Forum Discussion
safvan am
Aug 21, 2018Copper Contributor
Outlook e-mail encryption "security": 3DES and SHA1.
Does anyone know why these very outdated security algorithms are the only available ones in Outlook 365? This does not really seem that secure to me, considering both algorithms are very old and considered weak or patchy at best by now.
And RC2 should flat out be removed, it's from 1987!
It's worse than plain text because it makes people may think their messages are secure, but they aren't.
- Deleted
Seems to have changed since a recent update? I was able to use SHA2 (and 3) and AES for a very long time. Since today, they are gone and only older protocols are supported.
- Cipher support depends on the operating system used and which is agreed upon by both ends. My current connection uses TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384. Support for older versions of TLS (<1.2) will be dropped in October - see https://support.microsoft.com/en-us/help/4057306/preparing-for-tls-1-2-in-office-365
- safvan amCopper Contributor
- Chris_Aguilera
Microsoft
Are you using a moder Outlook version? Outlook 2013/2016 and for O365 supports AES 256.