10 ms·
German court forces mail provider Tutanota to insert a backdoor
- giancarlostoro 6y agoEncryption is the only thing that forces law enforcement to use warrants, without it it's just a wild wild west of privacy abuse. I do hope we see more services crop up, and new methods for people to encrypt email outside of specific services, maybe better plugins for Thunderbird or something, hell I'd easily pay for such a plugin if someone else can communicate back and forth with me through it and it is encrypted. Maybe even some sort of forward secrecy involved in the system.
- deleted 6y ago[deleted]
- throwaway2245 6y agoWe generally accept that warrants are a reasonable solution when it comes to the state entering private property without permission for law enforcement purposes. This also seems like a reasonable solution for encryption. The state here is not making or trying to make encryption illegal; and it is open about the fact that court authorisation is required to enforce a backdoor.
- 90red 6y agoA backdoor is never a solution. It can, and will, always be abused. Furthermore, warrants are also trivially abused which I have seen done first hand.
- deleted 6y ago[deleted]
- girvo 6y agoThe reason that breaks down is that a backdoor to achieve this isn’t for that one case, it’s for everyone on the service (or easily made to be). It’s like getting permission to break every lock from a particular manufacturer, rather than permission to enter one particular home. I know in this particular case they’ve said it’s for a singular mailbox. I’m curious how they achieve it.
- McDyver 6y agoThis is the same as the TSA lock in newly made luggage. In order for Americans to have their luggage inspected, the Europeans have to have a backdoor into their luggage. Fortunately in Europe you can add a layer of security on top of that by adding new locks.
- giancarlostoro 6y agoI mean when you think about it in the grand scheme of things luggage isn't secure anyway, you can just cut through the fabric and other materials if you're so inclined to steal someones belongings from their luggage.
- McDyver 6y agoThat's true, but at least you'd have some evidence of tampering. If it's your data that is breached or your privacy invaded, you have no idea.
- hxtk 6y agoYou can also just push a pen through the zipper to open it without leaving any evidence. Simply run both locked-together sliders back over the zipper to close it.
- 37eydyhrh 6y agoThis sounds more like the analogy breaking down than illustrating a meaningful difference in scenarios. The police already /can/ break a lock from just about any manufacturer. They just break the door down and enter regardless of the phenomenal quality of the lock itself.
- girvo 6y agoThat’s exactly what I meant :)
- matheusmoreira 6y ago> We generally accept that warrants are a reasonable solution "We" accept nothing. The state can't execute warrants to get at what's inside people's minds. Computers are extensions of people's minds and I expect them to be equally inviolable. Also, even if it does have lawful access to the system, the state is not entitled to finding usable evidence. > it is open about the fact that court authorisation is required to enforce a backdoor There mere possibility of a court-mandated backdoor means the entire system is already compromised and it's impossible to trust it.
- 542354234235 6y ago> Computers are extensions of people's minds and I expect them to be equally inviolable. This is not a statement of fact and is generally a minority opinion.
- mikecoles 6y agoGo home, Twitter.
- matheusmoreira 6y agoSo my opinion doesn't matter just because I'm part of some minority?
- 542354234235 6y agoIf you want your opinion to be taken seriously or be seen as credible, you should probably back it up of justify in some way, rather than just stating it as if it is a fact. The thing is, I agree with you but I understand that it is not the general opinion of most people. I think it is important to explain and justify the very significant shift in thinking about what is “the mind”.
- throwaway2245 6y agoYou misrepresented what I said by removing the conditional part of the sentence - that's a misquote. >There mere possibility of a court-mandated backdoor means the entire system is already compromised and it's impossible to trust it. So then you should trust literally no software or hardware.
- upofadown 6y agoI doubt that Thunderbird would want to go back to a plugin for PGP. They just moved that support into the program with S/MIME.
- giancarlostoro 6y agoIt's not necessary for the Thunderbird team to do it, there are paid plugins for Thunderbird. I'd happily pay for a decent plugin if it is developed properly.
- account42 6y agoYou mean they just broke the plugin without providing adequate built in support.
- KingMachiavelli 6y ago(I used Google translate to some quotes might not be 100% correct) > "We therefore had to start developing the monitoring function" Ouch, pretty hard to recommend a service that has admitted to building tools for LE. > This should not change anything for other users; their emails should continue to be encrypted by default. Nevertheless, Tutanota sees a one-time bypassing of encryption as a data protection and security risk for all customers. > As Tutanota emphasized, the surveillance measure only affects newly incoming unencrypted e-mails. The company cannot decrypt already encrypted data or end-to-end encrypted e-mails in Tutanota. It's a bit unclear here if it only means plaintext, incoming emails are effected while in transit or if all new plaintext emails are/could be saved without encryption.
- raverbashing 6y ago> pretty hard to recommend a service that has admitted to building tools for LE As opposed to the ones that build and won't admit/can't admit?
- KingMachiavelli 6y agoTrue. Not much has really changed beyond more confirmation that anything plain text can be and will be fall into the hands of third party actor/government. Although certain jurisdictions at least in theory have barriers to this e.g Germany vs Switzerland.
- floatingatoll 6y agoA relevant machine-translated paragraph appears to indicate that they are only required to implement monitoring of a single mailbox: > This is about a blackmail that had been sent to an automotive supplier from a Tutanota mailbox. Tutanota is now forced to program a function by the end of the year that allows the State Criminal Police Office of North Rhine-Westphalia to monitor this mailbox. Lacking the ability to read this without translation, I cannot determine conclusively whether or not they're also required to preemptively retain plaintext emails for other mailboxes in order to support any future wiretapping requests.
- dr_hooo 6y agoMy understanding is that they are only required to monitor a single specific mailbox (for which a court order has been issued) - so no preemptive collection.
- lights0123 6y agoThe following (machine-translated) paragraph clears that up: This should not change anything for the other users, their mails should continue to be encrypted by default. Nevertheless, Tutanota considers a one-time circumvention of the encryption to be a data protection and security risk for all customers. [Update, 30.11., 12 o'clock] As Tutanota emphasized, the monitoring measure only affects newly incoming unencrypted e-mails. Already encrypted data as well as end-to-end encrypted e-mails in Tutanota cannot be decrypted by the company. [Update]
- bhaak 6y agoNo, you got that right. It's about a single mailbox and only for new mails. As they can't decrypt old mails themselves without a backdoor. Still, once they have this function, all it takes is a court order to start collecting for other mailboxes. Tutanota will take this to the next higher court but as it says in the article, they have to start implementing the backdoor right away.
- floatingatoll 6y agoThere's a clear distinction between "We are mandated by the court to maintain plaintext for all accounts for all time" and "We are mandated by the court to have the capability to maintain plaintext for one account when ordered so by subpoena-or-equivalent". This is the latter. Arguments can be had about the relevance of that distinction, but relevant or not, the distinction does exist. Thanks for clarifying! (I'm not participating in the "Is this distinction relevant?" discussion today, sorry, just trying to understand what was passed. See other threads for pro/con arguments.)
- pb77 6y agoI almost got Tutanota, I went with runbox. It is based off Norway, hopefully this ruling will not applicable for other email companies with EU.
- j_jochem 6y agoFun fact: Norway is not a member of the EU.
- usr1106 6y agoThey aren't, but they are in the EEA (European Economic Area). So in trade they mostly follow EU rules without participating in the political process. I don't how much of the lawful interception stuff is governed by EU directives. Even less whether that would affect EEA countries.
- cookiengineer 6y ago> Fun fact: Norway is not a member of the EU. Which I think is a shame. Sweden and Norway together would have a net positive influence on modernizing law across the EU. (I'm saying that as a German)
- alltakendamned 6y agoSweden already is part of the EU.
- cookiengineer 6y agoI'm just saying that Sweden, Norway and Finland together would make an awesome couple; given how they overcame legislative issues and how they modernized their countries against all odds (with all that happened after 1808). From a political perspective they're quick to adapt to a changing landscape.
- gerikson 6y agoSweden and Finland are both in the EU but AFAIK there's not much policy alignment between them with regards to EU legislation.
- stunt 6y agoI worked in the telecom industry, and knowing how much surveillance related regulations was there, I can't believe true e2e encryption is a thing on the internet. I'm surprised how so many people in tech believe that a messaging application like WhatsApp is allowed to have real e2e encryption. It's impossible for regulators to ignore a platform with substantial traffic.
- rglullis 6y agoYou are right, and yet I always asked myself if all the regulations ever made sense. Those that really want to coordinate any kind of illicit activity, do they use Whatsapp thinking it is secure, or would they be smart enough to set up their own infrastructure? How many threats were stopped due to police/Three-Letter-Agencies being able to tap into the largest services vs going to the deep web and infiltrating/investigating the group "in person"? In any case, my feeling is that all these regulations do is push privacy-conscious people into running their own infra. I was even on the point of running my own email, Matrix and even a SIP server at home, but then I realized that whoever I will be communicating with would not be doing the same so the whole thing is at best an exercise in my sysadmin skills.
- girvo 6y agoMy thing is that it doesn’t seem to make me safer. So I give up my privacy without (what seems to me) much benefit. I don’t like the trade-off... Are organised dangerous criminals really using and relying on platforms for this stuff?
- secfirstmd 6y agoYes they are https://techcrunch.com/2020/07/02/police-roll-up-crime-networks-in-europe-after-infiltrating-popular-encrypted-chat-app/ https://techcrunch.com/2020/07/02/police-roll-up-crime-netwo...
- bigphishy 6y agoWhere do you work, if you don't mind my asking? The Telecom Industry is really all-encompassing these days.
- sneeze-slayer 6y agoFrom my understanding of the article (non-native), it seems like it is only one specific mailbox that is to be monitored > "Tutanota sieht sich nun gezwungen, bis Jahresende eine Funktion zu programmieren...dieses Postfach zu überwachen." and that nothing else will change for the other users > "Für die anderen Nutzer soll sich dadurch nichts ändern, ihre Mails sollen weiter standardmäßig verschlüsselt werden" As other users have pointed out, it will only be for new emails for the specific mailbox, as the rest are already encrypted > "betrifft die Überwachungsmaßnahme nur die neu eingehenden unverschlüsselten E-Mails" We may have to wait until tomorrow for some more native speakers to wake up and translate.
- cpach 6y agoIt’s not so late here in Europe yet. At least not for hackers :) And there ought to be some German-speaking persons over the pond as well. We’ll see :)
- uallo 6y agoGerman native here. Your translation is mostly correct. The court seems to have forced Tutanota to store new incoming non-encrypted emails in plaintext for a specific mailbox that was used to blackmail an automotive supplier. But the article is not entirely clear on whether that is for that specific mailbox only. At one point, the article mentions that storing emails in plain text could be used on "specific mailboxes" (plural). > Ein Urteil des Landgerichts Köln zwingt das hannoversche Unternehmen nun jedoch zum Einbau einer Funktion, mit der Ermittler einzelne Postfächer überwachen und Mails im Klartext lesen können.
- pintxo 6y agoIANAL, but if I am not mistaken, German law requires telecommunication providers (above a certain threshold) to provide law enforcement with a way to look into customer communication via the provider. Meaning here, they need to implement a way for law enforcement to look into any mailbox they can come up with a warrant for.
- 6y ago
- bgorman 6y agoI was planning to migrate to Tutanota, I guess I will not be doing so after all
- deleted 6y ago[deleted]
- gruez 6y agoRealistically speaking, is there jurisdiction where this isn't a threat? Most governments allow for wiretaps (basically what this "backdoor" is) when there's a warrant, so I'm not sure what the alternative is. Not even self-hosting works because they can seize your server/ip/domain name and install a backdoor there.
- betaby 6y agoUnless if your server has full drive encryption
- gruez 6y agoThat does nothing for mail delivered after the warrant has been issued, which is what's being discussed in this post.
- welterde 6y agoDoing this without being noticed will be somewhat difficult to do though. Passive sniffing is likely not going to be enough since opportunistic TLS usage is on the rise..
- sneak 6y agoThis vulnerability exists for all email hosts. There is no way for a provider to prove to you they didn't silently escrow your plaintext.
- beezle 6y agoIf I read Tutanota's explanation of encryption correctly, messages sent between users are encrypted on the client side. While it would be obvious in network traffic if they sent back plain text to their server, it is possible to encrypt txt with multiple keys, ie their key as well as the intended recipient's. Would something like that be able to be detected on the client side, in particular for one user? I'm guessing yes but it would require verifying the js everytime you used their service, right? (asking) (added 'correctly')
- Sunny_Tarnkappe 6y agoTo this topic there is a more recent statement from tutanota on a german scene site. https://tarnkappe.info/tutanota-will-beschwerde-vor-dem-bgh-vorbringen/ https://tarnkappe.info/tutanota-will-beschwerde-vor-dem-bgh-... A recent interview with Tutanota can also be found there. https://tarnkappe.info/tutanota-der-deutsche-e-mail-dienst-im-interview/ https://tarnkappe.info/tutanota-der-deutsche-e-mail-dienst-i...
- md- 6y agogerman here: Tutanota is a german email provider which encrypts incoming email after those were received. The court ordered tutanota to provide incoming emails to a single email account to law enforcement. This is "lawful interception" as you know it, as "service-side encryption" is useless against lawful interception laws. - md
- deleted 6y ago[deleted]
- techelite 6y ago"Nothing is so permanent as a temporary government program." Oh the court says you can do it in 1 exception? That same rulling will be used to allow it to happen to everyone.
- tick_tock_tick 6y agoJust a friendly reminder that 99% of the time when the EU says privacy they mean from private parties never from governments.
- deleted 6y ago[deleted]
- bzb6 6y agoI don’t know what people expected from a service like this hosted in Germany... Germany is a very bad place for personal freedoms when compared to most of the west
- Kim_Bruning 6y agoI suppose the employees at Tutanota can do what the employees at Apple did: they could threaten to quit if they are instructed to work on this.
- noodlesUK 6y agoWould there be some way of wording a contractual agreement with a company such that all of their customers contracts would irrevocably end if such a backdoor were installed. Tutanota should consider ceasing trading in response to this. Surely the court won’t force them to not just stop supplying email services to everyone.
- sneak 6y agoFWIW, Apple has backdoored iMessage's end-to-end encryption via iCloud Backup plaintext/key escrow, automatically on by default, so if people did quit or threaten to quit, it didn't actually stop or change anything. Apparently Apple was going to fix this glaring hole in their cryptosystem, but Apple Legal killed it as a favor to the FBI. https://www.reuters.com/article/us-apple-fbi-icloud-exclusive/exclusive-apple-dropped-plan-for-encrypting-backups-after-fbi-complained-sources-idUSKBN1ZK1CT https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
- pferde 6y agoI wonder if publicizing this was a good idea. Now whoever was blackmailing can simply stop, or will find other means. It's like setting up a trap for smugglers or whoever and hanging a big blinking "TRAP HERE" sign on it.
- RickS 6y agoPerhaps that's the intent, similar to a warrant canary. It's fortunate that they're even allowed to talk about being forced to comply.
- bfrog 6y agoAnd just like that tutanota loses trust. Sad, it's a great service
- Holylander 6y agoClickbait verging on the fake news - they took piece of information completely out of the context and baked a "sensation". No, Tutanova does NOT install "backdoor" be it a court order or not. Government or else can only read contents of non-encrypted mails and only metadata of the encrypted mails, it has been so ever since and this is the way the email works. Clarification in plain English here https://www.reddit.com/r/tutanota/comments/k3sfs5/in_englisch_court_forces_mail_provider_tutanota/ https://www.reddit.com/r/tutanota/comments/k3sfs5/in_englisc...
- MCOfficer 6y agoBoth the article's title and its contents line up with what you're saying. I'm not seeing any clickbait here, save for perhaps the HN title.
- oytis 6y agoThe article says criminal police had a problem with an extortion email. If the victim is willing to collaborate what's the problem with getting the plaintext? Anyway, I wonder how it's going to be implemented for the case where encryption is done on the client side with open-source tools (not sure if that's the case for Tutanota).
- dathinab 6y agoBe aware that the local courts decisions is not in line with the decisions done by other German courts. It's likely that the courts decisions will be overruled or even be found to be unconstitutional.