bk99.de entertain the web since 1997

Security hole in the encryption of Outlook 2002 (update)

Summary

In January 2003 Outlook 2002 sent emails unencrypted even though users had chosen encryption with a V1 Exchange Server Security certificate. The bug only affected HTML messages and only this method; PGP and S/MIME were not affected. Microsoft provided a patch, initially only in English and a few days later in German as well.

Ideas

  • A supposedly encrypted email went out in plain text.
  • The user did not notice that the encryption was missing.
  • The bug depended on the combination of certificate type and HTML format.

Insights

  • Silent failures in encryption are more dangerous than visible error messages.
  • Standard methods such as S/MIME are more robust than vendor-specific special paths.

Facts

  • The German patch followed a few days after the English one.

References

Critique

  • The report does not say how long the bug had existed and how many emails were affected.

Recommendations

  • Spot-check encrypted emails in raw format at the recipient’s end.
  • Rely on established standards such as S/MIME or OpenPGP instead of proprietary methods.

Read the original article

Search the Web Archive