ON SECURITY By Susan Bradley If you are a consumer, home user, small-business user, or even a medium-sized business user, today’s column may anger you
[See the full post at: Zero day in the cloud]
Susan Bradley Patch Lady/Prudent patcher
![]() |
Patch reliability is unclear, but widespread attacks make patching prudent. Go ahead and patch, but watch out for potential problems. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
Home » Forums » Newsletter and Homepage topics » Zero day in the cloud
ON SECURITY By Susan Bradley If you are a consumer, home user, small-business user, or even a medium-sized business user, today’s column may anger you
[See the full post at: Zero day in the cloud]
Susan Bradley Patch Lady/Prudent patcher
Too often, the click-bait technology news headlines make it seem as if all of us will suffer from some patching side effect (“the sky is falling”), when in reality few are impacted.
We get that from some AskWoody members, as well.
Great article! In addition to the logging where you said, “I hope this will become available to all Microsoft customers — at no charge.”, this should also be said about email encryption.
I would dare to say the average email user has no idea if their email is encrypted or not. I asked Google about this and surprisingly Microsoft only offers encryption if you have the MS 365. Web outlook users are out of luck. Google also said Yahoo and Gmail do encrypt using TLS but that does not sound like end to end.
With all the endless hacking and financial losses occurring these days I would dare to say that MS and other email providers have an obligation, both financial and moral, to provide encryption automatically, by default, and without requiring technical knowledge by the consumer. I especially commend Apple for doing this very thing with its iMessage automatically on its phones (although I admit I was not aware of this for a long time and the difference between a text noted with a green or blue symbol – so Apple needs better communication about this feature).
Encryption code is already there. It does not cost MS or anyone to develop it. It just needs to be added to all existing email systems.
Why do we make it so easy for criminals and foreign governments to steal from us?
I would dare to say that MS and other email providers have an obligation, both financial and moral, to provide encryption automatically, by default,
What good is encrypted mail were anyone on the receiving end has the key to decrypt ?
Encrypted end-to-end iMessages work only for Apple devices (other platforms get unencrypted SMSs).
Android has had encrypted messages for more than two years:
published June 16, 2021
Android Messages gets an important update with end-to-end encryption
Android Messages finally supports end-to-end encryption — How to use it
I was told many years ago to treat email just like sending a post card through the USPS. Anyone who handles it can read it. The email may be passed through and stored on many servers on its way to the recipient. Anyone who has access to that server can read the email. Many people are surprised when I tell them this. Email is NOT secure or private. Thank you for this article to alert more people.
What good is encrypted mail were anyone on the receiving end has the key to decrypt ?
Encrypted end-to-end iMessages work only for Apple devices
That is the problem. There is no standard for exchanging encrypted emails so we have this hodgepodge of some encryption and some not.
At least with Apple the encryption function is preinstalled on my phone. When I compose a text if the font is blue then Apple is telling me the receiver is also on iMessage and the whole text is encrypted. If green the receiver is not Apple and it is not encrypted.
I am not a technical person, but here is the possibility I see. There are 3 dominant email providers – Microsoft, Yahoo, and Gmail. If I am sending an email to just about any company or individual they are most likely using one of these three providers and Windows or Chrome. So why cannot these 3 giants come up with a common encryption standard and have it preinstalled on whatever version email the client is using such that when one sends an email from a home PC using Windows and MS to a bank customer service agent using Chrome and Yahoo or whatever that also has that common encryption standard preinstalled then that email is encrypted all the way – sort of like an email VPN tunnel?
I know this would not be a complete solution but with the dominance of the big 3 it surely would plug a big hole in the swiss cheese and could be expanded to other less dominant email systems. This could also be employed between Apple and Android to fill the text gap.
Sound reasonable or should I go back to using certified mail (which on several occasions has just disappeared without trace!)
A new standard was published last week for messaging apps (not email):
An important step towards secure and interoperable messaging
July 19, 2023
Most modern consumer messaging platforms (including Google Messages) support end-to-end encryption, but users today are limited to communicating with contacts who use the same platform. This is why Google is strongly supportive of regulatory efforts that require interoperability for large end-to-end messaging platforms.
…
With the recent publication of the IETF’s Message Layer Security (MLS) specification RFC 9420, messaging users can look forward to this reality.
RCS chats are not that obvious to me
Google is trying to push Rich Communication Service (RCS) and continue to harass Apple for not joining.
Meanwhile the EU pushes for Digital Markets Act’s Interoperability Rule for all messaging apps.
Simple txt messages over G4 or G5 phone connections are safe enough for me.
Both 4G and 5G provide built-in encryption.
4G includes 128-bit encryption.
5G includes 256-bit encryption.
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.