this post was submitted on 29 Jul 2023
87 points (97.8% liked)

DeGoogle Yourself

8799 readers
2 users here now

A community for those that would like to get away from Google.

Here you may post anything related to DeGoogling, why we should do it or good software alternatives!

Rules

  1. Be respectful even in disagreement

  2. No advertising unless it is very relevent and justified. Do not do this excessively.

  3. No low value posts / memes. We or you need to learn, or discuss something.

Related communities

[email protected] [email protected] [email protected] [email protected] [email protected] [email protected]

founded 4 years ago
MODERATORS
 

This guy can be pretty harsh at times, but he's clearly very knowledgeable..

However, not all providers have a recent review, and his priorities are skewed heavily to the "paranoid" side of the tech world. For example, he considers being able to mail cash to a provider a significant pro. The overwhelming majority of users aren't mailing cash to pay for their email.

Overall, it's good info that's worth sharing.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 9 points 1 year ago (2 children)

Seems a bit nearsighted to accuse every service of malice and then completely ignore that tutanota fixes lackluster pgp encryption by also encrypting the subject line.

This works virtually identically between both providers, except that Tutanota encrypts both the message body and subject line, whereas ProtonMail only encrypts the message body. This doesn't pose a huge risk if you use the former service. Just make sure that your subject lines don't contain any sensitive information. source

[–] [email protected] 4 points 1 year ago (1 children)
[–] [email protected] 2 points 1 year ago* (last edited 1 year ago) (1 children)

Not sure if this is entirely true, it is possible Proton mail is encrypting everything at rest (with the users public key) and only following PGP mail limitations during transit.

Like for example plaintext emails are encrypted at rest on Proton mail, what isn't ideally (compared to e2ee) but still minimizes the attack surface.

Actually for reference this is exactly the case

Message storage All messages in your Proton Mail mailbox are stored with zero-access encryption. This means we cannot read any of your messages or hand them over to third parties. This includes messages sent to you by non-Proton Mail users, although keep in mind if an email is sent to you from Gmail, Gmail likely retains a copy of that message as well. Password-protected Emails are also stored end-to-end encrypted. Subject lines and recipient/sender email addresses are encrypted but not end-to-end encrypted.

https://proton.me/support/proton-mail-encryption-explained

[–] [email protected] 2 points 1 year ago

Cool, thank you for clearing that up!

[–] [email protected] 2 points 1 year ago

I do like Tutanota's approach to encryption, but communication outside of other Tutanota addresses is less secure than PGP. It's just a symmetric, password-based scheme.

Since you will probably deal with a lot of non-tuta email providers, it's a hard sell for me. In network, though, it's good.

Second issue I had with it was the email client. I like my third party client and it's built into my workflow. Tuta doesn't support third party clients because they consider the storage of emails on your local drive a security risk. (That's only true if your hard drive isn't encrypted, and setting up encryption isn't all that hard to do)