New Outlook from Microsoft apparently passes on access data

November 10, 2023, 1:53 p.m. |
Reading time: 3 minutes

After the Windows 11 update there is the new version of Outlook. The mail client was also sometimes recommended to Windows users. But now it is said that all data is delivered to Microsoft servers.

The new Outlook version is intended to replace the Windows mail application and the old Outlook in the near future. You can download the application now. Either you search in the Microsoft Store or the app is recommended to users via “Start”. However, questions arise about security, because not only emails but also access data are reportedly leaked to Microsoft.

Outlook probably sends sensitive data to Microsoft

Not every innovation has to be positive. This could apply to the new Outlook version. In a report by Heise Online it means that Outlook would not only send emails, but also various access data to Microsoft. Accordingly, IMAP and SMTP data also end up with the company.

IMAP stands for “Internet Message Access Protocol” and ensures access to emails. It also synchronizes emails between server and mail program. SMTP stands for “Simple Mail Transfer Protocol” and is used to send email. When switching to the new Outlook, the IMAP and SMTP access data should be transmitted to Microsoft. TECHBOOK tested this and added a GMX email address (IMAP account) to Outlook – i.e. an email address that does not belong to Microsoft. Then there was a note:

Outlook IMAP

After you add a mail account to Outlook that is not from Microsoft, a message appears. The account will then be synchronized. Photo: TECHBOOK.de

Accordingly, contacts and events from the IMAP account (here GMX) are not synchronized with Microsoft, but emails are. Even in one Support report Microsoft says that Gmail, Yahoo, iCloud and IMAP accounts will be connected to Microsoft in Outlook. Heise Online also found that when the account was created, the target server, login name and password were transmitted to Microsoft servers via a TLS tunnel in plain text, i.e. visible.

Also read: This is what happened to the Hotmail email service

Federal authorities get involved

After the incident, even the federal authority, more precisely the Federal Commissioner for Data Protection and Freedom of Information (BfDI), got involved via Mastodon and wrote on the official one Mastodon server from the BfDI “social.bund.de” the following: “The reports about suspected data collection by MS via Outlook are alarming. “We will be asking the Irish data protection supervisors who are legally responsible for a report at the meeting of the European data protection supervisory authorities on Tuesday.”

Users give bad reviews

In the Microsoft Store, the new Outlook is touted as a “first-class email experience.” But if you look at the reviews of the new Outlook, it quickly becomes clear that users are not particularly satisfied. Users only gave it 2.9 out of 5 stars. It should also be mentioned that the new application only has over 600 reviews. However, it is a bad sign in advance if the reviews are bad at the start of the new Outlook.

New Outlook Windows

The new Outlook from Windows is available for download. However, the ratings are poor at 2.9. Photo: TECHBOOK.de

TECHBOOK has contacted Microsoft and will update this article as soon as the company responds.

ttn-35