Dan Griffin's Blog
Comments on security, PKI, smart cards, cryptography, and entrepreneurship.
Misleading Outlook Web Access private computer option
October 17, 2007
Ever used Outlook Web Access? There’s a Security radio button control at the bottom of the logon screen that provides two options: “Public or shared computer” which is selected by default, and “Private computer.”
Permalink |
Selecting the latter brings up some red bold text warning you, basically, that you better be sure that your client computer is secure from your employer’s perspective. But that is so misleading. I mean, suppose I leave the “Public …” one selected and just login to my email that way. Since I don’t get the security warning, does that mean it doesn’t matter if my client machine is running spyware? Or that it’s got a key logger?
Don’t be fooled – if you login to OWA from a public computer or kiosk, assume that your password is compromised (by a key logger) and that some hacker is reading your email (via spyware or an ActiveX control). The “Public or shared computer” setting doesn’t protect you!
No Comments »
No comments yet.
RSS feed for comments on this post. TrackBack URL