Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


September 29, 2006

Outlook 2007 Security and Privacy

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

As I discussed in my column last month ("Outlook 2007: HTML Forms Are 'Out;' CSS Is 'In,'" http://www.windowsitpro.com/Articles/ArticleID/93346/93346.html), one significant change in Microsoft Office Outlook 2007 is that scripts in HTML-formatted messages can't run at all. That's just one of many improvements in Outlook 2007 to make it more secure. With a more stable 2007 Microsoft Office system Beta 2 Technical Refresh (B2TR) now available, I thought this would be a good time to review Outlook 2007's security and privacy improvements.

Let's start with programmatic access and those intrusive security prompts that users see when external applications try to automate Outlook. By default, those won't appear in Outlook 2007 if the user is running an up-to-date antivirus application on Windows Vista or Windows XP. That's a big gain for corporations with older, inhouse applications that would be expensive to rewrite to use Outlook automation techniques that avoid security prompts. Furthermore, the programmatic access settings that formerly worked only in the Outlook Security Settings public folder can be managed in Outlook 2007 through a Group Policy Object (GPO), so they can apply even in organizations that don't use Exchange Server for mail.

Another security setting that might affect existing custom applications is that Outlook 2007, by default, doesn't display folder home pages for folders other than the user's default information store and the Public Folders hierarchy. A folder home page is a Web page associated with a folder. Like any Web page, it can run code, but because it's running inside Outlook, it isn't blocked from performing Outlook automation as an external Web site page opened in Microsoft Internet Explorer would be. If a folder home page in another folder is essential to an organization, an administrator can change this behavior by using a GPO. After adding the Outlk12.adm administrative template (see URL below for the template download), go to User Configuration, Administrative Templates, Microsoft Office Outlook 2007, Tools | Options..., Other, Advanced and look for a setting named Do not allow folders in non-default stores to be set as folder home pages.

Outlook 2007 includes improved protection against spam and phishing, plus a more prominent warning on suspected phishing messages. Recognizing that users often need to send legitimate messages that might look like spam to some email clients, Microsoft has added a new Email Postmark feature to Outlook. When the user sends a message with spamlike characteristics, Outlook solves a computationally costly puzzle, hashes the solution, and puts information about the puzzle and solution into two fields in the message's SMTP header. The recipient of the message sees nothing special about the message, but if the receiving mail client is Outlook 2007, it can use the contents of those fields to determine that the message is valid and not junk. The sender won't notice the slight delay on an individual message, but Microsoft contends that the computational cost of the Email Postmark feature makes it impractical for spammers to take advantage of it.

Outlook 2007 plugs a number of potential privacy leaks that were present in earlier versions. Like Outlook 2003, the new version blocks images and other external content in HTML messages that could be used with so-called Web bugs to reveal information about the user. But it expands this feature to give the user a new option to block external content not just on reading a message but also during reply, forward, and print operations.

In earlier versions, a user could add a vCard .vcf file to any Outlook email signature, but it was all too easy for Exchange users to unwittingly include in that vCard personal information stored in the Global Address List (GAL). Outlook 2007 eliminates that possibility. The only type of vCard .vcf file that can be included with a signature is one created with the new Electronic Business Card feature. To create an Electronic Business Card, the user must specify exactly what information to include. Therefore, there's no risk of information leaking out from the GAL.

Another area where privacy is tightened is around free/busy information. This might be the ultimate feature for secretive bosses! In earlier versions of Outlook, users either saw free/busy information for other users or, if they had Reviewer access to other users' Calendar folders, the details of appointments in the other users' calendars. The only way to block a person from seeing any free/busy information for a user was to stop publishing free/busy information for that user completely. When used with Exchange 2007, Outlook 2007 expands the free/busy permission options to offer new options for "None" and "Free/Busy time, subject, and location." Thus, the secretive boss could set four different levels of free/busy access for four different sets of people in the organization: no access as the default; full details (i.e., Reviewer access) for the boss's assistant; for peers, free/busy time, subject, and location; and for direct reports, free/busy time only.

A good way to get to know some of the new settings in Outlook 2007 is to download the administrative template .adm files for B2TR and add them to Group Policy Editor (GPE) so that you can then browse through the available options. One welcome change in the Outlk12.adm file is the addition of explanatory text for most policy settings.

Administrators have long asked for an option to completely disable the Outlook reading pane (even though it hasn't been a source of vulnerability for years). Outlook 2007 has this option, although it's a little hard to find in GPE. After you add the Outlk12.adm administrative template, look under User Configuration, Administrative Templates, Microsoft Office Outlook 2007, Tools | Options..., Other for an option named Do not display the reading pane.

One final security note: What about the Vector Markup Language vulnerability reported last week by Sunbelt Software (see http://www.windowsitpro.com/Article/ArticleID/93584/93584.html)? According to Sunbelt, Outlook 2007 B2TR is not vulnerable to this exploit.

Office 2007 Beta 2
http://www.microsoft.com/office/preview/

2007 Microsoft Office system Beta 2 Technical Refresh
http://www.microsoft.com/downloads/details.aspx?FamilyID=b07a3387-01cf-4bc3-821a-0bb10e7a59fa

2007 Office System Beta 2 Technical Refresh Administrative Templates (ADM)
http://www.microsoft.com/downloads/details.aspx?FamilyID=92d8519a-e143-4aee-8f7a-e4bbaeba13e7

End of Article



Reader Comments
no

t_thanawan@hotmail.com March 19, 2007 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

Escape From Yesterworld

Kevin points you to the funniest SQL Server website ever! ...

The Desktop tab is missing from the Display Properties in Windows XP?

...


Related Articles Outlook Tips & Techniques

Outlook 2007 vs. Outlook 2003

Security Whitepapers Anti-Virus Is Dead: The Advent of the Graylist Approach to Computer Protection

Getting the Job Done: Comparing Approaches for Desktop Software Lockdown

Instant Messaging, VoIP, P2P, and games in the workplace: How to take back control

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

WinConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

Maximize your SharePoint Investment – 8 Cities
Discover best practices and tips for both architecting and administering SharePoint. Early Bird Price of $99 through Sept 15th.

Find a new job now on the all new IT Job Hound!
Search jobs, post your resume, and set up job e-mail alerts!

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Top Tools for Virtualization Disaster Recovery & Replication
View this web seminar on August 14th to learn about two tools that will result in faster backup and restore with P2V disaster recovery.

SharePointConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

VMworld 2008 - Sign Up Today!
Join your peers on September 15-18 at The Venetian Hotel in Las Vegas as VMware hosts VMworld 2008, the leading Virtualization event.



When managing just VMware isn’t enough
Plan/Manage/Secure – NetIQ VMware management. Download whitepaper.

What’s up with your network? Find out with ipMonitor
Availability monitoring for servers, applications and networks – FREE trial

Microsoft® Tech•Ed EMEA 2008 IT Professionals
Advance your thinking with new ideas and practical real-world solutions at Microsoft’s FIVE day technical infrastructure conference 3-7 Nov., 2008. Register before 26 September 2008 to save €300.

Order Your Fundamentals CD Today!
Gain an introduction to Exchange, learn server security requirements, and understand how unified communications can play a role in your messaging strategies with this free Exchange CD.

Are You Really Compliant with Software Regulations?
View this web seminar that will help you with compliance best practices and check out a management solution to assure that you won’t be in jeopardy of an audit.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16 in London.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing