@Tutanota @protonprivacy Besides, it's not the first time you attacked Proton while stating that you are "the world's most secure email". Do I have to remind you that you JUST released manual key verification whereas the issue was raised to you ~8 years ago? It means that until very recently, Tuta servers could easily MITM all the "post-quantum" end-to-end encrypted emails...
https://github.com/tutao/tutanota/issues/768
Proton went beyond manual verifications years ago with a blockchain: https://proton.me/support/key-transparency
@Tutanota @protonprivacy And since we're talking about security and privacy, let's continue...
#Security #Privacy #OpenSource #Transparency #ThreatModeling #Email #E2EE
@Tutanota @protonprivacy To be clear, my goal here isn't to take sides. In fact, I'm a loyal Tuta customer since 2016, for both my work and personal accounts. But as a security practitioner, I just cannot decently recommend your services to people with high security requirements, and I cannot stand your security theater any more. Be more humble and do what it takes to be the best if it's your goal.
#Security #Privacy #OpenSource #Transparency #TheatModeling #Email #E2EE #Tuta #Tutanota #Proton