Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Outlook.com Android App Leaves Email Messages Exposed
Newest First  |  Oldest First  |  Threaded View
MrTibbs
50%
50%
MrTibbs,
User Rank: Apprentice
5/21/2014 | 6:34:44 PM
Re: Default Encryption
Hey Microsoft, At least a warning during installation is warranted here!

The Outlook desktop app has better controls over its local OST datafiles than this app.

I have used Touchdown for Exchange since Android 2.x, which DOES encrypt its datastore, plus I encrypt both internal storage and SD card and disable the developer option.

-MT

 
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
5/21/2014 | 3:41:08 PM
Re: Default Encryption
Randy you are right, but in this case I believe that the app itself his poor under security perspective. Microsoft statement has no sense. Guys who have designed the app have no clear idea of security requirements neither user privacy.

Since we will read reply like the one provided by MS we have no hope to user better application .... 

Please give a look to my post on the topic and read the stats I mentioned on HP Fortify study ...

http://securityaffairs.co/wordpress/25103/digital-id/outlook-app-leaks-encryption.html

Thanks

Pierluigi
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
5/21/2014 | 2:07:53 PM
Re: Default Encryption
Sad to say but the Android apps do not have the scrutiny that apple apps have. The android platform is solid but the apps need to be held to a higher level than they currently are.
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
5/21/2014 | 12:21:57 PM
Re: Default Encryption
The reply provided by Microsoft is simply absurd. This is the wrong way to think security by design. Let's blame the others ... it's too easy!

 
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
5/20/2014 | 9:59:30 PM
Default Encryption
It seems that this is a gaping security flaw considering the ease of extraction for an SD card. Majority of users as posed in the article are default set to be unencrypted, so this hole will be available for many android based users. 

Is there any detriment to defaulting settings to encrypt instead of defaulting to unecrypted from a vendor perspective? Allow the user to make the choice but make them consciously choose to become vulnerable. This way the majority of unaware users will not be unknowlingly in danger.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Enterprises Are Assessing Cybersecurity Risk in Today's Environment
The adoption of cloud services spurred by the COVID-19 pandemic has resulted in pressure on cyber-risk professionals to focus on vulnerabilities and new exposures that stem from pandemic-driven changes. Many cybersecurity pros expect fundamental, long-term changes to their organization's computing and data security due to the shift to more remote work and accelerated cloud adoption. Download this report from Dark Reading to learn more about their challenges and concerns.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-38694
PUBLISHED: 2022-01-18
SoftVibe SARABAN for INFOMA 1.1 allows SQL Injection.
CVE-2021-38784
PUBLISHED: 2022-01-18
There is a NULL pointer dereference in the syscall open_exec function of Allwinner R818 SoC Android Q SDK V1.0 that could executable a malicious file to cause a system crash.
CVE-2021-38785
PUBLISHED: 2022-01-18
There is a NULL pointer deference in the Allwinner R818 SoC Android Q SDK V1.0 camera driver /dev/cedar_dev that could use the ioctl cmd IOCTL_GET_IOMMU_ADDR to cause a system crash.
CVE-2021-22566
PUBLISHED: 2022-01-18
An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as executable from an unprivileged context. This can be leveraged by an attacker to bypass executability restrictions of kernel-mode pages from user-mode. An incorrect setting of PXN bit...
CVE-2021-33965
PUBLISHED: 2022-01-18
China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by POST request, and the parameter mesh_enable and mesh_device have a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.