Home Security Researchers Say Microsoft Workplace 365 Makes use of Damaged Electronic mail Encryption to Safe Messages

Researchers Say Microsoft Workplace 365 Makes use of Damaged Electronic mail Encryption to Safe Messages

by crpt os


New research has disclosed what’s being called a security vulnerability in Microsoft 365 that could be exploited to infer message contents due to the use of a broken cryptographic algorithm.

“The [Office 365 Message Encryption] messages are encrypted in insecure Electronic Codebook (ECB) mode of operation,” Finnish cybersecurity company WithSecure said in a report published last week.

Office 365 Message Encryption (OME) is a security mechanism used to send and receive encrypted email messages between users inside and outside an organization without revealing anything about the communications themselves.

CyberSecurity

A consequence of the newly disclosed issue is that rogue third-parties gaining access to the encrypted email messages may be able to decipher the messages, effectively breaking confidentiality protections.

Electronic Codebook is one of the simplest modes of encryption wherein each message block is encoded separately by a key, meaning identical plaintext blocks will be transposed into identical ciphertext blocks, making it unsuitable as a cryptographic protocol.

Indeed, the U.S. National Institute of Standards and Technology (NIST) pointed out earlier this year that “ECB mode encrypts plaintext blocks independently, without randomization; therefore, the inspection of any two ciphertext blocks reveals whether or not the corresponding plaintext blocks are equal.”

That said, the shortcoming identified by WithSecure doesn’t relate to the decryption of a single message per se, but rather banks on analyzing a stash of encrypted stolen mails for such leaky patterns and subsequently decoding the contents.

“An attacker with a large database of messages may infer their content (or parts of it) by analyzing relative locations of repeated sections of the intercepted messages,” the company said.

The findings add to growing concerns that encrypted information previously exfiltrated may be decrypted and exploited for attacks in the future, a threat called “hack now, decrypt later,” fueling the need to switch to quantum-resistant algorithms.

CyberSecurity

Microsoft, for its part, considers OME as a legacy system, with the company recommending customers to use a data governance platform called Purview to secure emails and documents via encryption and access controls.

“Even though both versions can coexist, we highly recommend that you edit your old mail flow rules that use the rule action Apply the previous version of OME to use Microsoft Purview Message Encryption,” Redmond notes in its documentation.

“Since Microsoft has no plans to fix this vulnerability the only mitigation is to avoid using Microsoft Office 365 Message Encryption,” WithSecure said.





Source link

Related Articles

xxxanti beeztube.mobi hot sexy mp4 menyoujan hentaitgp.net jason voorhees hentai indian soft core chupatube.net youjzz ez2 may 8 2023 pinoycinema.org ahensya ng pamahalaan pakistani chut ki chudai pimpmovs.com www xvedio dost ke papa zztube.mobi 300mbfilms.in صور مص الزب arabporna.net نهر العطش لمن تشعر بالحرمان movierulz plz.in bustyporntube.info how to make rangoli video 穂高ゆうき simozo.net 四十路五十路 ロシアav javvideos.net 君島みお 無修正 افلام سكس في المطبخ annarivas.net فيلم سكس قديم rashmi hot videos porncorn.info audiosexstories b grade latest nesaporn.pro high school girls sex videos real life cam eroebony.info painfull porn exbii adult pics teacherporntrends.com nepali school sex