Email or username:

Password:

Forgot your password?
Niels K.

Don’t use “Outlook (new)” in #Windows 11. I just did a tcpdump and looked also at my #mail servers when setting up an account in there. The mail client only spoke with Microsoft-servers, never with my mail-servers and I saw on my mail-servers only connections from Microsoft-IPs.

134 comments
Martin Schmitt

@nielsk So would it make sense to block MS on submission and IMAP ports? What legitimate business could they have?

Niels K.

@unixtippse If your users use the new Outlook which will replace Windows Mail you can’t block them.

Martin Schmitt

@nielsk You haven't tested whether it falls back to direct communication, though, have you?

Niels K.

@unixtippse No, I didn’t. I just had a support team member telling me that Outlook didn’t work and if we can make it work (it worked for him after a reboot) and that’s why I did what I did.

Leeloo

@nielsk @unixtippse
It should at least be possible to put your mail server on an rfc1918 ip, they wouldn't block corporate mail servers.

Use a VPN if you need access on the go.

Niels K.

@js @unixtippse Well, I operate a mail-platform for external users. I can’t do that because the support-team will kill me.

J$

@nielsk @unixtippse Well, I’d say its not up to you to break your spine to create workarounds for broken-by-design end user software. They have plenty of working clients to choose from.

EndlessMason

@js
That's literally what a support engineer's job is lol
@nielsk @unixtippse

Stefan Fendt

@nielsk @unixtippse

You can and you should block these.

These users need to be protected from themselves.

Wolf480pl

@nielsk @unixtippse I think from a security point of view, it's better when it doesn't work. More than that, every time your server sees a user successfully log in from a Microsoft IP, it should reset (or disable) that user's password, since you have to assume it's compromised.

railmeat

@unixtippse @nielsk

It sounds like they proxy all the connections so all the mail passes through their servers. I wonder how long they keep it? I guess everyone’s emails become grist for AI.

I wonder what their terms of service say about that?

Niels K.

@railmeat @unixtippse I dunno. But it is more less the same what they do with the mobile Outlook-clients

railmeat

@nielsk @unixtippse

I guess that is the world we live in now. Not really my preference.

Yet another reason to move my computing to self hosted and possibly Linux.

Mr Cool

@railmeat @nielsk @unixtippse If we don't stop companies from implementing toxic business culture, it will get worse. Someday we will live in a world we don't really want to live in. We will no longer own anything, not even our data.
Too many people don't care and even defend these companies.

Tom

@mrcool @railmeat @nielsk @unixtippse

Agreed, except for the word 'someday'.

It will get worse for sure, but that's already the world we live in.

Mr Cool

@Tom @railmeat @nielsk @unixtippse You are right. Even I can see how I'm slowly getting used to it. And that's how it will continue. Small steps, so that people don't realize that their rights and their data are gradually being taken away from them.

X

@mrcool

Too late! We already gave up our entire life to them.
Sadly, this is true.

Chewie

@railmeat if you have time, bandwidth and money, I would highly recommend self-hosting, I've learnt loads by doing it!

seism0saurus 🦕

@railmeat @unixtippse @nielsk

It's documented, that they store the credentials to the Mailservers in cleartext on their servers and fetch the Mails there. It's a shitty design.

railmeat

@seism0saurus @unixtippse @nielsk

Credentials in plain text? I thought we got past that in the’90s.

Where is that documented?

seism0saurus 🦕

@railmeat @unixtippse @nielsk

Otherwise they can't access your Mailservers.
I'm not sure if the data at rest is unencrypted but at least it is reversible since they need it for login to your mailservers.
It is definitely not a standard like bcrypt or scrypt there the credentials are secured by a one way function

heise.de/en/news/Microsoft-lay

@railmeat @unixtippse @nielsk

Otherwise they can't access your Mailservers.
I'm not sure if the data at rest is unencrypted but at least it is reversible since they need it for login to your mailservers.
It is definitely not a standard like bcrypt or scrypt there the credentials are secured by a one way function

Gavin

@unixtippse @nielsk Everything Microsoft does now should be viewed through the prism of surveillance capitalism and the collection of behavioural surplus.

Hijacking your email traffic is a great way to collect data for targeted ads.

alihan_banan

@unixtippse @nielsk why not stop using it altogether instead of going all out sadomaso just to use their crappy software?

DELETED

@nielsk

F..k M$ so hard, those piece of sh*t!

what a plague! But they are not the only guility here, those fucking IT managers are!

🌻 Defederate Threads 🌻

@nielsk I wonder if this is how Microsoft avoids scrutiny by EU regulators.... they exfiltrate as much personal data as possible so police get data that #chatcontrol would have taken.

Pavle

@nielsk I noped out of there as soon as I saw the notification that they would be syncing my data to their ~cloud~

I didn't even realize it included passwords too. That's even worse than I thought.

evin / yujiri

@nielsk jesus! they should be sued hard for this

Christian Huitema

@nielsk That's not exactly new. Outlook started uploading mailboxes to their cloud service for POP3 and IMAP4 accounts 8 or 9 years ago. About the time when I stopped using it. Thank you for reminding people about it!

europlus :autisminf:

@nielsk my understanding from when this first blew up was that MS stores your mail on their servers after picking it up from your mail server. What a nightmare.

Data Artist

@nielsk Don't use Outlook (no matter whether old or new) I'd suggest to make the message more universal and understandable for people

Karsten

@nielsk you can stop the sentence after "Outlook".

#Windows #mail

orava

@byteborg @nielsk and replace Outlook with "Microsoft products"

osmodia

@nielsk The mobile Outlook app (on at least iOS) does this for many years.

Dźwiedziu

@nielsk That is one of the grave faults of Outlook. One other critical one I've found is that people are still using it⸮

Ayo Ayco

@nielsk If I remember correctly I saw a setting before asking if I want to sync third-party mail to their cloud… maybe they turned that ON by default

Gulli

@nielsk i've seen this behavior in Outlook 2019 as well. With some new accounts (don't know what triggers this behavior) every traffic for external imap accounts goes through Microsoft. IT was luck to see that, as some clients couldnt establish a connection and others could. Completely random.

Scott Knowles

@nielsk Century Link requires ISP users to use their outgoing e-mail server so they can monitor your traffic and content. They allow other incoming e-email servers. AT&T is worse. They limit what domain names users can send or receive through their e-mail servers. I can't send or receive e-mail rom my own domain name and Website host. I have to wait for when wifi is available.

Jernej Simončič �

@wsrphoto @nielsk Blocking outbound port 25 is pretty common, since a lot of spam originates from infected end-user computers. Use the submission (587) or SMTPS (465) port when sending mail, those should be open (because they only work with encryption and authentication).

Scott Knowles

@jernej__s @nielsk Thanks. Century Link monitors users' volume, domain names and content on all ports. Twice I've had my account locked because of another user sent spam with my e-mail address. It took a week to get them to check and correct things, and unlock my account. Except for cable there are no options for companies since they have monopoly as telephone service provider.

Extreme Electronics

@nielsk Yep, spy-ware, and great fun when you only have locally accessible mail servers.

Winter Trabex

@nielsk

My rule of thumb is: if it's Microsoft, don't use it.

Take It EV Podcast 🎙️

@nielsk @Maker_of_Things google and microsoft. Nothing good comes out of them .
When it comes to security, microsoft is just a joke atm

DELETED

@TechTriumph
Don't use ANY #microsoft products apart from mousepads if you like those. Not even a feckin' #keyboard: One that i plugged into my #debian desktop instantly began harassing my #dbus #daemon
@nielsk

Scotty Trees

@nielsk you spelled “don’t use windows 11” wrong 🤣

Lukas Rox

@nielsk I just switched to Thunderbird for that reason...
Outlook (New) is a mess, it won't allow you to manually configure a mail server, so if it doesn't work automatically, you're out of luck

🅰️🇱🇪

@nielsk then let's not talk about how it manages email images.

Keen

@nielsk and the 365 web client I'm forced to use for school keeps begging me to try adding external accounts

George Liquor :verified:

@nielsk Classic MITM attack (Microsoft In The Middle)

Arcane Alchemist

@liquor_american @nielsk And classic Phishing: Please enter your login credentials here - Microsoft support

F4GRX Sébastien

@nielsk do you mean that they tunnel imap connections through their servers?

edit: wow ok we didnt know.

Pete Orrall

@nielsk I call that email client "Micro$oft Lookout!" for good reason.

lorax

@nielsk
I would personally advise not to use Windows and other Microsoft Products at all if you can.

Jakra

@nielsk The only email I use with outlook is my work exchange server. They already have access to whatever they want, and they are limited by contract, whatever that's worth. Everything else is a nah.

David Haller

@nielsk This is also the case for the Outlook Android app (maybe iOS too). My organization blocks Microsoft servers from accessing our mail servers and automatically sends a mail to affected users that they must immediately change their password.

ducksauz 🦆

@nielsk Outlook Mobile has been doing this for at least half a decade now. It's why we banned it at $BigTechCompany where I used to work.

ianto

@nielsk this can be extended to don't use outlook (any), and don't use windows 11. I appreciate many folks have no choice.
I'm not some militants anti MS nutter though: Word v6 through to office XP was excellent, and i still like windows 10 when I have to run things that aren't available in other environments.
This redirecting your mail traffic is just nasty though, means your server creds have been exported (along with all your email, obvs).

24😷-1🇺🇦5

@nielsk Not being able to open .PST files is a sufficient reason to not use it.

w
also it barely works as an email client and is missing most of Outlook features (including obscure things like dragging and dropping). I'm astonished that anyone at Microsoft willingly put this thing out into the world
jamespthomas

@nielsk have not used outlook since they told me they lost my password,i wont be at the office today or the next or the ones after365

Condalmo.

@nielsk What does this mean? Break it down for me, your friendly neighborhood layperson

Niels K.

@condalmo “Outlook “New””will replace Windows Mail. When you use Outlook New, you give Microsoft access to your mail-account and they store your credentials incl. your password and mails on their servers, even if you are not using them as your e-mail-provider but a totally different mail-provider. It is the same for the Outlook-client on iOS, Android and macOS.

Jonathan R

@nielsk

Thanks for the warning.

I have been happily using #mozilla #Thunderbird for years.

Jim Vernon

@nielsk It's a web app wrapped in a browser shell. All privacy concerns aside (I use M365 for email and OneDrive), I tried using it for awhile and abandoned it due to a complete lack of offline functionality. They don't make it easy find the original Outlook either. Have to download a special O365 installer to get it.

cameronbosch :endeavourOS:

@nielsk Or better yet, don't use ANY built-in Windows 11 app! Or even better still, don't use Windows 11! 😂

CausticMango

@nielsk I wouldn’t use Outlook as an email client for anything other than a Microsoft email service.

In fact, I wouldn’t use it *at all* if it weren’t for persistent bugs in the Exchange protocol that causes calendar issues with 3rd party clients.

theothertom

@nielsk My wife had a go with it, and aside from the “MS read all your email” thing, it also had an amazing bug where her inbox didn’t show the most recent message. As in, you could could only see a message once there was a newer email. Was totally maddening, and really hard to spot.

Salva

@nielsk I use @thunderbird in Windows instead :blobcat:

hobbsc

@nielsk is it basically just a web client like maybe an electron based program? That would make sense if so. Not defending it, just trying to reason through the why.

none gender with left politics

@nielsk @pcy it straight up told me that it would mirror my mail on their server when it tried to push it to me the first time. I immediately rejected giving it my credentials and installed Thunderbird.

Fuck that shit

alihan_banan

@nielsk wow, so Microsoft proprietary software on their proprietary OS can do whatever Microsoft wants without asking you? What a surprise, nobody could have anticipated that

No Useless Tech

@nielsk

Protip:

Don't use anything by Microsoft if you can avoid it.

🌻 Defederate Threads 🌻

@nielsk Um, yeah. Its total #spyware sh_t and the main beneficiary seems to be the Russian government.

“Although Microsoft explains that it is possible to switch back to the previous apps at any time, the data will already be stored by the company,” Heise reported. “This allows Microsoft to read the emails.”

You can’t use the new Outlook without syncing all this information with Microsoft Cloud
proton.me/blog/outlook-is-micr

Mike Trotz

@nielsk This would be expected based on how the New Outlook works. It's just the web version in a window. There are no PST files for local storage for IMAP or POP accounts; it is all stored on the web.

eons Luna

@nielsk I genuinely hope Microsoft gets investigated for, and ultimately stopped from doing this, and be forced to make a proper mail client app that isn’t just a glorified web app that does this.

Genuinely hate the new Outlook app, that piece of shit needs to die in a fire.

Ukiah Danger Smith

@nielsk does your imap server use SSL certs? That should prevent mitm attacks like this. Or at least warn of them.

ed(1) conference

@UkiahSmith

It would depend on which piece is verifying the SSL/TLS certs.

If the Outlook (New) client does the "I'm talking to neilscorp.example.com" verification, then it's less bad because in theory the MS machines are only acting as a conduit for encrypted bits (still dumb because it breaks when attempting to connect to mailservers in RFC1918 ranges).

However, if the local client is talking to the MS cloud, and it's the cloud machines initiate the conversation to the mail-server and checking the SSL/TLS certs (which is what I suspect is happening; @nielsk doesn't provide pcaps nor detail whether the client is connecting to some web-servicey port like 443 instead of mail-servicey ports), then SSL/TLS certs don't protect.

@UkiahSmith

It would depend on which piece is verifying the SSL/TLS certs.

If the Outlook (New) client does the "I'm talking to neilscorp.example.com" verification, then it's less bad because in theory the MS machines are only acting as a conduit for encrypted bits (still dumb because it breaks when attempting to connect to mailservers in RFC1918 ranges).

Andreas Bulling

@nielsk Don't use Microsoft. It's that simple.

David Croyle

@nielsk I would simplify this statement down to "Don't use Outlook. Don't use Windows 11." or perhaps simply "Don't use Windows."

Gramshelper 🇨🇦😷🌻🏳️‍🌈🏳️‍⚧️

@nielsk Just bought a new laptop. It came with Windows 11. I am not very savvy on any of this. All these warnings about Microsoft scares the crap out of me. I basically just use it to borrow books from the library and then download them to my Kobo. Hopefully it won't cause me any problems. Why do these companies have to make everything so complicated?

Niels K.

@WJBL Use a decent mail client like Thunderbird for example
thunderbird.net/en-US/

And using a browser that is not by the big data collectors might be helpful, too
mozilla.org/en-US/firefox/new/

SouprMatt

@nielsk The new outlook is basically just a wrapper for the M365 web app. Do not use if you’re not comfy with your data being on M365.

Marc Haber

@einfachnurmark
@nielsk dont worry. People dont care. Theyre still going to use it.

Jörg 🇩🇪🇬🇧🇪🇺

@nielsk Fortunately I never used Outlook on my private computer and never will. Currently I’ve thunderbird in use.

Henrik Kramselund - kramse

@nielsk do they validate certificates?

I reported similar stuff when I got my Nokia N97 probably around 2010. Was confusing that I didn't get a warning when setting up mail

This is a man in the middle, and should be treated as a vulnerability! Shame on them!

🇺🇦 haxadecimal

@nielsk
What a surprise, that Microsoft would decide to Man-in-the-Middle their user's email, to steal data, target advertising, train AI, and who knows what else.
Microsoft is doing their damnedest to drive users to alternatives to their products.

skorkr.arj

@nielsk So it's not only janky as hell, ugly and with a horrific ui - it also doesn't care about privacy? What a clusterfuck

Linux Is Best

@nielsk@mastodon.social If you read the TOS (terms of service), you agree to use Microsoft as your email proxy server. As you have discovered, the app shares the details with Microsoft who then acts as a middle man between you and your email.

Stefan Schmidt

@nielsk For your amusement: I read Windows 3.11 and it took me a while.

William B Peckham

@nielsk Another great reason to not use Windows at all! There is no Microsoft product that is truly benign since MS-DOS.

Mike Spooner

@nielsk The Android version of Outlook has been doing that since at least 2017 (tested on my own mailserver), and maybe even earlier.

Ken O'Driscoll

@nielsk When you install or switch, it clearly explains that all accounts are currently proxied through Microsoft.

I don't use it and am certainly not a Microsoft fan, but they don't hide "new" Outlook's limitations. It's also a beta product.

Threadbane

@nielsk
Better yet, don't use ANY Micro$haft product. There are two basic choices, Mac or Linux. Using Gatesware at all is a fundamental error.

mirabilos

@nielsk pc-pine should still work as MUA and newsreader.

Go Up