# O365 "secure" email

**URL:** <https://forums.suse.com/t/o365-secure-email/33810>\
**Category:** Chatting over the Back Fence\
**Created:** [April 11, 2019, 8:11pm UTC](https://forums.suse.com/t/o365-secure-email/33810 "2019-04-11T20:11:05Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![AndersG](https://avatars.discourse-cdn.com/v4/letter/a/54ee81/32.png) [@AndersG](https://forums.suse.com/u/AndersG)\
**Post date:** [April 11, 2019, 8:11pm UTC](https://forums.suse.com/t/o365-secure-email/33810/1 "2019-04-11T20:11:05Z")

</div>



---

<div class="post-metadata">

**Author:** ![AndersG](https://avatars.discourse-cdn.com/v4/letter/a/54ee81/32.png) [@AndersG](https://forums.suse.com/u/AndersG)\
**Post date:** [April 11, 2019, 8:11pm UTC](https://forums.suse.com/t/o365-secure-email/33810/2 "2019-04-11T20:11:05Z")

</div>

Seriusly… What is the point? We have had TLS for SMTP \> 10 years so  
email between responsible parties is encrypted in transit.

All this adds is an extra level of hassle and no benefit?

–  
Anders Gustafsson (NKP)  
The Aaland Islands (N60 E20)

Have an idea for a product enhancement? Please visit:  
[https://www.novell.com/products/enhancement-request.html](https://www.novell.com/products/enhancement-request.html)

---

<div class="post-metadata">

**Author:** ![ketter](https://avatars.discourse-cdn.com/v4/letter/k/2bfe46/32.png) [@ketter](https://forums.suse.com/u/ketter)\
**Post date:** [April 11, 2019, 11:16pm UTC](https://forums.suse.com/t/o365-secure-email/33810/3 "2019-04-11T23:16:08Z")

</div>

On Thu, 11 Apr 2019 17:11:05 GMT, Anders Gustafsson  
[andersg@no-mx.forums.microfocus.com](mailto:andersg@no-mx.forums.microfocus.com) wrote:  
[color=blue]

> Seriusly… What is the point? We have had TLS for SMTP \> 10 years so  
> email between responsible parties is encrypted in transit.
> 
> All this adds is an extra level of hassle and no benefit?[/color]

What are you referring to?

–  
Ken  
Knowledge Partner

Create and vote for enhancements!  
[https://www.microfocus.com/products/enhancement-request.html](https://www.microfocus.com/products/enhancement-request.html)

---

<div class="post-metadata">

**Author:** ![AndersG](https://avatars.discourse-cdn.com/v4/letter/a/54ee81/32.png) [@AndersG](https://forums.suse.com/u/AndersG)\
**Post date:** [April 12, 2019, 11:18am UTC](https://forums.suse.com/t/o365-secure-email/33810/4 "2019-04-12T11:18:08Z")

</div>

KeN Etter,[color=blue]

> What are you referring to?[/color]

When people send an “encrypted” email from O365 you get a link to  
login. There you can log in with O365 credentials or via an one-time  
password mailed to your mailaddress. What extra protection does that  
give?

–  
Anders Gustafsson (NKP)  
The Aaland Islands (N60 E20)

Have an idea for a product enhancement? Please visit:  
[https://www.novell.com/products/enhancement-request.html](https://www.novell.com/products/enhancement-request.html)

---

<div class="post-metadata">

**Author:** ![mrosen](https://avatars.discourse-cdn.com/v4/letter/m/4bbf92/32.png) [@mrosen](https://forums.suse.com/u/mrosen)\
**Post date:** [April 12, 2019, 11:51am UTC](https://forums.suse.com/t/o365-secure-email/33810/5 "2019-04-12T11:51:58Z")

</div>

On 12.04.2019 10:18, Anders Gustafsson wrote:[color=blue]

> KeN Etter,[color=green]
> 
> > What are you referring to?[/color]
> 
> When people send an “encrypted” email from O365 you get a link to  
> login. There you can log in with O365 credentials or via an one-time  
> password mailed to your mailaddress. What extra protection does that  
> give?  
> [/color]  
> LOL

–  
Massimo Rosen  
Micro Focus Knowledge Partner  
No emails please!  
[http://www.cfc-it.de](http://www.cfc-it.de)

---

<div class="post-metadata">

**Author:** ![ScorpionSting](https://avatars.discourse-cdn.com/v4/letter/s/ba9def/32.png) [@ScorpionSting](https://forums.suse.com/u/ScorpionSting)\
**Post date:** [April 12, 2019, 12:34pm UTC](https://forums.suse.com/t/o365-secure-email/33810/6 "2019-04-12T12:34:01Z")

</div>

AndersG;2498252 Wrote:[color=blue]

> KeN Etter,[color=green]
> 
> > What are you referring to?[/color]
> 
> When people send an “encrypted” email from O365 you get a link to  
> login. There you can log in with O365 credentials or via an one-time  
> password mailed to your mailaddress. What extra protection does that  
> give?
> 
> –  
> Anders Gustafsson (NKP)  
> The Aaland Islands (N60 E20)
> 
> Have an idea for a product enhancement? Please visit:  
> [https://www.novell.com/products/enhancement-request.html](https://www.novell.com/products/enhancement-request.html)[/color]

The recipient has to be really really keen to read your email…that’s  
the protection 😃

## – Visit my ‘Website’ ([https://www.isag.melbourne/](https://www.isag.melbourne/)) for links to Cool Solution articles.

ScorpionSting’s Profile: [https://forums.novell.com/member.php?userid=1663](https://forums.novell.com/member.php?userid=1663)  
View this thread: [https://forums.novell.com/showthread.php?t=511938](https://forums.novell.com/showthread.php?t=511938)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)\
**Post date:** [April 12, 2019, 12:53pm UTC](https://forums.suse.com/t/o365-secure-email/33810/7 "2019-04-12T12:53:31Z")

</div>

On 11/04/2019 18:11, Anders Gustafsson wrote:[color=blue]

> Seriusly… What is the point? We have had TLS for SMTP \> 10 years so  
> email between responsible parties is encrypted in transit.
> 
> All this adds is an extra level of hassle and no benefit?[/color]

it’s an oracle based encryption system meant to compete with cisco’s  
CRES offering (and pgp universal gateway, zixmail and similar) which  
traditionally can be used with on-premise exchange, but obviously not o365.

TLS for SMTP can be trivially broken in MITM attacks by hiding the  
“STARTTLS” offer during ehlo. Cisco routers certainly used to do that  
by default (INSPECT ESMTP) which is irritating. Almost no SMTP senders  
insist on TLS.

---

<div class="post-metadata">

**Author:** ![AndersG](https://avatars.discourse-cdn.com/v4/letter/a/54ee81/32.png) [@AndersG](https://forums.suse.com/u/AndersG)\
**Post date:** [April 12, 2019, 2:50pm UTC](https://forums.suse.com/t/o365-secure-email/33810/8 "2019-04-12T14:50:45Z")

</div>

ScorpionSting,[color=blue]

> The recipient has to be really really keen to read your email…that’s  
> the protection :D[/color]

So true 🙂

–  
Anders Gustafsson (NKP)  
The Aaland Islands (N60 E20)

Have an idea for a product enhancement? Please visit:  
[https://www.novell.com/products/enhancement-request.html](https://www.novell.com/products/enhancement-request.html)

---

<div class="post-metadata">

**Author:** ![AndersG](https://avatars.discourse-cdn.com/v4/letter/a/54ee81/32.png) [@AndersG](https://forums.suse.com/u/AndersG)\
**Post date:** [April 12, 2019, 2:50pm UTC](https://forums.suse.com/t/o365-secure-email/33810/9 "2019-04-12T14:50:45Z")

</div>

Dave Howe,[color=blue]

> TLS for SMTP can be trivially broken in MITM attacks by hiding the  
> “STARTTLS” offer during ehlo.[/color]

That is true, but what additional protection does the O365-way give?  
None IMHO.

–  
Anders Gustafsson (NKP)  
The Aaland Islands (N60 E20)

Have an idea for a product enhancement? Please visit:  
[https://www.novell.com/products/enhancement-request.html](https://www.novell.com/products/enhancement-request.html)

---

<div class="post-metadata">

**Author:** ![ketter](https://avatars.discourse-cdn.com/v4/letter/k/2bfe46/32.png) [@ketter](https://forums.suse.com/u/ketter)\
**Post date:** [April 12, 2019, 5:31pm UTC](https://forums.suse.com/t/o365-secure-email/33810/10 "2019-04-12T17:31:22Z")

</div>

On Fri, 12 Apr 2019 08:18:08 GMT, Anders Gustafsson  
[andersg@no-mx.forums.microfocus.com](mailto:andersg@no-mx.forums.microfocus.com) wrote:  
[color=blue]

> KeN Etter,[color=green]
> 
> > What are you referring to?[/color]
> 
> When people send an “encrypted” email from O365 you get a link to  
> login. There you can log in with O365 credentials or via an one-time  
> password mailed to your mailaddress. What extra protection does that  
> give?[/color]

🙂

–  
Ken  
Knowledge Partner

Create and vote for enhancements!  
[https://www.microfocus.com/products/enhancement-request.html](https://www.microfocus.com/products/enhancement-request.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)\
**Post date:** [April 18, 2019, 4:04pm UTC](https://forums.suse.com/t/o365-secure-email/33810/11 "2019-04-18T16:04:17Z")

</div>

On 12/04/2019 12:50, Anders Gustafsson wrote:[color=blue]

> Dave Howe,[color=green]
> 
> > TLS for SMTP can be trivially broken in MITM attacks by hiding the  
> > “STARTTLS” offer during ehlo.[/color]
> 
> That is true, but what additional protection does the O365-way give?  
> None IMHO.[/color]

a little, but very little. The same is true of the other offerings I  
mentioned though; MS is offering this to compete in a market, and is not  
noticeably worse than most (although I note pgp universal _will_ allow  
you to log onto it and upload your pgp key, so future emails are  
conventionally encrypted with pgp, rather than using their “oracle” system.)
