• 8 Posts
  • 20 Comments
Joined 2 years ago
cake
Cake day: July 2nd, 2023

help-circle










  • Quite a lot of cryptography detail in their blog post, not all of which do I understand. Curious to find out what the community thinks of this …

    For instance:

    We’ve re-built the Tuta cryptographic protocol from the ground up and are now upgrading our encryption using quantum-resistant algorithms together with conventional algorithms (Kyber in combination with AES 256 and ECDH x25519 in a hybrid protocol) for our asymmetric public key encryption of emails

    I know Bruce Schneier says rolling your own Crypto is hard and most will get it wrong. So is it concerning that they made their own encryption protocol?


  • Wouldn’t that be only between Tutanota users anyway?

    Just since nobody else answered your question: No. A Tuta user can send an encrytped message to anyone (including non-Tuta users). Those users then get an unecrypted message, saying “Click here to read your message”, which takes them to the Tuta site, which lets them see the message. The non-Tuta user can then reply to the Tuta user as they like.

    But you’re right about the UI. Tuta users have to use the Tuta UIs (mobile, desktop, web).