Live data from Hacker News

German court forces mail provider Tutanota to insert a backdoor

heise.de

21–30 of 103 posts

Re: German court forces mail provider Tutanota to insert a backdoor

#21

From my understanding of the article (non-native), it seems like it is only one specific mailbox that is to be monitored > "Tutanota sieht sich nun gezwungen, bis Jahresende eine Funktion zu programmieren...dieses Postfach zu überwachen." and that nothing else will change for the other users > "Für die anderen Nutzer soll sich dadurch nichts ändern, ihre Mails sollen weiter standardmäßig verschlüsselt werden" As othe…

[deleted]

Re: German court forces mail provider Tutanota to insert a backdoor

#22

(I used Google translate to some quotes might not be 100% correct) > "We therefore had to start developing the monitoring function" Ouch, pretty hard to recommend a service that has admitted to building tools for LE. > This should not change anything for other users; their emails should continue to be encrypted by default. Nevertheless, Tutanota sees a one-time bypassing of encryption as a data protection and securit…

> pretty hard to recommend a service that has admitted to building tools for LE As opposed to the ones that build and won't admit/can't admit?

True. Not much has really changed beyond more confirmation that anything plain text can be and will be fall into the hands of third party actor/government. Although certain jurisdictions at least in theory have barriers to this e.g Germany vs Switzerland.

Re: German court forces mail provider Tutanota to insert a backdoor

#23

From my understanding of the article (non-native), it seems like it is only one specific mailbox that is to be monitored > "Tutanota sieht sich nun gezwungen, bis Jahresende eine Funktion zu programmieren...dieses Postfach zu überwachen." and that nothing else will change for the other users > "Für die anderen Nutzer soll sich dadurch nichts ändern, ihre Mails sollen weiter standardmäßig verschlüsselt werden" As othe…

My German is extremely rusty, but the whole dispute here seems to stem from the discussion wether or not the company has to comply with what we normally call 'lawfull-intercept' as part of telecom regulations. They contest the notion that they are a telecom provider.

Re: German court forces mail provider Tutanota to insert a backdoor

#24
post #19
post #18

Earlier quoted context omitted.

German native here. Your translation is mostly correct. The court seems to have forced Tutanota to store new incoming non-encrypted emails in plaintext for a specific mailbox that was used to blackmail an automotive supplier. But the article is not entirely clear on whether that is for that specific mailbox only. At one point, the article mentions that storing emails in plain text could be used on "specific mailboxes…

IANAL, but if I am not mistaken, German law requires telecommunication providers (above a certain threshold) to provide law enforcement with a way to look into customer communication via the provider. Meaning here, they need to implement a way for law enforcement to look into any mailbox they can come up with a warrant for.

Correct but from the article

> So hatte im Sommer das Landgericht Hannover entschieden, dass Tutanota im rechtlichen Sinn keine „Telekommunikationsdienste“ erbringt oder daran mitwirkt – und deshalb auch nicht zur Telekommunikationsüberwachung verpflichtet werden kann

In the summer the Landgericht Hannover judged that Tutanota isn't a "Telekommunikationsdienste" (telecommunication providers) and they also don't take part in one. That is why Tutanota calls bullshit.

> Das Kölner Gericht sieht Tutanota dennoch als „Mitwirkenden“ bei der Erbringung von Telekommunikationsdiensten. Folglich müsse das Unternehmen die Überwachung ermöglichen.

Cologne now says the opposite and says they "take part" in providing telecommunication without clarification.

Re: German court forces mail provider Tutanota to insert a backdoor

#25
post #18

From my understanding of the article (non-native), it seems like it is only one specific mailbox that is to be monitored > "Tutanota sieht sich nun gezwungen, bis Jahresende eine Funktion zu programmieren...dieses Postfach zu überwachen." and that nothing else will change for the other users > "Für die anderen Nutzer soll sich dadurch nichts ändern, ihre Mails sollen weiter standardmäßig verschlüsselt werden" As othe…

German native here. Your translation is mostly correct. The court seems to have forced Tutanota to store new incoming non-encrypted emails in plaintext for a specific mailbox that was used to blackmail an automotive supplier. But the article is not entirely clear on whether that is for that specific mailbox only. At one point, the article mentions that storing emails in plain text could be used on "specific mailboxes…

> Für die anderen Nutzer soll sich dadurch nichts ändern, ihre Mails sollen weiter standardmäßig verschlüsselt werden.

They seem to suggest that it really only applies to this one specific inbox

Re: German court forces mail provider Tutanota to insert a backdoor

#26
post #6

I worked in the telecom industry, and knowing how much surveillance related regulations was there, I can't believe true e2e encryption is a thing on the internet. I'm surprised how so many people in tech believe that a messaging application like WhatsApp is allowed to have real e2e encryption. It's impossible for regulators to ignore a platform with substantial traffic.

You are right, and yet I always asked myself if all the regulations ever made sense.

Those that really want to coordinate any kind of illicit activity, do they use Whatsapp thinking it is secure, or would they be smart enough to set up their own infrastructure? How many threats were stopped due to police/Three-Letter-Agencies being able to tap into the largest services vs going to the deep web and infiltrating/investigating the group "in person"?

In any case, my feeling is that all these regulations do is push privacy-conscious people into running their own infra. I was even on the point of running my own email, Matrix and even a SIP server at home, but then I realized that whoever I will be communicating with would not be doing the same so the whole thing is at best an exercise in my sysadmin skills.

Re: German court forces mail provider Tutanota to insert a backdoor

#28
german here:

Tutanota is a german email provider which encrypts incoming email after those were received. The court ordered tutanota to provide incoming emails to a single email account to law enforcement. This is "lawful interception" as you know it, as "service-side encryption" is useless against lawful interception laws.

- md

Re: German court forces mail provider Tutanota to insert a backdoor

#30

From my understanding of the article (non-native), it seems like it is only one specific mailbox that is to be monitored > "Tutanota sieht sich nun gezwungen, bis Jahresende eine Funktion zu programmieren...dieses Postfach zu überwachen." and that nothing else will change for the other users > "Für die anderen Nutzer soll sich dadurch nichts ändern, ihre Mails sollen weiter standardmäßig verschlüsselt werden" As othe…

You are missing the entire point of why this is a horrible thing to begin with! They have to develop new encryption circumvention technology for this one surveillance which weakens encryption for everyone using the encryption technology.

Its exactly like if you were to force the creator of PGP to build a backdoored version of PGP with the right windows signatures or something. You could just say, "it will only be for new emails for the specific mailbox, as the rest are already encrypted", but then you are missing the point entirely.

BTW germany is currently in the process of shoving a new law though the EU which will effectively destroy all encrypted services in europe (by means of forcing backdoors/secondary keys). Just for context.

Post reply on HN