A few day ago I wrote about serious security issues for day ago I wrote about serious security issues for Microsoft mobile Outlook app, the researcher and Head of Development at midpoints GmbH and IBM Champion René Winkelmeyer published a blog post to warn about security issues in the newborn iOS Outlook app. According to the expert, the iOS Microsoft mobile Outlook app recently presented by the company, allows the it to access corporate emails and server credentials without user’s knowledge.
For this reason, the EU Parliament has blocked politicians from using the Microsoft mobile Outlook app in the wake of security and privacy concerns. The EU Parliament fears that members’ credentials could be exposed to a third party.
The DG ITEC, which is the IT department of the Parliament, has requested to the members of the EU Parliament to avoid the use of the application.
“Please do not install this application, and in case you have already done so for your EP corporate mail, please uninstall it immediately and change your password,” requested the DG ITEC,.
The experts at DG ITEC also invited the staff to remove the app if installed and to reset corporate email passwords if it was used.
Let’s close the post highlighting a significant excerpt from the policy implemented by the software.
“… our service retrieves your incoming and outgoing email messages and securely pushes them to the app on your device [and] may be temporarily stored and indexed securely both in our servers and locally on the app on your deviceIf your emails have attachments and you request to open them in our app, the service retrieves them from the mail server, securely stores them temporarily on our servers, and delivers them to the app.”
(Security Affairs – EU Parliament, Microsoft mobile Outlook app)
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.