4 ms·
It is encrypted in transit, but Microsoft is on the receiving end of that transit and gets the plain text password. The encryption does nothing to prevent the t
by matrss 3y ago
It is encrypted in transit, but Microsoft is on the receiving end of that transit and gets the plain text password. The encryption does nothing to prevent the third party, that is Microsoft, from impersonating the user and reading all their mail.
- mynameisvlad 3y agoHow would a hashed password fix that problem?
- matrss 3y agoIt would make it harder for them to impersonate their users and read all their mail. I would still be concerned that they want to run a rainbow table attack against it though. They should not steal user credentials at all, because it is simply not necessary for a functioning email client.
- mynameisvlad 3y agoWhat? They would use the hashed password to login to the server, using something like XOAUTH2. That’s the point of the hashed password. It accomplishes nothing other than revocation, which can be done already by changing your password.
- matrss 3y agoWhat you are referring to is called an access token and has nothing to do with hashed passwords. A hashed password cannot be used directly to authenticate, otherwise it would not be a hashed password, but just a password (or access token, which is the same really). I don't understand how hashed passwords got into this discussion though. My point is that microsoft should have no way to authenticate as an outlook user against their third party mail provider without the user explicitly giving them permission to do so and what they do is strictly unnecessary to provide the functionality of an email client.
- gmueckl 3y agoIt's worse: anybody who can proxy the communication between Outlook and the MS servers can impersonate the user.
- matrss 3y agoIt is not entirely clear to me from the article that this is the case. I'd assume that they had to at least install their MitM certificate into the OS's trust store to intercept that message. If not then this is indeed even worse.
- phendrenad2 3y agosigh It's literally encrypted. You can try to derail the topic, but we're arguing about a very simple fact here. It's either encrypted or not. It's not complicated.
- matrss 3y agoYes, it is literally encrypted in transit. This encryption, however, does not offer any value in protecting the user from microsoft stealing their credentials, because microsoft is the recipient of that encrypted message and is able to decrypt the credentials and therefore has access to the plain text password. Just like this comment I am writing is literally encrypted when it is send to HN, and still everyone can read it.
- phendrenad2 3y agoOkay, I thikn the problem is, when someone says that something is "sent in plaintext" that usually means that it's interceptable. However, in this case, maybe, the author means that "it's being sent in a form that they can use, not just being stored like LastPass or something". Of course, the entire point of the article is that it's being sent in a format that they can use to connect to your server, so it's a strange statement to drop in the middle of the article.
- matrss 3y agoFirst of all, the article shows that it is indeed interceptable (although they didn't mention which additional steps, if any, were necessary to achieve that). And yes, the issue is obviously that it is send in a way that microsoft can (ab)use. > [...] tunneling [through an encrypted channel] back to their servers in plain text Seems pretty clear to me. The message that is send contains the password in plain text. Any encryption that is applied in transit is absolutely irrelevant and meaningless. Just microsoft receiving the credentials is only marginally better than anyone getting them. In both cases the account will be compromised.
- phendrenad2 3y ago