app

Create new topic

Twitter »

Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.