Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • News
  • How-to
  • Feature stories
  • Deals
  • Microsoft / office 365
  • Reviews
Menu
  • Home
  • About
  • Contact
  • News
  • How-to
  • Feature stories
  • Deals
  • Microsoft / office 365
  • Reviews
  1. Home
  2. News
  3. Outlook.com App For Android Reportedly Exposes User Data, Microsoft Responds – onmsft.com

Outlook.com App For Android Reportedly Exposes User Data, Microsoft Responds – onmsft.com

Ron Ron
May 27, 2014
3 min read

Outlook.com app for Android reportedly exposes user data, Microsoft responds

Apparently, Microsoft’s Outlook.com app for Android exposes user data by giving the impression that it encrypts email when it actually doesn’t do that. Security firm Include Security is reporting that the Outlook.com Android app provides weak security when it comes to protecting user data.

“The app allows users to access their Outlook.com email on Android devices. In the course of our research we found that the on-device email storage doesn’t really make any effort to ensure confidentiality of messages and attachments within the phone file system itself. After notifying Microsoft (vendor notification timeline is found at the end of this post) they disagreed that our concern was a direct responsibility of their software, in light of similar problems with iOS being deemed a concern by privacy advocates we thought it’d be a good idea to share what we see with the Outlook.com app,” Include Security reports.

Include Security has identified two key areas of concern. First, email attachments are stored in a file system area that is accessible to any app or 3rd parties who have physical access to your phone. Second, the email themselves are stores on the file system, while the “Pincode” feature of the Outlook.com app only applies to the UI of the app. The “Pincode” feature does nothing in protecting the confidentiality of email messages on the file system. This gives off the false sense that your email messages are protected, when in fact, they are not.

As you can see from the image below, when setting up a “Pincode,” you are told to add a secure password in order to “protect your email.”

Outlook.com app for Android reportedly exposes user data, Microsoft responds

“Outlook.com provides a Pincode feature. When activated, users have to enter a code in order to interact with the application (launch it, resume it, etc). This feature is not enabled by default in the application: the user must manually enable this feature. We’ve found that the Pincode feature does not encrypt the underlying data, it only protects the Graphical User Interface, and we feel this is a behavior users should be aware of,” Inside Security adds.

Inside Security recommends that you disable USB debugging (Settings > Developer Options > USB Debugging) on Android, effectively preventing 3rd parties from getting access to any data in plain-text, from a messaging app or other apps that may choose to store private data on the SDCard. It is also being recommended to change the email attachments download directory (Settings > General > Attachments Settings > Attachment Folder) to something other than the removable SD card.

Microsoft was made aware of this issue and had the following to say: “Microsoft is committed to protecting the security of your personal information. We use a variety of security technologies and procedures to help protect your personal information from unauthorized access, use, or disclosure. For people using the Outlook.com app for Android, applications run in sandboxes where the operating system protects customers’ data. Additionally, customers who wish to encrypt their email can go through their phone settings and encrypt the SD card data. Please see Microsoft’s online privacy policy for more information,” a Microsoft spokesperson stated.

Share This Post:

Share this article:
Tags:
Android Microsoft Outlook Security
Previous Article Nokia Lumia 635 Headed To Telus And Rogers In Canada – onmsft.com Next Article Polish Carrier Plus Is Giving Away Windows Phone Themed Shoes To Its Subscribers – onmsft.com

Related Articles

Chrome tests Google Drive file uploads in the AI Mode compose box

April 14, 2026
Gemini image creation using right click desktop Chrome

Chrome lets you remake images with Gemini on desktop using just a right-click

April 13, 2026
Samsung Display crosses 5 million QD-OLED monitor shipments as demand grows fast, with new panels and strong premium market expansion worldwide.

Samsung Display Ships 5 Million QD-OLED Monitor Panels in Four Years

April 9, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Chrome tests Google Drive file uploads in the AI Mode compose box
  • Chrome lets you remake images with Gemini on desktop using just a right-click
  • Samsung Display Ships 5 Million QD-OLED Monitor Panels in Four Years
  • Intel Arc Pro B70 Teardown Reveals Blower Cooler and Early Board Design Details
  • Users Modify RTX 5090 Lightning Z Hardware to Unlock MSI’s Restricted 2500W BIOS

Recent Comments

  1. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  2. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Chrome tests Google Drive file uploads in the AI Mode compose box
  • Chrome lets you remake images with Gemini on desktop using just a right-click
  • Samsung Display Ships 5 Million QD-OLED Monitor Panels in Four Years
  • Intel Arc Pro B70 Teardown Reveals Blower Cooler and Early Board Design Details
  • Users Modify RTX 5090 Lightning Z Hardware to Unlock MSI’s Restricted 2500W BIOS

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy