Tutanota is now Tuta
tuta.com
tuta.com
There is no way to verify key fingerprint of your recipient right now. So server can just man-in-the-middle you providing third-party key and read all messages silently. It is not e2e encryption if you have to trust the server. Period.
Presto
>Verification of safety numbers is a good security practice for sensitive communication.
It is perfectly OK for a user to trust, say, Tutanota to not take an affirmative action to get access to their messages. We need a way to express this sort of tradeoff and providers should be required to put this expression where the user can see it and understand it.
Understatement.
Tutanota published a ranty blog post accusing Microsoft of suppressing competition in the email space. Because they didn't understand how fucking Azure works or even how corporate security works.
They literally let users register email addresses for @tutanota.com At the same time, they are using @tutanota.com for internal corporate and such they had an Azure AD Tenant already registered for that domain.
They complained that their tutanota.com email users couldn't register Microsoft accounts and this was all part of Microsoft's ploy to eliminate them.
No, they compromised themselves and unless they grew a brain, are still compromised for corporate communications.
As a first step, we are currently addressing cyptographic authentication of incoming messages. Our development team is implementing this feature as part of the work on tuta crypt, our pq messaging protocol. It will be released within the next months. However, we have to admit that easy and automatic key verification will take some more time as we are still researching best options to implement this.
Switched away because of terrible search experience and lack of SMTP and IMAP access.
Tuta became understandably a walled garden that my other tools couldn't easily work with. This wasted alot of my time.
Nowadays using $normalemailprovider with Thunderbird.
Infomaniak also sells email hosting for around 20 Euro per year, they are based in Switzerland. If you have your own domain, just type the domain name as you would buy the domain and if the interface says domain taken, select email hosting (the three dots).
"So, further to recent changes at Gandi, I've just got some more info from support which I've included below. I've purchased domains from Gandi, pre-paying for multiple years of service such that some domains I have don't need renewing until 2027. When I purchased that service the offer was inclusive of 2 mailboxes for the duration of the contract, and now they're planning to remove those inclusive mailboxes and start charging me extra for them from next month.
To me, this sounds like a planned and fully intentional breach of contract."
Sorry, I was not aware that they changed. Currently I don't hold a domain with them. They were always a decent provider. This behavior seems very unfortunate.
https://www.lesbonscomptes.com/recoll/pages/index-recoll.htm...
FastMail has excellent documentation to get this set up. Migrating there from GMail (were I already used my own domain) was a breeze.
They're based in Belgium, and have a solid stance on privacy and security. They provide IMAP/SMTP access, calendar/CalDAV, contacts/CardDAV, custom domain names, filters, spam blocking, etc. It's a pretty well-rounded and maintained service. The web UI is not the most modern, but it's usable.
The police were able to get a lot of info from mailfence to catch a stupid student who thought using a vpn and mailfence would enable him to send threats easily to the richest man in india. The police got info on how many accounts were from this country, how many of them were active, monitor the mail account for new mails etc..
Mailfence is pretty open about this[1]. Their privacy policy[2] also seems reasonable. Their only obligation is complying with Belgian law, and I'll take that any day over a service within the Five Eyes jurisdiction.
[1]: https://blog.mailfence.com/transparency-report-and-warrant-c...
sometimes some actions (mostly moving mails between folders - like deleting) are slow. But not a show stopper.
Other options: https://www.privacytools.io/privacy-email
We're constantly improving the service, for instance we've just added unlimited email addresses with your own domain (https://tuta.com/blog/summer-releases-2023) so always happy to hear feedback and how we can meet your needs!
Trust in accounts like Tutanota seems to be rather informal. Perhaps it works anyway.
Just so you know the original team behind that site moved to https://www.privacyguides.org/en/email/
We don't list StartMail because it's not really zero knowledge (if you look at their "vault" system it's basically a LUKS container which is "opened" when you login server side). The author of PTIO puts no effort into reviewing/reading or understanding how any of the recommendations work.
Disclosure: I am one of them, the old privacytools website now is mostly an affiliate marketing portal. More info about that can be found here: https://www.privacyguides.org/en/about/privacytools/
Been using this since 2005 I think
And I cannot "bridge" Thunderbird to Tutanota to apply my filters.
Recent price change was the last straw to make me another end-to-end encrypted alternative.
Recently I switched to Proton Mail with advanced Sieve filter [1] and feel much happier.
[1]: https://proton.me/support/sieve-advanced-custom-filters
This is the part that resonates with me very strongly right now. I have always been concerned about privacy, security... re: the applications I use. Recently, I started to question this in regard to some applications.
I needed a WiFi-friendly way to SMS & call for about a year and opted for Signal. The year's over, no longer need Signal. Now I find that I can't delete Signal without losing the (very boring) chat files forever.
Signal does not support exporting, saving chat logs. I looked into 3rd-parties:
1. Great solution by YourFavouriteElite (2 years old) - sadly it failed
https://www.reddit.com/r/signal/comments/irbxii/how_can_i_ex...
2. Two Windows solutions here (failed to run in WINE, will need Windows to test):
https://www.ticktechtold.com/export-signal-pdf-csv-html/
3. Also... I'm finding that I'm having problems communicating with Apple users over regular SMS. I will often not receive their SMS messages unless I turn on WiFi (I'm on Android). This could be several hours after they sent it. I have not bothered to investigate further but it feels like more walled garden stuff, competing protocols, etc..
There just doesn't seem to be a nice 'in-between' between security/privacy and closing yourself off from your data.
'nuf said. I think I'm ranting now mostly because I didn't make the right choice early on for my needs. I just didn't think it through.
I used Tutanota for a bit. Great product,all around better than protonmail from technical and usability standpoint, but I stopped using it.
Why? You don't realize how often you give out your email over the phone or to someone verbally. "Tutanota" is simply way too easy to screw up. Tootanota? Tutanoda? two-ta-what??? Even when there wasn't a struggle passing this along to someone, I'd always be worried that they wrote it down incorrectly.
I know I could get my own domain, but still, the default email should offer a domain that's easy to spell (e.g. proton.me).
I didn't know that this was possible. It is a feature on browser's password managers? How it works?
- (To my knowledge) Tuta doesn't have secondary services like VPN, etc.
- Tuta intentionally does not provide a bridge for email. So everything with their service has to be done through their apps. If you want to use your own email client or command line tools (such as for submitting patchsets to mailing lists), that's not an option.
What sane person would do this? Use infomaniak instead (Switzerland). Tuta seems to be a German company. There is another one, I forgot the name but a few friends of mine were using it. I used google, could not find it but I am actually surprised that there are many providers. E.g.
https://www.qualityhosting.de/hosted-exchange/hosted-exchang...
https://www.netart.com/de/email/
Ah, found it: https://posteo.de/de
Surprised that there are so many players in this field.
I use Gmail, and have exclusively used the web app and Android app to access it, for, what, 15 years? I don't think it's insane, if those apps work well.
Products should just work the way they are intended to be. Apple built an empire on this simple concept.
But hey, "open source all things" have decided I must use 4 products from 4 different providers to send an receive emails so that I am "safe".
Depends. For my mother? She is fine with gmail. But an IT savvy person should consider having their own email domain. And why not host your own rss reader and a few other things. It is rarely a good idea to buy this out of one hand. So domain registrar (e.g. internet.bs ), email hosting (e.g. infomaniak.com ) and hosting (e.g. nearlyfreespeech.net ). So we are close to your 4 different providers.
"Products should just work the way they are intended to be."
Until they don't. Until you get blocked (try calling google email customer service). Or until they go bankrupt. Your license? Sorry, the server for license validation does not exist anymore. Or until somebody decides what you can do with the product and what not. Doing your own thing and using open source gives your freedom.
if you don't pay for the product you are the product.
Having email domain is different than hosting your own email servers. And even that - why would I care so much? There are plenty of articles here on HN of people telling how hard it is to host your own email servers.
Plus, tech-savvy doesn't mean I want to waste 2 hours a week updating managing servers etc., while I could maybe learn ... "Flutter"? Or technology X. Or something else completely different.
In general, assuming what a group of people should or shouldn't do seems pretty naive to me.
> if you don't pay for the product you are the product.
I pay for Fastmail and it works. Until when? I can't tell - I hope they don't go bankrupt. But they offer a good service, decent price, and it gives me 1-2 hours of life back per week or month.
I understand your counterarguments, however nowadays there is enough variety that enables us to use products and services for quite some time. Even open source can get you into "vendor" lock-in, especially when a tool or product doesn't evolve anymore and the community doesn't have interest or manpower to improve it.
As a word of caution: Should you ever lose access to your gmail account, you run into deep trouble. I currently can't access my gmail. I know the password, I have access to my backup email but it won't let me log-in except if I am able to confirm it on my android phone. And my US android phone is out of service. I have to fly to the US to get this working again (Google project fi).
For E2EE email it's a bit different because most of the standard protocols don't work out of the box but it's very clear that whatever system Tuta uses works locally or they wouldn't have anything but a web app.
I'm not saying don't prioritise your apps, I just want to be able to mutt and send in patches easily. And my grandparents want to use their outlook because it's what they know how to use.
They deliberately don't allow your own domain, and they lie about their reason, claiming privacy:
"No. We are an email provider with a particular, privacy-oriented model – and this is not compatible with incorporating own domains."
> Can I use Posteo with my own domains?
> “No. We are an email provider with a particular, privacy-oriented model – and this is not compatible with incorporating own domains. One of our emphases is data economy: we do not collect any user information (names, addresses, etc) of our customers. We always answer requests from authorities for user information in the negative. On the other hand, own domains need to be registered to the name and address of a person. If you were able to use own domains with us, this would affect the entire concept of Posteo: we would need to start saving user information for all customers who use their own domains with us – and to provide these to the Federal Network Agency to be provided on request to the authorities. Even if only the MX record pointed to us, we would still need to store the assignment of the domain in your Posteo account as user information. Thus we would possess your user information and be required to give it out. For this reason, we have decided not to offer this possibility and instead to use data economy.”
Whether this sounds fine or not and whether this is acceptable to someone or not is subjective.
So let the user decide. They can use non-de domains, they can use privacy shielding services.
Posteo doesn't need any real name or address to put a domain in their mail configuration. That whole part is just more lies.
I paid for Tutanota and started switching to it from Gmail, but the accumulation of inconveniences is starting to make me consider switching back, in spite of all the Google privacy issues.
About your comparison:
Why exactly do you believe Switzerland is better in terms of data protection than Germany? Do you not need to share data with the US as well upon request? The good thing - in both countries - is that it has legal oversight, besides the data on our servers is encrypted so we don't really see the location benefit here.
And what about data retention laws in Switzerland? In the past, you said Protonmail is exempt from this as its too small. Would be interesting to know if this is still the case?
quaintdev@tuta.com sounds funny lol.
He used to recommend mailbox.org and migadu.
Two questions:
1) Does anyone know why he does not recommend Tuta(nota)? Edit: I missed the footnote
> Do they make unfounded claims about security or privacy, or develop techniques which ultimately rely on trusting them instead of supporting or improving standards which rely on encryption?
> This also rules out ProtonMail and Tutanota, doubly damning them, especially because it provides an excuse for skipping IMAP and SMTP, which conveniently enables vendor lock-in.
I see from other comments that they don't support IMAP/SMTP and force their own apps.
2) Does anyone know why he stopped recommending mailbox.org? He changed it a few weeks ago without any explanation I can see.
I mentioned infomaniak.com already as an Email provider (can bring you own domain). It is also Switzerland. But regarding law enforcement, posteo.de did a pretty decent job. E.g.:
https://posteo-de.translate.goog/site/transparenzbericht_201...
I once saw a long post from posteo with examples for idiot law enforcement trying to get customer data. Sometimes even writing from private emails (e.g. gmail). Without a court order, such requests are not legit.
I have previously also used Migadu, but I migrated to mailbox.org. Can't remember why exactly and looking at migadu.com again today, they seem to tick all the boxes for me when it comes to personal email. I remember they had a great UI in general, but in particular the settings UI was fantastic.
> How can I trust you? You can't. Cock.li doesn't parse your E-mail to provide you with targeted ads, nor does cock.li read E-mail contents unless it's for a legal court order. However, it is 100% possible for me to read E-mail, and IMAP/SMTP doesn't provide user-side/client-side encryption, so you're just going to have to take my word for it. Any encryption implementation would still technically allow me to read E-mail, too. This was true for Lavabit as well -- while your E-mail was stored encrypted (only if you were a paid member, which most people forget), E-mail could still technically be intercepted while being received / sent (SMTP), or while being read by your mail client (IMAP). For privacy, we recommend encrypting your E-mails using PGP using a mail client add-on like Enigmail, or downloading your mail locally with POP and regularly deleting your mail from our server.
Also, there's this quote from /g/:
Administering a mail host is sort of like being a nurse; there's a brief period at the start when the thought of seeing people's privates might be vaguely titillating in a theoretical sense, but that sort of thing doesn't last long when it's up against the daily reality of shit, piss, blood, and vomit.
Now that I think about it, administering a mail host is exactly like being a nurse, only people die slightly less often.
--------------------------------
They also publish all emails/call recordings when dealing with law enforcement on their transparency page.
Some people are way too serious on the Internet. If you are offended by a bunch of words without proper context you really need to go outside.
Also see this thread that discusses this at length: https://news.ycombinator.com/item?id=33142122
I'd also argue that most people that complain about those jokes unironically think that author is actually racist, like it doesn't even cross their mind that it could be a joke, even a "bad" one.
Ironically, the fact that some people react in this way makes these jokes even funnier
[1] https://www.lemonde.fr/pixels/article/2019/10/11/derriere-l-...
Cock.li on the other hand is run by the OvO systems owner himself.
Now just make sure that elderly relative can sign up once they get to the landing page.
With no guarantee of compliance, nor guarantee of a backdoor not being added to this service - it’s hard to put Tuta ahead of any other supposed privacy-first provider. They didn’t pull a TPB and tell the court to get fucked, and exit the country. So it’s hard to assume they’ll ever not comply with a backdoor order.
So instead I’ll opt for the one least likely to go under, with the most features. And it’s not Tuta.
This isn't an out of sight out of mind situation, if you ask for bulletproof hosting you will face consequences on way or another and you can't just ignore that in a calculation. Same as you don't ignore the consequences of abuse of political power clearly.
Not goona .. which was admittedly my first thought for a possible translation.
Though it does sound like "tota", which in Moroccan dialect again is the childish synonym for penis :))
I guess any short name is bound to have weird meanings in other languages!