Tuta (formerly Tutanota) denies claim it has intelligence ties
cp24.com
cp24.com
Don't get me wrong, whether they have or don't have intelligence ties is irrelevant. No one serious uses them, they're a general public supplier, and the general public is about as brave as a gringo cop, i.e.: not much.
So they're about to lose a chunk of customers and Tutanota's leadership isn't exactly quality so who knows what they'll do.
Hey... :c
In my understanding, anything that Tuta potentially did to compromise e-mails would necessarily have to shine through in their open source client code -- unless they willingly serve binaries that are not actually built from that code, which of course would be a scandal.
So even if I don't like them, I'm going to need something more concrete than someone simply saying they have "intelligence ties" to be willing to believe that they are somehow duping their users.
Quite the opposite even, according to them at least. They are one of the first pioneering post-quantum encryption in email.
I always ask this because ultimately if you are consuming a web-based application, you have to have some level of trust in the provider. And if you didn't trust them, your only option would be to completely self-host in an environment that only you have full control over.
The point here is, if they have nothing to hide, they can easily open source. If they already have a weird system to serve some people insecure code, they have to extract that from their code base, maintain 2 versions and make sure both sides are up to date at all times. So not going open source is easier if you wanna be malicious. Not a huge task for feds tbh, but still.
Also, there's still benefits for my privacy and security as in I'm sure some people would find vulns in the code and report them.
Also, regardless of whether someone is actually interested in self-hosting or not, one can still call Tuta disingenuous for repeatedly marketing themselves as “open source” when they are clearly not.
But my comments were mostly around your original post, where you said you were sceptical of their trustworthiness because they hadn't open-sourced the server-side components. This implied that you would trust them (and I assumed the SaaS service) more if they did this. I was just expanding on a theme that you mentioned: "unless they willingly serve binaries that are not actually built from that code...", and I was just highlighting the fact we would never know if this was happening. So if you're sceptical without them open-sourcing, you should remain sceptical even if they did open source the backend.
I never said that. I said that:
- Their marketing is disingenuous because they call themselves "open source",[1] when their server side component is in fact not open source.
- I was "skeptical" regarding one very specific thing:
> if their clients are indeed open source (...), and all encryption happens client-side before being sent to the server (...), how would it even be possible for this [tutanota being compromised] to be true?
[1]: You can confirm this by searching for `site:https://mastodon.social/@Tutanota open source`
Tuta has all kind of weird restrictions, like not being able to search back more than a month.
Without having a good anonymous starting point, protonmail does not let you get that starting point, at least the last time I tired (maybe a year ago).
It's a stark contrast to Tuta, which allows anonymous account creation with Tor Browser if you pay with cryptocurrency (Monero or Bitcoin, via their partner ProxyStore) and doesn't require a whitelisted verification email address or any other data.
"They accept cryptocurrency, but only for existing accounts - after you've already doxxed yourself" (during the initial signup flow, where this payment option has been removed)
This looks very bad to me.
And what suspicious thing about the network would you be detecting for Tor Browser users arriving on the .onion? Their network is uniform as far as you can tell, and you are blocking them from opening either a free account without an invasive verification method (non-disposable email or phone) if it works at all, or a paid account without an invasive payment method.
For Tor users arriving on proton.me, what sense is there in saying "There's a surprise in every 100th exit node! If you cycle through enough of them maybe you too will be allowed to open an account anonymously!" Not treating them as equivalent to .onion visitors is a you problem.
> It takes a while for the Bitcoin transaction to come through, which is why we the process is the way it is.
By not allowing this payment option at all in the signup flow? Removing what would be the only way for Tor users to sign up to your service anonymously without beating lottery odds. Just use any normal off-the-shelf checkout page that waits for however many transaction confirmations you want! (Let's not even get into the lack of privacy coin support, e.g. Monero. For a privacy focused service, Bitcoin L1 only is substandard in 2023.)
Meanwhile, whenever people are concerned about user data being handed over to the authorities again, you counter by pointing out the supposed Tor support: https://web.archive.org/web/20210906132309/https://protonmai...
I'm not saying you are a honeypot. I'm saying you've cultivated such a careless indifference to data minimization that you've become indistinguishable from one.
To add an exemption for proton.me: The list of Tor exit IPs is public. For the .onion: That's loopback traffic from the tor daemon running on your own load balancer or wherever you've put it.
The email addresses, however, are not tied to your account - we only save a cryptographic hash of your email address. Due to the hash functions being one-way, we cannot derive your data back from the hash: https://proton.me/support/human-verification.
https://protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7ozyd.onion/
and I was never asked to provide any personally identifying information.Did you access the .onion with something more fingerprintable like Brave?
In the past, their billing was based on blackmailing. I don't know if that is the case anymore. But I dropped using it ever since.
> In the past, their billing was based on blackmailing.
Not saying I don't believe you but I'd like to know more.
Well, anyway when the credits ended, your service did not downgrade but they put your negative credit automatically, and if you don't pay it, you were never able to use your account until you pay this negative part.
There was no mention in anywhere that this would happen, and also all the messages were quite threatening.
I think the Western intelligence agencies have lots of documented cases of creating companies for purposes like this. https://www.theguardian.com/us-news/2020/feb/11/crypto-ag-ci...
no shit, but the claim is that you aren't...
Perhaps what makes the ruse convincing in Tutanota's case is the crappy interface and clear dearth of basic features: search basically doesn't work; it's impossible to select all messages or use shift to select pages of messages. Their excuse is that customers might accidentally delete emails, but it might make more sense that they want to retain as much data as possible: https://www.reddit.com/r/tutanota/comments/nc9jxx/suggestion...
Implementing search for E2EE mailbox is difficult problem (Protonmail is not doing the same). For search to be efficient, you would need to download the whole mailbox for your device. If you want to support as many users as possible, you can't. But maybe they could make it optional.
And they are very small team, offering mail for very low price (free for most), which has resulted on using Electron for producing the applications for as many platforms as possible. And it is a mess.
What comes to that Reddit post, it is two years old and they have supported mass selection for a long while for now.
Maybe over longer period it would be possible to integrate and maintain the index so, that you can guarantee the correctness without full mailbox.