Live data from Hacker News

German court forces mail provider Tutanota to insert a backdoor

heise.de

1–10 of 103 posts

Re: German court forces mail provider Tutanota to insert a backdoor

#2
Encryption is the only thing that forces law enforcement to use warrants, without it it's just a wild wild west of privacy abuse. I do hope we see more services crop up, and new methods for people to encrypt email outside of specific services, maybe better plugins for Thunderbird or something, hell I'd easily pay for such a plugin if someone else can communicate back and forth with me through it and it is encrypted. Maybe even some sort of forward secrecy involved in the system.

Re: German court forces mail provider Tutanota to insert a backdoor

#3
(I used Google translate to some quotes might not be 100% correct)

> "We therefore had to start developing the monitoring function"

Ouch, pretty hard to recommend a service that has admitted to building tools for LE.

> This should not change anything for other users; their emails should continue to be encrypted by default. Nevertheless, Tutanota sees a one-time bypassing of encryption as a data protection and security risk for all customers.

> As Tutanota emphasized, the surveillance measure only affects newly incoming unencrypted e-mails. The company cannot decrypt already encrypted data or end-to-end encrypted e-mails in Tutanota.

It's a bit unclear here if it only means plaintext, incoming emails are effected while in transit or if all new plaintext emails are/could be saved without encryption.

Re: German court forces mail provider Tutanota to insert a backdoor

#4
A relevant machine-translated paragraph appears to indicate that they are only required to implement monitoring of a single mailbox:

> This is about a blackmail that had been sent to an automotive supplier from a Tutanota mailbox. Tutanota is now forced to program a function by the end of the year that allows the State Criminal Police Office of North Rhine-Westphalia to monitor this mailbox.

Lacking the ability to read this without translation, I cannot determine conclusively whether or not they're also required to preemptively retain plaintext emails for other mailboxes in order to support any future wiretapping requests.

Re: German court forces mail provider Tutanota to insert a backdoor

#6
I worked in the telecom industry, and knowing how much surveillance related regulations was there, I can't believe true e2e encryption is a thing on the internet.

I'm surprised how so many people in tech believe that a messaging application like WhatsApp is allowed to have real e2e encryption. It's impossible for regulators to ignore a platform with substantial traffic.

Re: German court forces mail provider Tutanota to insert a backdoor

#7

A relevant machine-translated paragraph appears to indicate that they are only required to implement monitoring of a single mailbox: > This is about a blackmail that had been sent to an automotive supplier from a Tutanota mailbox. Tutanota is now forced to program a function by the end of the year that allows the State Criminal Police Office of North Rhine-Westphalia to monitor this mailbox. Lacking the ability to re…

My understanding is that they are only required to monitor a single specific mailbox (for which a court order has been issued) - so no preemptive collection.

Re: German court forces mail provider Tutanota to insert a backdoor

#8

(I used Google translate to some quotes might not be 100% correct) > "We therefore had to start developing the monitoring function" Ouch, pretty hard to recommend a service that has admitted to building tools for LE. > This should not change anything for other users; their emails should continue to be encrypted by default. Nevertheless, Tutanota sees a one-time bypassing of encryption as a data protection and securit…

> pretty hard to recommend a service that has admitted to building tools for LE

As opposed to the ones that build and won't admit/can't admit?

Re: German court forces mail provider Tutanota to insert a backdoor

#9

A relevant machine-translated paragraph appears to indicate that they are only required to implement monitoring of a single mailbox: > This is about a blackmail that had been sent to an automotive supplier from a Tutanota mailbox. Tutanota is now forced to program a function by the end of the year that allows the State Criminal Police Office of North Rhine-Westphalia to monitor this mailbox. Lacking the ability to re…

The following (machine-translated) paragraph clears that up:

This should not change anything for the other users, their mails should continue to be encrypted by default. Nevertheless, Tutanota considers a one-time circumvention of the encryption to be a data protection and security risk for all customers.

[Update, 30.11., 12 o'clock] As Tutanota emphasized, the monitoring measure only affects newly incoming unencrypted e-mails. Already encrypted data as well as end-to-end encrypted e-mails in Tutanota cannot be decrypted by the company. [Update]

Re: German court forces mail provider Tutanota to insert a backdoor

#10

A relevant machine-translated paragraph appears to indicate that they are only required to implement monitoring of a single mailbox: > This is about a blackmail that had been sent to an automotive supplier from a Tutanota mailbox. Tutanota is now forced to program a function by the end of the year that allows the State Criminal Police Office of North Rhine-Westphalia to monitor this mailbox. Lacking the ability to re…

No, you got that right. It's about a single mailbox and only for new mails. As they can't decrypt old mails themselves without a backdoor.

Still, once they have this function, all it takes is a court order to start collecting for other mailboxes.

Tutanota will take this to the next higher court but as it says in the article, they have to start implementing the backdoor right away.

Post reply on HN