Forum Discussion

5 Replies

  • Hello, I have not seen an official announcement, but AIP is not affected by efail.  Efail is a S/MIME/PGP vulnerability has nothing to do with AIP.  AIP encrypts at the document level using Rights Management.

     

     

    EDIT:Typo

    • Frederik Lentjes's avatar
      Frederik Lentjes
      Copper Contributor

      Thanks for your answer.

       

      Just to be sure that we are talking about the same things.

       

      I am just searching for a confirmation that Office 365 Message Encryption (part of AIP) is not affected by efail. In my opinion it is just not affected because it is not based on S/MIME or openPGP.

       

      Am i right?

      • Losercore's avatar
        Losercore
        Icon for Microsoft rankMicrosoft

        Sorry for the delay. Our terminology makes this confusing.  Office 365 Message Encryption (OME) uses RMS.  S/MIME is another way of encrypting messages in Exchange Online using certificates and creates digital signatures.  The vulnerability described does not apply to RMS (AIP) thus, it does not apply to OME.

         

        I hope that helps.

         

        Thanks