3 ms·
> Solutions like signal or whatsapp also used their "own custom encryption scheme" (in that sense), instead of PGP. But Signal's "own custom encryption scheme"
by Leace 8y ago
> Solutions like signal or whatsapp also used their "own custom encryption scheme" (in that sense), instead of PGP.
But Signal's "own custom encryption scheme" have obvious advantages over PGP, for example forward secrecy. That's what I meant by "I can understand (...) if they have something better".
In Tutanota's case judging from their public descriptions the scheme doesn't have any advantages over PGP as it is currently used.
Implementing custom crypto usually ends up with something like this: https://tutanota.uservoice.com/forums/237921-general/suggestions/7858974-tutanota-is-using-unauthenticated-aes-cbc-encrypti https://tutanota.uservoice.com/forums/237921-general/suggest...
- jrochkind1 8y agoIf you're providing an encryption service and not doing it well, that's certainly a problem. There are various levels of "custom". I'm not sure anything that isn't PGP is "implementing custom crypto" in the same way; you could be using a good crypto library like NaCL -- or not -- for instance. But you gotta know what you're doing. With so much critique of PGP though, I'm not sure "using PGP or not," or suggesting that using PGP is the obvious way to go, is the right line to be drawing. But yeah, that link you provide to an issue does not one make confident that tutanota has the proper staffing to do crypto right.