5 ms·
This is an email client. Not email server. > your IMAP and SMTP username and password are transmitted to Microsoft in plain text. What the heck?
by hdhdjdjd 3y ago
This is an email client. Not email server.
> your IMAP and SMTP username and password are transmitted to Microsoft in plain text.
What the heck?
- NoZebra120vClip 3y ago> > your IMAP and SMTP username and password are transmitted to Microsoft in plain text. I think that is not true. I think that is a lie on Proton's behalf. When I set up the email client, it connects via OAUTH2 to the other services. It's connected as an app and not via credentials. If it connected via bare credentials, then it'd be a "legacy app" and you'd need to generate an "app password" for it, but you don't.
- miles 3y ago>> your IMAP and SMTP username and password are transmitted to Microsoft in plain text. > I think that is not true. I think that is a lie on Proton's behalf. Sadly, it is all too true: Microsoft lays hands on login data: Beware of the new Outlook https://www.heise.de/news/Microsoft-lays-hands-on-login-data-Beware-of-the-new-Outlook-9358925.html https://www.heise.de/news/Microsoft-lays-hands-on-login-data... Warning: New Outlook sends passwords, mails and other data to Microsoft https://mailbox.org/en/post/warning-new-outlook-sends-passwords-mails-and-other-data-to-microsoft?nl=e https://mailbox.org/en/post/warning-new-outlook-sends-passwo...
- Arnavion 3y agoTheir concern is valid, but it's weird that they call it "in plain text". "Plain text" has a specific meaning of "unencrypted", whereas this is encrypted in a TLS connection. Yes, both TFA and the original heise.de article say (paraphrased) "Although it's in a TLS connection, it's in plain text." but it's just confusing to phrase it this way, especially since it becomes easy to remove the "Although it's in a TLS connection" clause, as you did in your quote. Their objection is that the credentials are being transmitted to and stored by Microsoft at all, instead of Microsoft generating and storing an automation token / app password. That is a valid concern. But tacking on "in plain text" to it just creates confusion.
- nuker 3y ago> But tacking on "in plain text" to it just creates confusion. Today, when the context is service provider and customers, "plain text" is used to say that service provider has the data unencrypted.
- c0pium 3y agoThat’s not what transmitted in plain text means. Transmitted in plain text means unencrypted on the wire, which is not the case here. Proton definitely knows that, and deliberately worded it this way for maximum scare factor. If they’ll be deceptive here, where else will they be?
- xarope 3y agoI would say that plaintext is correct. if password "secret123" is sent to you, it doesn't matter if it was sent via carrier pigeon, locked up in a secure briefcase and delivered by someone driving an aston martin, or via a TLS channel. It's still plaintext, because the receiver now has the actual password, and not a hash of the password.
- Arnavion 3y agoIt does matter. Transmiting it in plain text, ie unencrypted, is much worse, because it means eavesdroppers also have access to it.