Biz & IT —

Using IE with Hotmail’s photo uploads led to security flaw (Updated)

The Windows Live Hotmail team has indicated that it has disabled adding photos …

Windows Live Hotmail users that have recently been using the Web service may have noticed that it's no longer possible to add photos directly into the body of a Windows Live Hotmail message as easily as before. This issue wasn't apparent immediately because images can still be uploaded; the only difference is they appear as any other file would. This seems to occur in any browser, although when we started digging deeper into the issue, we found the following statement on the Windows Live Hotmail blog, which indicates that IE is the culprit:

During a recent review, we identified an incompatibility with Internet Explorer that caused a security flaw with photo uploads, and we made the decision to temporarily remove the feature. The Hotmail team takes security very seriously and we expect to bring back the photo upload feature by the end of September. In the meantime, you can still add pictures as attachments to your Hotmail messages, by clicking Attach, and then File, and then selecting the picture you want to include.

It's not known how severe the flaw is, but it's severe enough for Microsoft to disable the photo upload tool on all browsers. We will keep you posted as this story develops.

Update

"The photo upload tool is only being disabled for a short-term basis in order to fix the issue," a Microsoft spokesperson confirmed with Ars. "Hotmail customers can still add pictures as attachments in the interim. A fix is expected to be in place by late September. We will be sure to keep you posted when we have more to share."

Channel Ars Technica