Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Outlook.com Android App Leaves Email Messages Exposed
Newest First  |  Oldest First  |  Threaded View
MrTibbs
50%
50%
MrTibbs,
User Rank: Apprentice
5/21/2014 | 6:34:44 PM
Re: Default Encryption
Hey Microsoft, At least a warning during installation is warranted here!

The Outlook desktop app has better controls over its local OST datafiles than this app.

I have used Touchdown for Exchange since Android 2.x, which DOES encrypt its datastore, plus I encrypt both internal storage and SD card and disable the developer option.

-MT

 
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
5/21/2014 | 3:41:08 PM
Re: Default Encryption
Randy you are right, but in this case I believe that the app itself his poor under security perspective. Microsoft statement has no sense. Guys who have designed the app have no clear idea of security requirements neither user privacy.

Since we will read reply like the one provided by MS we have no hope to user better application .... 

Please give a look to my post on the topic and read the stats I mentioned on HP Fortify study ...

http://securityaffairs.co/wordpress/25103/digital-id/outlook-app-leaks-encryption.html

Thanks

Pierluigi
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
5/21/2014 | 2:07:53 PM
Re: Default Encryption
Sad to say but the Android apps do not have the scrutiny that apple apps have. The android platform is solid but the apps need to be held to a higher level than they currently are.
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
5/21/2014 | 12:21:57 PM
Re: Default Encryption
The reply provided by Microsoft is simply absurd. This is the wrong way to think security by design. Let's blame the others ... it's too easy!

 
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
5/20/2014 | 9:59:30 PM
Default Encryption
It seems that this is a gaping security flaw considering the ease of extraction for an SD card. Majority of users as posed in the article are default set to be unencrypted, so this hole will be available for many android based users. 

Is there any detriment to defaulting settings to encrypt instead of defaulting to unecrypted from a vendor perspective? Allow the user to make the choice but make them consciously choose to become vulnerable. This way the majority of unaware users will not be unknowlingly in danger.


COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
Exploiting Google Cloud Platform With Ease
Dark Reading Staff 8/6/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-16219
PUBLISHED: 2020-08-07
Delta Electronics TPEditor Versions 1.97 and prior. An out-of-bounds read may be exploited by processing specially crafted project files. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.
CVE-2020-16221
PUBLISHED: 2020-08-07
Delta Electronics TPEditor Versions 1.97 and prior. A stack-based buffer overflow may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.
CVE-2020-16223
PUBLISHED: 2020-08-07
Delta Electronics TPEditor Versions 1.97 and prior. A heap-based buffer overflow may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.
CVE-2020-16225
PUBLISHED: 2020-08-07
Delta Electronics TPEditor Versions 1.97 and prior. A write-what-where condition may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.
CVE-2020-16227
PUBLISHED: 2020-08-07
Delta Electronics TPEditor Versions 1.97 and prior. An improper input validation may be exploited by processing a specially crafted project file not validated when the data is entered by a user. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute a...