In this scenario, if Office Outlook 2007 first checks non-SSL locations or allows failover to a non-SSL location, and a user types an e-mail address and password in a vulnerable security situation such as a main-in-the-middle attack, the automatic configuration service in Office Outlook 2007 could weaken security by being the weakest link in the connection chain if a non-SSL connection is allowed.