• Experts warn emails sent with sensitive data are still getting delivered unencrypted, and no one gets notified
  • Microsoft 365 sends email in plain text when encryption fails, without alerting the user at all
  • Google Workspace still uses insecure TLS 1.0 and 1.1 without warning senders or rejecting messages

Most users assume that emails sent through cloud services are encrypted and secure by default, but this might not always be the case, new research has claimed.

A report from Paubox found Microsoft 365 and Google Workspace both mishandle these failures in ways that leave messages exposed, without notifying the sender or logging the failure.



Source link

Podcast also available on PocketCasts, SoundCloud, Spotify, Google Podcasts, Apple Podcasts, and RSS.