home.social

#e2ee — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #e2ee, aggregated by home.social.

fetched live
  1. I often see that question about the way I use #E2EE over #ActivityPub.
    #FediHood and #HolosSocial do not use the end-to-end encryption #Mastodon is working on. They are going for MLS over ActivityPub. I use the Signal Protocol, already working between Holos and FediHood, which I both maintain. Once MLS is available, I'll happily switch.
    But to be clear: it works perfectly with the Signal Protocol. The switch would only be for compatibility.

  2. I often see that question about the way I use #E2EE over #ActivityPub.
    #FediHood and #HolosSocial do not use the end-to-end encryption #Mastodon is working on. They are going for MLS over ActivityPub. I use the Signal Protocol, already working between Holos and FediHood, which I both maintain. Once MLS is available, I'll happily switch.
    But to be clear: it works perfectly with the Signal Protocol. The switch would only be for compatibility.

  3. I often see that question about the way I use #E2EE over #ActivityPub.
    #FediHood and #HolosSocial do not use the end-to-end encryption #Mastodon is working on. They are going for MLS over ActivityPub. I use the Signal Protocol, already working between Holos and FediHood, which I both maintain. Once MLS is available, I'll happily switch.
    But to be clear: it works perfectly with the Signal Protocol. The switch would only be for compatibility.

  4. I often see that question about the way I use #E2EE over #ActivityPub.
    #FediHood and #HolosSocial do not use the end-to-end encryption #Mastodon is working on. They are going for MLS over ActivityPub. I use the Signal Protocol, already working between Holos and FediHood, which I both maintain. Once MLS is available, I'll happily switch.
    But to be clear: it works perfectly with the Signal Protocol. The switch would only be for compatibility.

  5. I often see that question about the way I use #E2EE over #ActivityPub.
    #FediHood and #HolosSocial do not use the end-to-end encryption #Mastodon is working on. They are going for MLS over ActivityPub. I use the Signal Protocol, already working between Holos and FediHood, which I both maintain. Once MLS is available, I'll happily switch.
    But to be clear: it works perfectly with the Signal Protocol. The switch would only be for compatibility.

  6. Question to my fellow #Django friends:

    Is there a good zero trust framework for E2EE Django applications?

    Ideally with a decryption UX that doesn't require a PhD…

    #django #python #libsodium #security #e2ee #infosec #ccc

  7. Question to my fellow friends:

    Is there a good zero trust framework for E2EE Django applications?

    Ideally with a decryption UX that doesn't require a PhD…

  8. Question to my fellow #Django friends:

    Is there a good zero trust framework for E2EE Django applications?

    Ideally with a decryption UX that doesn't require a PhD…

    #django #python #libsodium #security #e2ee #infosec #ccc

  9. Question to my fellow #Django friends:

    Is there a good zero trust framework for E2EE Django applications?

    Ideally with a decryption UX that doesn't require a PhD…

    #django #python #libsodium #security #e2ee #infosec #ccc

  10. Question to my fellow #Django friends:

    Is there a good zero trust framework for E2EE Django applications?

    Ideally with a decryption UX that doesn't require a PhD…

    #django #python #libsodium #security #e2ee #infosec #ccc

  11. #FediHood keeps growing, and many bugs have been fixed thanks to your feedback.

    Federation now works smoothly over #ActivityPub. The Nearby and Discover timelines work as intended, and push notifications are available. #E2EE still needs work to support several browsers or devices.

    It is a good start. You can join this new fediverse software at fedihood.social

  12. #FediHood keeps growing, and many bugs have been fixed thanks to your feedback.

    Federation now works smoothly over #ActivityPub. The Nearby and Discover timelines work as intended, and push notifications are available. #E2EE still needs work to support several browsers or devices.

    It is a good start. You can join this new fediverse software at fedihood.social

  13. #FediHood keeps growing, and many bugs have been fixed thanks to your feedback.

    Federation now works smoothly over #ActivityPub. The Nearby and Discover timelines work as intended, and push notifications are available. #E2EE still needs work to support several browsers or devices.

    It is a good start. You can join this new fediverse software at fedihood.social

  14. #FediHood keeps growing, and many bugs have been fixed thanks to your feedback.

    Federation now works smoothly over #ActivityPub. The Nearby and Discover timelines work as intended, and push notifications are available. #E2EE still needs work to support several browsers or devices.

    It is a good start. You can join this new fediverse software at fedihood.social

  15. #FediHood keeps growing, and many bugs have been fixed thanks to your feedback.

    Federation now works smoothly over #ActivityPub. The Nearby and Discover timelines work as intended, and push notifications are available. #E2EE still needs work to support several browsers or devices.

    It is a good start. You can join this new fediverse software at fedihood.social

  16. Today, @Tutanota published a new blog post titled "Proton Mail vs Gmail: Which Is Best in 2026?". We generally don't pay attention to these biased marketing posts which end up always the same way ("neither, because we are the best"), but given the number of inaccuracies we found in it, we decided to take the time to comment it.

    tuta.com/blog/protonmail-vs-gm

    First of all, the post doesn't differentiate security from privacy. Even if the two notions are intertwined, it's still two different concepts.

    End-to-end encryption (E2EE) brings mainly privacy, that Gmail lacks heavily because it goes against Google's business model, but saying that having E2EE always brings you security is taking a shortcut. For example, most people are more exposed to email phishing than state actors' eavesdropping, and both Gmail and @protonprivacy are better at phishing detection than Tuta. We know it due to a simple fact: we recently launched a phishing simulation service (not launched publicly yet, still exploring with a few clients for now) 🙃

    > Like Tuta Mail, Proton Mail has become a popular email provider for individuals and organizations who prioritize privacy and security.

    This sentence tends to be understood as if Tuta preceded Proton in terms of market shares and technical standards. Also, from our experience, people tend to know Proton and not Tuta.

    > [...] introducing an AI email writer defies the purpose of a private, secure email service such as Proton Mail

    Even though we are against the current AI trend given its social and environmental impacts to keep it short, this sentence is also inaccurate. Scribe, Proton's writing assistant, can run locally on your own device:

    proton.me/support/proton-scrib.

    Besides, it's an opt-in feature, it is not enabled by default.

    > Users [of Proton] on the free email plan are limited to sending 150 emails daily.

    Well, at least Proton gives a straight answer regarding the daily limit on a free account. From Tuta's FAQ (tuta.com/support/howto#email-l):

    > If you receive the following message in your Tuta account "It looks like you exceeded the number of allowed emails. Please try again later.", the anti-spam protection method has stopped your account temporarily from sending new emails. Please wait a day or two to send new emails again.

    It seems there is no way to know if you are about to reach the limit before not being able to send emails for up to 2 days...

    > With the free Proton Mail account, users get 1 GB of storage space.

    We don't get it. It's listed in "Proton Mail downsides" whereas you also get 1 GB of storage with a free Tuta account... And with Proton, you can easily unlock 5 GB of storage with a free account...

    > [...] Tuta Mail, has decided not to build a bridge for third-party desktop clients but has instead focused on developing its own native email desktop clients for Windows, Apple and Linux - and these work like a charm and are completely free.

    This is part of the "Limited integrations" bullet point which is also part of the "Proton Mail downsides". That doesn't make any sense. Tuta is saying that Proton has limited integrations with third-party email clients and services (which is true), whereas Tuta has none... And regarding their "and these work like a charm" claim, sorry, but being a Tuta client since our creation in 2021, we have encountered numerous serious bugs. Like having sent emails ending up in both "Draft" and "Sent" folders with no way to know if the emails have actually been sent, the impossibility to change the language of the spell checker, getting a empty calendar because of a slow internet connection in a train whereas it is supposed to be offline-first, lost all our contact notes...

    > Proton is a good choice if you’re looking for an end-to-end encrypted email provider, but it is not worth it if you compare it to Tuta Mail, the most secure quantum-proof email provider.

    And there comes the inevitable conclusion that we all saw coming: "we are the best". It is the part that annoys us the most, because we are security practitioners, and we don't like false claims.

    First, after 5 years of professional activity, and 10+ years with a personal account for our CEO, the amount of E2EE'd emails we have sent and received must represent roughly 1% of our exchanges (we use emails mostly for external communications). This is because Tuta made the choice to use a home-brewed implementation that only works between Tuta users. You like it or not, but the only standard for email encryption remains OpenPGP, which is annoying to use with the Tuta client. When we report security vulnerabilities to third-parties for example, we need to write and encrypt our emails in a separate text editor, encrypt them (we use @QubesOS Split GPG implementation to keep our private keys in a separate, offline, environment), and paste the result in the Tuta client...

    Also, Tuta keeps talking about being an "quantum-proof email provider", but guess what? Thanks to RFC 9980, OpenPGP is quantum-proof too, meaning anyone using OpenPGP can benefit from it, including Proton:

    proton.me/blog/introducing-pos

    Besides, it is a nice thing to have a strong encryption on the paper, but the implementation needs to be regularly checked for bugs and vulnerabilities. As far as we know, Tuta has never published any audit report, unlike Proton (which also has a bug bounty program: proton.me/security/bug-bounty).

    When you do E2EE, you also need to make sure you are talking to the intended recipient, which means you need a way to verify their cryptographic public key. It turns out it took Tuta 7 years to implement it after the issue was raised to them: github.com/tutao/tutanota/issu. It means that Tuta could read all the E2EE'd exchanges on their platform without anyone noticing. Additionally, their current implementation saves the verified fingerprints locally and per-device. And given that bugs in the Tuta client regularly require to erase all local data and log back in, key verification remains mostly a gadget.

    If you wonder how Proton does it: proton.me/support/address-veri, and proton.me/support/key-transpar.

    To conclude, are we saying that Tuta is a bad choice? No, we will still recommend actors like Tuta which are not part of surveillance capitalism. Are we recommending Proton over Tuta? Not necessarily, it depends on multiple factors and your threat model. But we urge Tuta to improve their communication by sticking to the facts, and stop acting as if they were doing everything better than others. Because they are not.

    #Tuta #Proton #Security #Privacy #Email #E2EE #PostQuantum #FOSS #EU

  17. Today, @Tutanota published a new blog post titled "Proton Mail vs Gmail: Which Is Best in 2026?". We generally don't pay attention to these biased marketing posts which end up always the same way ("neither, because we are the best"), but given the number of inaccuracies we found in it, we decided to take the time to comment it.

    tuta.com/blog/protonmail-vs-gm

    First of all, the post doesn't differentiate security from privacy. Even if the two notions are intertwined, it's still two different concepts.

    End-to-end encryption (E2EE) brings mainly privacy, that Gmail lacks heavily because it goes against Google's business model, but saying that having E2EE always brings you security is taking a shortcut. For example, most people are more exposed to email phishing than state actors' eavesdropping, and both Gmail and @protonprivacy are better at phishing detection than Tuta. We know it due to a simple fact: we recently launched a phishing simulation service (not launched publicly yet, still exploring with a few clients for now) 🙃

    > Like Tuta Mail, Proton Mail has become a popular email provider for individuals and organizations who prioritize privacy and security.

    This sentence tends to be understood as if Tuta preceded Proton in terms of market shares and technical standards. Also, from our experience, people tend to know Proton and not Tuta.

    > [...] introducing an AI email writer defies the purpose of a private, secure email service such as Proton Mail

    Even though we are against the current AI trend given its social and environmental impacts to keep it short, this sentence is also inaccurate. Scribe, Proton's writing assistant, can run locally on your own device:

    proton.me/support/proton-scrib.

    Besides, it's an opt-in feature, it is not enabled by default.

    > Users [of Proton] on the free email plan are limited to sending 150 emails daily.

    Well, at least Proton gives a straight answer regarding the daily limit on a free account. From Tuta's FAQ (tuta.com/support/howto#email-l):

    > If you receive the following message in your Tuta account "It looks like you exceeded the number of allowed emails. Please try again later.", the anti-spam protection method has stopped your account temporarily from sending new emails. Please wait a day or two to send new emails again.

    It seems there is no way to know if you are about to reach the limit before not being able to send emails for up to 2 days...

    > With the free Proton Mail account, users get 1 GB of storage space.

    We don't get it. It's listed in "Proton Mail downsides" whereas you also get 1 GB of storage with a free Tuta account... And with Proton, you can easily unlock 5 GB of storage with a free account...

    > [...] Tuta Mail, has decided not to build a bridge for third-party desktop clients but has instead focused on developing its own native email desktop clients for Windows, Apple and Linux - and these work like a charm and are completely free.

    This is part of the "Limited integrations" bullet point which is also part of the "Proton Mail downsides". That doesn't make any sense. Tuta is saying that Proton has limited integrations with third-party email clients and services (which is true), whereas Tuta has none... And regarding their "and these work like a charm" claim, sorry, but being a Tuta client since our creation in 2021, we have encountered numerous serious bugs. Like having sent emails ending up in both "Draft" and "Sent" folders with no way to know if the emails have actually been sent, the impossibility to change the language of the spell checker, getting a empty calendar because of a slow internet connection in a train whereas it is supposed to be offline-first, lost all our contact notes...

    > Proton is a good choice if you’re looking for an end-to-end encrypted email provider, but it is not worth it if you compare it to Tuta Mail, the most secure quantum-proof email provider.

    And there comes the inevitable conclusion that we all saw coming: "we are the best". It is the part that annoys us the most, because we are security practitioners, and we don't like false claims.

    First, after 5 years of professional activity, and 10+ years with a personal account for our CEO, the amount of E2EE'd emails we have sent and received must represent roughly 1% of our exchanges (we use emails mostly for external communications). This is because Tuta made the choice to use a home-brewed implementation that only works between Tuta users. You like it or not, but the only standard for email encryption remains OpenPGP, which is annoying to use with the Tuta client. When we report security vulnerabilities to third-parties for example, we need to write and encrypt our emails in a separate text editor, encrypt them (we use @QubesOS Split GPG implementation to keep our private keys in a separate, offline, environment), and paste the result in the Tuta client...

    Also, Tuta keeps talking about being an "quantum-proof email provider", but guess what? Thanks to RFC 9980, OpenPGP is quantum-proof too, meaning anyone using OpenPGP can benefit from it, including Proton:

    proton.me/blog/introducing-pos

    Besides, it is a nice thing to have a strong encryption on the paper, but the implementation needs to be regularly checked for bugs and vulnerabilities. As far as we know, Tuta has never published any audit report, unlike Proton (which also has a bug bounty program: proton.me/security/bug-bounty).

    When you do E2EE, you also need to make sure you are talking to the intended recipient, which means you need a way to verify their cryptographic public key. It turns out it took Tuta 7 years to implement it after the issue was raised to them: github.com/tutao/tutanota/issu. It means that Tuta could read all the E2EE'd exchanges on their platform without anyone noticing. Additionally, their current implementation saves the verified fingerprints locally and per-device. And given that bugs in the Tuta client regularly require to erase all local data and log back in, key verification remains mostly a gadget.

    If you wonder how Proton does it: proton.me/support/address-veri, and proton.me/support/key-transpar.

    To conclude, are we saying that Tuta is a bad choice? No, we will still recommend actors like Tuta which are not part of surveillance capitalism. Are we recommending Proton over Tuta? Not necessarily, it depends on multiple factors and your threat model. But we urge Tuta to improve their communication by sticking to the facts, and stop acting as if they were doing everything better than others. Because they are not.

    #Tuta #Proton #Security #Privacy #Email #E2EE #PostQuantum #FOSS #EU

  18. Today, @Tutanota published a new blog post titled "Proton Mail vs Gmail: Which Is Best in 2026?". We generally don't pay attention to these biased marketing posts which end up always the same way ("neither, because we are the best"), but given the number of inaccuracies we found in it, we decided to take the time to comment it.

    tuta.com/blog/protonmail-vs-gm

    First of all, the post doesn't differentiate security from privacy. Even if the two notions are intertwined, it's still two different concepts.

    End-to-end encryption (E2EE) brings mainly privacy, that Gmail lacks heavily because it goes against Google's business model, but saying that having E2EE always brings you security is taking a shortcut. For example, most people are more exposed to email phishing than state actors' eavesdropping, and both Gmail and @protonprivacy are better at phishing detection than Tuta. We know it due to a simple fact: we recently launched a phishing simulation service (not launched publicly yet, still exploring with a few clients for now) 🙃

    > Like Tuta Mail, Proton Mail has become a popular email provider for individuals and organizations who prioritize privacy and security.

    This sentence tends to be understood as if Tuta preceded Proton in terms of market shares and technical standards. Also, from our experience, people tend to know Proton and not Tuta.

    > [...] introducing an AI email writer defies the purpose of a private, secure email service such as Proton Mail

    Even though we are against the current AI trend given its social and environmental impacts to keep it short, this sentence is also inaccurate. Scribe, Proton's writing assistant, can run locally on your own device:

    proton.me/support/proton-scrib.

    Besides, it's an opt-in feature, it is not enabled by default.

    > Users [of Proton] on the free email plan are limited to sending 150 emails daily.

    Well, at least Proton gives a straight answer regarding the daily limit on a free account. From Tuta's FAQ (tuta.com/support/howto#email-l):

    > If you receive the following message in your Tuta account "It looks like you exceeded the number of allowed emails. Please try again later.", the anti-spam protection method has stopped your account temporarily from sending new emails. Please wait a day or two to send new emails again.

    It seems there is no way to know if you are about to reach the limit before not being able to send emails for up to 2 days...

    > With the free Proton Mail account, users get 1 GB of storage space.

    We don't get it. It's listed in "Proton Mail downsides" whereas you also get 1 GB of storage with a free Tuta account... And with Proton, you can easily unlock 5 GB of storage with a free account...

    > [...] Tuta Mail, has decided not to build a bridge for third-party desktop clients but has instead focused on developing its own native email desktop clients for Windows, Apple and Linux - and these work like a charm and are completely free.

    This is part of the "Limited integrations" bullet point which is also part of the "Proton Mail downsides". That doesn't make any sense. Tuta is saying that Proton has limited integrations with third-party email clients and services (which is true), whereas Tuta has none... And regarding their "and these work like a charm" claim, sorry, but being a Tuta client since our creation in 2021, we have encountered numerous serious bugs. Like having sent emails ending up in both "Draft" and "Sent" folders with no way to know if the emails have actually been sent, the impossibility to change the language of the spell checker, getting a empty calendar because of a slow internet connection in a train whereas it is supposed to be offline-first, lost all our contact notes...

    > Proton is a good choice if you’re looking for an end-to-end encrypted email provider, but it is not worth it if you compare it to Tuta Mail, the most secure quantum-proof email provider.

    And there comes the inevitable conclusion that we all saw coming: "we are the best". It is the part that annoys us the most, because we are security practitioners, and we don't like false claims.

    First, after 5 years of professional activity, and 10+ years with a personal account for our CEO, the amount of E2EE'd emails we have sent and received must represent roughly 1% of our exchanges (we use emails mostly for external communications). This is because Tuta made the choice to use a home-brewed implementation that only works between Tuta users. You like it or not, but the only standard for email encryption remains OpenPGP, which is annoying to use with the Tuta client. When we report security vulnerabilities to third-parties for example, we need to write and encrypt our emails in a separate text editor, encrypt them (we use @QubesOS Split GPG implementation to keep our private keys in a separate, offline, environment), and paste the result in the Tuta client...

    Also, Tuta keeps talking about being an "quantum-proof email provider", but guess what? Thanks to RFC 9980, OpenPGP is quantum-proof too, meaning anyone using OpenPGP can benefit from it, including Proton:

    proton.me/blog/introducing-pos

    Besides, it is a nice thing to have a strong encryption on the paper, but the implementation needs to be regularly checked for bugs and vulnerabilities. As far as we know, Tuta has never published any audit report, unlike Proton (which also has a bug bounty program: proton.me/security/bug-bounty).

    When you do E2EE, you also need to make sure you are talking to the intended recipient, which means you need a way to verify their cryptographic public key. It turns out it took Tuta 7 years to implement it after the issue was raised to them: github.com/tutao/tutanota/issu. It means that Tuta could read all the E2EE'd exchanges on their platform without anyone noticing. Additionally, their current implementation saves the verified fingerprints locally and per-device. And given that bugs in the Tuta client regularly require to erase all local data and log back in, key verification remains mostly a gadget.

    If you wonder how Proton does it: proton.me/support/address-veri, and proton.me/support/key-transpar.

    To conclude, are we saying that Tuta is a bad choice? No, we will still recommend actors like Tuta which are not part of surveillance capitalism. Are we recommending Proton over Tuta? Not necessarily, it depends on multiple factors and your threat model. But we urge Tuta to improve their communication by sticking to the facts, and stop acting as if they were doing everything better than others. Because they are not.

    #Tuta #Proton #Security #Privacy #Email #E2EE #PostQuantum #FOSS #EU

  19. Today, @Tutanota published a new blog post titled "Proton Mail vs Gmail: Which Is Best in 2026?". We generally don't pay attention to these biased marketing posts which end up always the same way ("neither, because we are the best"), but given the number of inaccuracies we found in it, we decided to take the time to comment it.

    tuta.com/blog/protonmail-vs-gm

    First of all, the post doesn't differentiate security from privacy. Even if the two notions are intertwined, it's still two different concepts.

    End-to-end encryption (E2EE) brings mainly privacy, that Gmail lacks heavily because it goes against Google's business model, but saying that having E2EE always brings you security is taking a shortcut. For example, most people are more exposed to email phishing than state actors' eavesdropping, and both Gmail and @protonprivacy are better at phishing detection than Tuta. We know it due to a simple fact: we recently launched a phishing simulation service (not launched publicly yet, still exploring with a few clients for now) 🙃

    > Like Tuta Mail, Proton Mail has become a popular email provider for individuals and organizations who prioritize privacy and security.

    This sentence tends to be understood as if Tuta preceded Proton in terms of market shares and technical standards. Also, from our experience, people tend to know Proton and not Tuta.

    > [...] introducing an AI email writer defies the purpose of a private, secure email service such as Proton Mail

    Even though we are against the current AI trend given its social and environmental impacts to keep it short, this sentence is also inaccurate. Scribe, Proton's writing assistant, can run locally on your own device:

    proton.me/support/proton-scrib.

    Besides, it's an opt-in feature, it is not enabled by default.

    > Users [of Proton] on the free email plan are limited to sending 150 emails daily.

    Well, at least Proton gives a straight answer regarding the daily limit on a free account. From Tuta's FAQ (tuta.com/support/howto#email-l):

    > If you receive the following message in your Tuta account "It looks like you exceeded the number of allowed emails. Please try again later.", the anti-spam protection method has stopped your account temporarily from sending new emails. Please wait a day or two to send new emails again.

    It seems there is no way to know if you are about to reach the limit before not being able to send emails for up to 2 days...

    > With the free Proton Mail account, users get 1 GB of storage space.

    We don't get it. It's listed in "Proton Mail downsides" whereas you also get 1 GB of storage with a free Tuta account... And with Proton, you can easily unlock 5 GB of storage with a free account...

    > [...] Tuta Mail, has decided not to build a bridge for third-party desktop clients but has instead focused on developing its own native email desktop clients for Windows, Apple and Linux - and these work like a charm and are completely free.

    This is part of the "Limited integrations" bullet point which is also part of the "Proton Mail downsides". That doesn't make any sense. Tuta is saying that Proton has limited integrations with third-party email clients and services (which is true), whereas Tuta has none... And regarding their "and these work like a charm" claim, sorry, but being a Tuta client since our creation in 2021, we have encountered numerous serious bugs. Like having sent emails ending up in both "Draft" and "Sent" folders with no way to know if the emails have actually been sent, the impossibility to change the language of the spell checker, getting a empty calendar because of a slow internet connection in a train whereas it is supposed to be offline-first, lost all our contact notes...

    > Proton is a good choice if you’re looking for an end-to-end encrypted email provider, but it is not worth it if you compare it to Tuta Mail, the most secure quantum-proof email provider.

    And there comes the inevitable conclusion that we all saw coming: "we are the best". It is the part that annoys us the most, because we are security practitioners, and we don't like false claims.

    First, after 5 years of professional activity, and 10+ years with a personal account for our CEO, the amount of E2EE'd emails we have sent and received must represent roughly 1% of our exchanges (we use emails mostly for external communications). This is because Tuta made the choice to use a home-brewed implementation that only works between Tuta users. You like it or not, but the only standard for email encryption remains OpenPGP, which is annoying to use with the Tuta client. When we report security vulnerabilities to third-parties for example, we need to write and encrypt our emails in a separate text editor, encrypt them (we use @QubesOS Split GPG implementation to keep our private keys in a separate, offline, environment), and paste the result in the Tuta client...

    Also, Tuta keeps talking about being an "quantum-proof email provider", but guess what? Thanks to RFC 9980, OpenPGP is quantum-proof too, meaning anyone using OpenPGP can benefit from it, including Proton:

    proton.me/blog/introducing-pos

    Besides, it is a nice thing to have a strong encryption on the paper, but the implementation needs to be regularly checked for bugs and vulnerabilities. As far as we know, Tuta has never published any audit report, unlike Proton (which also has a bug bounty program: proton.me/security/bug-bounty).

    When you do E2EE, you also need to make sure you are talking to the intended recipient, which means you need a way to verify their cryptographic public key. It turns out it took Tuta 7 years to implement it after the issue was raised to them: github.com/tutao/tutanota/issu. It means that Tuta could read all the E2EE'd exchanges on their platform without anyone noticing. Additionally, their current implementation saves the verified fingerprints locally and per-device. And given that bugs in the Tuta client regularly require to erase all local data and log back in, key verification remains mostly a gadget.

    If you wonder how Proton does it: proton.me/support/address-veri, and proton.me/support/key-transpar.

    To conclude, are we saying that Tuta is a bad choice? No, we will still recommend actors like Tuta which are not part of surveillance capitalism. Are we recommending Proton over Tuta? Not necessarily, it depends on multiple factors and your threat model. But we urge Tuta to improve their communication by sticking to the facts, and stop acting as if they were doing everything better than others. Because they are not.

    #Tuta #Proton #Security #Privacy #Email #E2EE #PostQuantum #FOSS #EU

  20. Today, @Tutanota published a new blog post titled "Proton Mail vs Gmail: Which Is Best in 2026?". We generally don't pay attention to these biased marketing posts which end up always the same way ("neither, because we are the best"), but given the number of inaccuracies we found in it, we decided to take the time to comment it.

    tuta.com/blog/protonmail-vs-gm

    First of all, the post doesn't differentiate security from privacy. Even if the two notions are intertwined, it's still two different concepts.

    End-to-end encryption (E2EE) brings mainly privacy, that Gmail lacks heavily because it goes against Google's business model, but saying that having E2EE always brings you security is taking a shortcut. For example, most people are more exposed to email phishing than state actors' eavesdropping, and both Gmail and @protonprivacy are better at phishing detection than Tuta. We know it due to a simple fact: we recently launched a phishing simulation service (not launched publicly yet, still exploring with a few clients for now) 🙃

    > Like Tuta Mail, Proton Mail has become a popular email provider for individuals and organizations who prioritize privacy and security.

    This sentence tends to be understood as if Tuta preceded Proton in terms of market shares and technical standards. Also, from our experience, people tend to know Proton and not Tuta.

    > [...] introducing an AI email writer defies the purpose of a private, secure email service such as Proton Mail

    Even though we are against the current AI trend given its social and environmental impacts to keep it short, this sentence is also inaccurate. Scribe, Proton's writing assistant, can run locally on your own device:

    proton.me/support/proton-scrib.

    Besides, it's an opt-in feature, it is not enabled by default.

    > Users [of Proton] on the free email plan are limited to sending 150 emails daily.

    Well, at least Proton gives a straight answer regarding the daily limit on a free account. From Tuta's FAQ (tuta.com/support/howto#email-l):

    > If you receive the following message in your Tuta account "It looks like you exceeded the number of allowed emails. Please try again later.", the anti-spam protection method has stopped your account temporarily from sending new emails. Please wait a day or two to send new emails again.

    It seems there is no way to know if you are about to reach the limit before not being able to send emails for up to 2 days...

    > With the free Proton Mail account, users get 1 GB of storage space.

    We don't get it. It's listed in "Proton Mail downsides" whereas you also get 1 GB of storage with a free Tuta account... And with Proton, you can easily unlock 5 GB of storage with a free account...

    > [...] Tuta Mail, has decided not to build a bridge for third-party desktop clients but has instead focused on developing its own native email desktop clients for Windows, Apple and Linux - and these work like a charm and are completely free.

    This is part of the "Limited integrations" bullet point which is also part of the "Proton Mail downsides". That doesn't make any sense. Tuta is saying that Proton has limited integrations with third-party email clients and services (which is true), whereas Tuta has none... And regarding their "and these work like a charm" claim, sorry, but being a Tuta client since our creation in 2021, we have encountered numerous serious bugs. Like having sent emails ending up in both "Draft" and "Sent" folders with no way to know if the emails have actually been sent, the impossibility to change the language of the spell checker, getting a empty calendar because of a slow internet connection in a train whereas it is supposed to be offline-first, lost all our contact notes...

    > Proton is a good choice if you’re looking for an end-to-end encrypted email provider, but it is not worth it if you compare it to Tuta Mail, the most secure quantum-proof email provider.

    And there comes the inevitable conclusion that we all saw coming: "we are the best". It is the part that annoys us the most, because we are security practitioners, and we don't like false claims.

    First, after 5 years of professional activity, and 10+ years with a personal account for our CEO, the amount of E2EE'd emails we have sent and received must represent roughly 1% of our exchanges (we use emails mostly for external communications). This is because Tuta made the choice to use a home-brewed implementation that only works between Tuta users. You like it or not, but the only standard for email encryption remains OpenPGP, which is annoying to use with the Tuta client. When we report security vulnerabilities to third-parties for example, we need to write and encrypt our emails in a separate text editor, encrypt them (we use @QubesOS Split GPG implementation to keep our private keys in a separate, offline, environment), and paste the result in the Tuta client...

    Also, Tuta keeps talking about being an "quantum-proof email provider", but guess what? Thanks to RFC 9980, OpenPGP is quantum-proof too, meaning anyone using OpenPGP can benefit from it, including Proton:

    proton.me/blog/introducing-pos

    Besides, it is a nice thing to have a strong encryption on the paper, but the implementation needs to be regularly checked for bugs and vulnerabilities. As far as we know, Tuta has never published any audit report, unlike Proton (which also has a bug bounty program: proton.me/security/bug-bounty).

    When you do E2EE, you also need to make sure you are talking to the intended recipient, which means you need a way to verify their cryptographic public key. It turns out it took Tuta 7 years to implement it after the issue was raised to them: github.com/tutao/tutanota/issu. It means that Tuta could read all the E2EE'd exchanges on their platform without anyone noticing. Additionally, their current implementation saves the verified fingerprints locally and per-device. And given that bugs in the Tuta client regularly require to erase all local data and log back in, key verification remains mostly a gadget.

    If you wonder how Proton does it: proton.me/support/address-veri, and proton.me/support/key-transpar.

    To conclude, are we saying that Tuta is a bad choice? No, we will still recommend actors like Tuta which are not part of surveillance capitalism. Are we recommending Proton over Tuta? Not necessarily, it depends on multiple factors and your threat model. But we urge Tuta to improve their communication by sticking to the facts, and stop acting as if they were doing everything better than others. Because they are not.

    #Tuta #Proton #Security #Privacy #Email #E2EE #PostQuantum #FOSS #EU

  21. For people like me who are obsessed with details, the blog post is a long and fun read.

    Not that it is in any corporates' interest to allow their customers to encrypt communications entirely, but signal's work on encryption is worthy to be a product of its own.

    mastodon.world/@signalapp/1170

    #tech #encryption #E2EE #signal

  22. For people like me who are obsessed with details, the blog post is a long and fun read.

    Not that it is in any corporates' interest to allow their customers to encrypt communications entirely, but signal's work on encryption is worthy to be a product of its own.

    mastodon.world/@signalapp/1170

    #tech #encryption #E2EE #signal

  23. For people like me who are obsessed with details, the blog post is a long and fun read.

    Not that it is in any corporates' interest to allow their customers to encrypt communications entirely, but signal's work on encryption is worthy to be a product of its own.

    mastodon.world/@signalapp/1170

    #tech #encryption #E2EE #signal

  24. For people like me who are obsessed with details, the blog post is a long and fun read.

    Not that it is in any corporates' interest to allow their customers to encrypt communications entirely, but signal's work on encryption is worthy to be a product of its own.

    mastodon.world/@signalapp/1170

    #tech #encryption #E2EE #signal

  25. For people like me who are obsessed with details, the blog post is a long and fun read.

    Not that it is in any corporates' interest to allow their customers to encrypt communications entirely, but signal's work on encryption is worthy to be a product of its own.

    mastodon.world/@signalapp/1170

    #tech #encryption #E2EE #signal

  26. RE: toot.fedilab.app/@apps/1170784

    I built #FediHood on the #Mastodon API, so you can connect your account with any Mastodon-compatible app, such as #Fedilab.
    Fedilab will soon support the extra features at the heart of the project: finding people nearby by city via #OSM, and using #E2EE DMs.

  27. RE: toot.fedilab.app/@apps/1170784

    I built #FediHood on the #Mastodon API, so you can connect your account with any Mastodon-compatible app, such as #Fedilab.
    Fedilab will soon support the extra features at the heart of the project: finding people nearby by city via #OSM, and using #E2EE DMs.

  28. RE: toot.fedilab.app/@apps/1170784

    I built #FediHood on the #Mastodon API, so you can connect your account with any Mastodon-compatible app, such as #Fedilab.
    Fedilab will soon support the extra features at the heart of the project: finding people nearby by city via #OSM, and using #E2EE DMs.

  29. RE: toot.fedilab.app/@apps/1170784

    I built #FediHood on the #Mastodon API, so you can connect your account with any Mastodon-compatible app, such as #Fedilab.
    Fedilab will soon support the extra features at the heart of the project: finding people nearby by city via #OSM, and using #E2EE DMs.

  30. RE: toot.fedilab.app/@apps/1170784

    I built #FediHood on the #Mastodon API, so you can connect your account with any Mastodon-compatible app, such as #Fedilab.
    Fedilab will soon support the extra features at the heart of the project: finding people nearby by city via #OSM, and using #E2EE DMs.

  31. #FediHood is now available!

    Talk with people near you. A local chat on the #Fediverse where you share only your city, never your exact location. You adjust your timeline with distance and topic filters.

    It's in early beta and web only for now. It connects to the whole Fediverse, and you can send #E2EE DMs between FediHood and Holos users. The source code will be published soon. Don't hesitate to share!

    Instance: fedihood.social

  32. #FediHood is now available!

    Talk with people near you. A local chat on the #Fediverse where you share only your city, never your exact location. You adjust your timeline with distance and topic filters.

    It's in early beta and web only for now. It connects to the whole Fediverse, and you can send #E2EE DMs between FediHood and Holos users. The source code will be published soon. Don't hesitate to share!

    Instance: fedihood.social

  33. #FediHood is now available!

    Talk with people near you. A local chat on the #Fediverse where you share only your city, never your exact location. You adjust your timeline with distance and topic filters.

    It's in early beta and web only for now. It connects to the whole Fediverse, and you can send #E2EE DMs between FediHood and Holos users. The source code will be published soon. Don't hesitate to share!

    Instance: fedihood.social

  34. #FediHood is now available!

    Talk with people near you. A local chat on the #Fediverse where you share only your city, never your exact location. You adjust your timeline with distance and topic filters.

    It's in early beta and web only for now. It connects to the whole Fediverse, and you can send #E2EE DMs between FediHood and Holos users. The source code will be published soon. Don't hesitate to share!

    Instance: fedihood.social

  35. #FediHood is now available!

    Talk with people near you. A local chat on the #Fediverse where you share only your city, never your exact location. You adjust your timeline with distance and topic filters.

    It's in early beta and web only for now. It connects to the whole Fediverse, and you can send #E2EE DMs between FediHood and Holos users. The source code will be published soon. Don't hesitate to share!

    Instance: fedihood.social

  36. RE: mstdn.ca/@theyycmonk/116925718

    #espionage #surveillance #messaging #E2EE #securemessaging #securemessengers #BoycottUSA #BoycottAmerica #boycotttechbros

    Signal isn't *really* safe for Canadians. Signal is headquartered in the USA which makes it subject to FISA & THE CLOUD ACT which means you are a target of the NSA, who by their own admission "collect everything". They may not be able to get more than metadata for now but that can change any day. And metadata alone has been enough for the USA to order drone strike assassinations. Metadata can be used to map out all your contacts and family and loved ones. Why trust Trumpistan at all?

    Wire is safer for Canadians. Not Signal's fault, it's just the way it is because they are subject to laws that force them to comply with american spy agencies and makes it illegal for them to acknowledge/announce that they are complying.

  37. RE: mstdn.ca/@theyycmonk/116925718

    #espionage #surveillance #messaging #E2EE #securemessaging #securemessengers #BoycottUSA #BoycottAmerica #boycotttechbros

    Signal isn't *really* safe for Canadians. Signal is headquartered in the USA which makes it subject to FISA & THE CLOUD ACT which means you are a target of the NSA, who by their own admission "collect everything". They may not be able to get more than metadata for now but that can change any day. And metadata alone has been enough for the USA to order drone strike assassinations. Metadata can be used to map out all your contacts and family and loved ones. Why trust Trumpistan at all?

    Wire is safer for Canadians. Not Signal's fault, it's just the way it is because they are subject to laws that force them to comply with american spy agencies and makes it illegal for them to acknowledge/announce that they are complying.

  38. RE: mstdn.ca/@theyycmonk/116925718

    #espionage #surveillance #messaging #E2EE #securemessaging #securemessengers #BoycottUSA #BoycottAmerica #boycotttechbros

    Signal isn't *really* safe for Canadians. Signal is headquartered in the USA which makes it subject to FISA & THE CLOUD ACT which means you are a target of the NSA, who by their own admission "collect everything". They may not be able to get more than metadata for now but that can change any day. And metadata alone has been enough for the USA to order drone strike assassinations. Metadata can be used to map out all your contacts and family and loved ones. Why trust Trumpistan at all?

    Wire is safer for Canadians. Not Signal's fault, it's just the way it is because they are subject to laws that force them to comply with american spy agencies and makes it illegal for them to acknowledge/announce that they are complying.

  39. Слабосолёный мессенджер из MikroTik CHR и Java, по домашнему

    Как это? У вас есть аккаунт на хабре, есть своё мнение по каждой статье, есть желание этим мнением поделиться с дедушкой, но нет своего мессенджера чтоб это сделать? Срочно исправляем. Lim (local ip messenger) работает в вашей локальной сети, на вашем CHR или ARM64 роутере Mikrotik, без внешних сервисов. Обмен текстовыми и голосовыми сообщениями, файлами до 50мб. Публичным ключом собеседника шифруются: сообщения, файлы и имена файлов. И кнопка "Отправить", тоже зашифрована. Приготовить дома самому

    habr.com/ru/articles/1068722/

    #сетевое_оборудование #mikrotik #diy_или_сделай_сам #android #java #routeros #selfhosted #e2ee #локальная_сеть #мессенджер

  40. Слабосолёный мессенджер из MikroTik CHR и Java, по домашнему

    Как это? У вас есть аккаунт на хабре, есть своё мнение по каждой статье, есть желание этим мнением поделиться с дедушкой, но нет своего мессенджера чтоб это сделать? Срочно исправляем. Lim (local ip messenger) работает в вашей локальной сети, на вашем CHR или ARM64 роутере Mikrotik, без внешних сервисов. Обмен текстовыми и голосовыми сообщениями, файлами до 50мб. Публичным ключом собеседника шифруются: сообщения, файлы и имена файлов. И кнопка "Отправить", тоже зашифрована. Приготовить дома самому

    habr.com/ru/articles/1068722/

    #сетевое_оборудование #mikrotik #diy_или_сделай_сам #android #java #routeros #selfhosted #e2ee #локальная_сеть #мессенджер

  41. Слабосолёный мессенджер из MikroTik CHR и Java, по домашнему

    Как это? У вас есть аккаунт на хабре, есть своё мнение по каждой статье, есть желание этим мнением поделиться с дедушкой, но нет своего мессенджера чтоб это сделать? Срочно исправляем. Lim (local ip messenger) работает в вашей локальной сети, на вашем CHR или ARM64 роутере Mikrotik, без внешних сервисов. Обмен текстовыми и голосовыми сообщениями, файлами до 50мб. Публичным ключом собеседника шифруются: сообщения, файлы и имена файлов. И кнопка "Отправить", тоже зашифрована. Приготовить дома самому

    habr.com/ru/articles/1068722/

    #сетевое_оборудование #mikrotik #diy_или_сделай_сам #android #java #routeros #selfhosted #e2ee #локальная_сеть #мессенджер

  42. #FediHood and #HolosSocial, two separate #Fediverse projects (that I maintain), can now send each other #E2EE DMs, fully over #ActivityPub.

  43. #FediHood and #HolosSocial, two separate #Fediverse projects (that I maintain), can now send each other #E2EE DMs, fully over #ActivityPub.

  44. #FediHood and #HolosSocial, two separate #Fediverse projects (that I maintain), can now send each other #E2EE DMs, fully over #ActivityPub.

  45. #FediHood and #HolosSocial, two separate #Fediverse projects (that I maintain), can now send each other #E2EE DMs, fully over #ActivityPub.

  46. #FediHood and #HolosSocial, two separate #Fediverse projects (that I maintain), can now send each other #E2EE DMs, fully over #ActivityPub.

  47. @RoastbeefHashTag Howdy! What do you want to know?

    The good: Bonfire and #Emissary delivered interoperable prototypes at the end of June.

    The bad: With this experience, we're still updating the protocol to account for some very specific encryption/delivery issues. So, we haven't launched #E2EE on our own servers.

    So, Emissary's (my) messenger is actually live, and usable on Bandwagon.fm -- however, it's only trading *unencrypted* messages for now, until we lock down some protocol decisions.

  48. @RoastbeefHashTag Howdy! What do you want to know?

    The good: Bonfire and #Emissary delivered interoperable prototypes at the end of June.

    The bad: With this experience, we're still updating the protocol to account for some very specific encryption/delivery issues. So, we haven't launched #E2EE on our own servers.

    So, Emissary's (my) messenger is actually live, and usable on Bandwagon.fm -- however, it's only trading *unencrypted* messages for now, until we lock down some protocol decisions.

  49. @RoastbeefHashTag Howdy! What do you want to know?

    The good: Bonfire and #Emissary delivered interoperable prototypes at the end of June.

    The bad: With this experience, we're still updating the protocol to account for some very specific encryption/delivery issues. So, we haven't launched #E2EE on our own servers.

    So, Emissary's (my) messenger is actually live, and usable on Bandwagon.fm -- however, it's only trading *unencrypted* messages for now, until we lock down some protocol decisions.

  50. @RoastbeefHashTag Howdy! What do you want to know?

    The good: Bonfire and #Emissary delivered interoperable prototypes at the end of June.

    The bad: With this experience, we're still updating the protocol to account for some very specific encryption/delivery issues. So, we haven't launched #E2EE on our own servers.

    So, Emissary's (my) messenger is actually live, and usable on Bandwagon.fm -- however, it's only trading *unencrypted* messages for now, until we lock down some protocol decisions.

  51. @RoastbeefHashTag Howdy! What do you want to know?

    The good: Bonfire and #Emissary delivered interoperable prototypes at the end of June.

    The bad: With this experience, we're still updating the protocol to account for some very specific encryption/delivery issues. So, we haven't launched #E2EE on our own servers.

    So, Emissary's (my) messenger is actually live, and usable on Bandwagon.fm -- however, it's only trading *unencrypted* messages for now, until we lock down some protocol decisions.