Secure email: Tutanota free encrypted email.
tutanota.com
external-link
Tutanota is the secure email service, built in Germany. Use encrypted emails on all devices with our open source email client, mobile apps & desktop clients.

Can’t believe this is real. But on a mass scale we can use FOSS with full encryption.

They did this before with the eliptic curve cryptography, and we knew it had this problem before it was implemented as a standard.

So if the NSA offers a standard, don’t trust it and include in your encryption software the option to use something different.

Rustmilian
link
fedilink
71Y

Good luck with that. FOSS is transparency on a source code level, there’s no obscurity they can hide their back door behind.

Rustmilian
link
fedilink
5
edit-2
1Y

You realize nobody would know about this in the first place if it was Proprietary, right?
FOSS allows for whistleblowers, scrutiny, and audits. Proprietary ‘security via obscurity’ does not.

I’m perfectly aware of all that. but cryptography is an extremely complicated discipline that even the most experienced mathematicians have a hard time to design and scrutinize an algorithm, they heavily rely on peer review. If one major institution like the NIST is biased by the NSA, they will have a bigger chance of compromising algorithms if that are their intentions.

Rustmilian
link
fedilink
3
edit-2
1Y

You’d be surprised what the world wide collective of Cryptographers are capable of when they’re able to scrutinize a project in the first place. Which would you prefer? A closed unscrutinizable encryption algorithm or one that’s entirely open from the ground up?
NIST could do damage if they’re biased, but it’s not like people aren’t keeping a close eye on them and scrutinizing as many mistakes as possible. Especially for an algorithm as globally important as PQC.

I’m totally against anything proprietary. That’s the first requisite for anything I use. And I’m not advocating for proprietary algorithms at all, that would be very much the demise of encryption.

I’m just worried that a sufficiently influent actor (let’s say a government) could theoretically bribe these institutions to promote weaker encryption standards. I’m not even saying they are trying to introduce backdoors, just that like the article suggest they might bias organizations to support weaker algorithms.

AES 128 bits is still considered secure in public institutions, when modern computers can do much stronger encryption without being noticeable slower.

Rustmilian
link
fedilink
2
edit-2
1Y

A huge amount of organization are already biased and using weaker algorithms… They just do so under the obscurity of proprietary software so it’s much harder to scrutinize them.

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 57 users / day
  • 383 users / week
  • 1.5K users / month
  • 5.7K users / 6 months
  • 1 subscriber
  • 2.97K Posts
  • 74.6K Comments
  • Modlog