3 ms·
The article has a point but do know that Tutanota is using their own custom encryption scheme. I can understand they don't want to support PGP if they have some
by Leace 8y ago
The article has a point but do know that Tutanota is using their own custom encryption scheme. I can understand they don't want to support PGP if they have something better but judging from their FAQ [0] they just replicated what PGP already can do [1] [2] effectively reinventing square wheel.
As for browser encryption Mailvelope [3] works and can even use local GnuPG (through NativeMessaging). FlowCrypt [4] is a little bit more tightly integrated with Gmail (through their API).
[0]: https://tutanota.com/faq/#pgp https://tutanota.com/faq/#pgp
[1]: "That's why we have developed a solution that is also based on recognized algorithms (RSA and AES) and that automatically encrypts the subject, the content and the attachments."
[2]: https://github.com/autocrypt/memoryhole#memory-hole-protected-e-mail-headers https://github.com/autocrypt/memoryhole#memory-hole-protecte...
[3]: https://www.mailvelope.com/en https://www.mailvelope.com/en
[4]: https://flowcrypt.com/ https://flowcrypt.com/
- jrochkind1 8y agoHmm. Solutions like signal or whatsapp also used their "own custom encryption scheme" (in that sense), instead of PGP. I'm not sure PGP is actually good enough that alternatives aren't desirable. Here's a Wired article saying "PGP is dead... use Signal for your encrypted messaging instead": https://www.wired.co.uk/article/efail-pgp-vulnerability-outlook-thunderbird-smime https://www.wired.co.uk/article/efail-pgp-vulnerability-outl... Here's respected cryptographer Matthew Green saying PGP is "a model of email encryption that’s fundamentally broken" in 2014. https://blog.cryptographyengineering.com/2014/08/13/whats-matter-with-pgp/ https://blog.cryptographyengineering.com/2014/08/13/whats-ma... I think there was another more recent "what's the matter with PGP" post I saw on HN, I found these above while trying to see if I could remember what I saw more recently.
- Leace 8y ago> Solutions like signal or whatsapp also used their "own custom encryption scheme" (in that sense), instead of PGP. But Signal's "own custom encryption scheme" have obvious advantages over PGP, for example forward secrecy. That's what I meant by "I can understand (...) if they have something better". In Tutanota's case judging from their public descriptions the scheme doesn't have any advantages over PGP as it is currently used. Implementing custom crypto usually ends up with something like this: https://tutanota.uservoice.com/forums/237921-general/suggestions/7858974-tutanota-is-using-unauthenticated-aes-cbc-encrypti https://tutanota.uservoice.com/forums/237921-general/suggest...
- jrochkind1 8y agoIf you're providing an encryption service and not doing it well, that's certainly a problem. There are various levels of "custom". I'm not sure anything that isn't PGP is "implementing custom crypto" in the same way; you could be using a good crypto library like NaCL -- or not -- for instance. But you gotta know what you're doing. With so much critique of PGP though, I'm not sure "using PGP or not," or suggesting that using PGP is the obvious way to go, is the right line to be drawing. But yeah, that link you provide to an issue does not one make confident that tutanota has the proper staffing to do crypto right.