Tuta Launches Post Quantum Cryptography For Email | Tuta
tuta.com
external-link
Tuta Mail enables TutaCrypt, a protocol to exchange messages using quantum-safe encryption.

Just in time for 10 years of Tuta/Tutanota, we are launching the most significant security upgrade of Tuta Mail with TutaCrypt. This groundbreaking post-quantum encryption protocol will secure emails with a hybrid protocol combining state-of-the-art quantum-safe algorithms with traditional algorithms (AES/ECC) making Tuta Mail the world’s first email provider that can protect emails from quantum computer attacks.

making Tuta Mail the world’s first email provider that can protect emails from quantum computer attacks.

I don’t see how mails are secured when being sended from or to a Tutanota user and to or from a non Tutanota user. Those mails are only secured on their servers.

If you, a non tuta user, receive a mail from a tuta user you only get a download link. Which at least protects the content but not the metadata that someone send you an email. If a non tuta user sends a mail to a tuta user, there isn’t much tuta can do unfortunately. I’m not quite sure how you expect tuta to do magic? They do what they can.

Quite a lot of cryptography detail in their blog post, not all of which do I understand. Curious to find out what the community thinks of this …

For instance:

We’ve re-built the Tuta cryptographic protocol from the ground up and are now upgrading our encryption using quantum-resistant algorithms together with conventional algorithms (Kyber in combination with AES 256 and ECDH x25519 in a hybrid protocol) for our asymmetric public key encryption of emails

I know Bruce Schneier says rolling your own Crypto is hard and most will get it wrong. So is it concerning that they made their own encryption protocol?

So, are they putting a piece of cardboard in front of a bullet-resistant door?

🤔

It sounds like they’re just encrypting it twice (once with each algorithm), but I could be wrong.

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 124 users / day
  • 1.05K users / week
  • 1.3K users / month
  • 4.58K users / 6 months
  • 1 subscriber
  • 3.9K Posts
  • 98.3K Comments
  • Modlog