5 ms·
Tutanota likes to tell everyone that they are literally Signal in the email world in terms of security. But there is a known vulnerability in their "E2EE": htt
by abc_xyz 3y ago
Tutanota likes to tell everyone that they are literally Signal in the email world in terms of security. But there is a known vulnerability in their "E2EE":
https://github.com/tutao/tutanota/issues/768 https://github.com/tutao/tutanota/issues/768
There is no way to verify key fingerprint of your recipient right now. So server can just man-in-the-middle you providing third-party key and read all messages silently. It is not e2e encryption if you have to trust the server. Period.
- unixhero 3y agoYou can slap PGP on top Presto
- nehal3m 3y agoBut you can do that with any provider right?
- unixhero 3y agoYes you may
- alwayslikethis 3y agoCan you? It's arguably much more annoying than other providers because you can't use a normal email interface. I've been trying to switch off it for a while and just use a normal provider with simplelogin slapped in front. Also, the spam filter isn't very good.
- tharne 3y agoYou can do this with any email. What's your point? The reason for the rise of email providers advertising encrypted email is because PGP is a pain for most people to use and never saw widespread adaption among regular users.
- unixhero 3y agoMy point is still true
- uconnectlol 3y agoyou cant because tutanota has no POP/SMTP/IMAP so its basically just a web form. you could of course add PGP to any such communication medium but it wont be very standard
- upofadown 3y agoIt all comes down to truth in advertising. Such misrepresentations are very common these days. Even Signal is not entirely innocent here. Signal only has the potential to have end to end authentication/encryption. By default you trust Signal, Twilio and the phone company. The app/documentation does not make it entirely clear to the user that verifying the "Safety Number" is critical to establishing an end to end connection with someone. From the Signal documentation: >Verification of safety numbers is a good security practice for sensitive communication. It is perfectly OK for a user to trust, say, Tutanota to not take an affirmative action to get access to their messages. We need a way to express this sort of tradeoff and providers should be required to put this expression where the user can see it and understand it.
- delfinom 3y ago>It all comes down to truth in advertising Understatement. Tutanota published a ranty blog post accusing Microsoft of suppressing competition in the email space. Because they didn't understand how fucking Azure works or even how corporate security works. They literally let users register email addresses for @tutanota.com At the same time, they are using @tutanota.com for internal corporate and such they had an Azure AD Tenant already registered for that domain. They complained that their tutanota.com email users couldn't register Microsoft accounts and this was all part of Microsoft's ploy to eliminate them. No, they compromised themselves and unless they grew a brain, are still compromised for corporate communications.
- laurentlbm 3y agoThat's hilarious!
- Tutanota 3y agoKey verification is an important part and we are working towards the goal to enable easy authentication. However, we are not happy how manual key verification works with Signal nor how it is implemented with GPG (Web of Trust). Most (at least 95%) don't verify keys with Signal because it is too cumbersome. As a first step, we are currently addressing cyptographic authentication of incoming messages. Our development team is implementing this feature as part of the work on tuta crypt, our pq messaging protocol. It will be released within the next months. However, we have to admit that easy and automatic key verification will take some more time as we are still researching best options to implement this.