Security hole in the encryption of Outlook 2002 (update)
Summary
In January 2003 Outlook 2002 sent emails unencrypted even though users had chosen encryption with a V1 Exchange Server Security certificate. The bug only affected HTML messages and only this method; PGP and S/MIME were not affected. Microsoft provided a patch, initially only in English and a few days later in German as well.
Ideas
- A supposedly encrypted email went out in plain text.
- The user did not notice that the encryption was missing.
- The bug depended on the combination of certificate type and HTML format.
Insights
- Silent failures in encryption are more dangerous than visible error messages.
- Standard methods such as S/MIME are more robust than vendor-specific special paths.
Facts
- The German patch followed a few days after the English one.
References
Critique
- The report does not say how long the bug had existed and how many emails were affected.
Recommendations
- Spot-check encrypted emails in raw format at the recipient’s end.
- Rely on established standards such as S/MIME or OpenPGP instead of proprietary methods.
Links to the original source and the Web Archive open in a new tab.