Live data from Hacker News

German court forces mail provider Tutanota to insert a backdoor

heise.de

81–90 of 103 posts

Re: German court forces mail provider Tutanota to insert a backdoor

#81

Encryption is the only thing that forces law enforcement to use warrants, without it it's just a wild wild west of privacy abuse. I do hope we see more services crop up, and new methods for people to encrypt email outside of specific services, maybe better plugins for Thunderbird or something, hell I'd easily pay for such a plugin if someone else can communicate back and forth with me through it and it is encrypted.…

We generally accept that warrants are a reasonable solution when it comes to the state entering private property without permission for law enforcement purposes. This also seems like a reasonable solution for encryption. The state here is not making or trying to make encryption illegal; and it is open about the fact that court authorisation is required to enforce a backdoor.

> We generally accept that warrants are a reasonable solution

"We" accept nothing. The state can't execute warrants to get at what's inside people's minds. Computers are extensions of people's minds and I expect them to be equally inviolable.

Also, even if it does have lawful access to the system, the state is not entitled to finding usable evidence.

> it is open about the fact that court authorisation is required to enforce a backdoor

There mere possibility of a court-mandated backdoor means the entire system is already compromised and it's impossible to trust it.

Re: German court forces mail provider Tutanota to insert a backdoor

#82
post #51

Earlier quoted context omitted.

The reason that breaks down is that a backdoor to achieve this isn’t for that one case, it’s for everyone on the service (or easily made to be). It’s like getting permission to break every lock from a particular manufacturer, rather than permission to enter one particular home. I know in this particular case they’ve said it’s for a singular mailbox. I’m curious how they achieve it.

This sounds more like the analogy breaking down than illustrating a meaningful difference in scenarios. The police already /can/ break a lock from just about any manufacturer. They just break the door down and enter regardless of the phenomenal quality of the lock itself.

That’s exactly what I meant :)

Re: German court forces mail provider Tutanota to insert a backdoor

#83

Earlier quoted context omitted.

Sweden already is part of the EU.

I'm just saying that Sweden, Norway and Finland together would make an awesome couple; given how they overcame legislative issues and how they modernized their countries against all odds (with all that happened after 1808). From a political perspective they're quick to adapt to a changing landscape.

Sweden and Finland are both in the EU but AFAIK there's not much policy alignment between them with regards to EU legislation.

Re: German court forces mail provider Tutanota to insert a backdoor

#84

Clickbait verging on the fake news - they took piece of information completely out of the context and baked a "sensation". No, Tutanova does NOT install "backdoor" be it a court order or not. Government or else can only read contents of non-encrypted mails and only metadata of the encrypted mails, it has been so ever since and this is the way the email works. Clarification in plain English here https://www.reddit.com…

Both the article's title and its contents line up with what you're saying. I'm not seeing any clickbait here, save for perhaps the HN title.

Re: German court forces mail provider Tutanota to insert a backdoor

#85

I suppose the employees at Tutanota can do what the employees at Apple did: they could threaten to quit if they are instructed to work on this.

FWIW, Apple has backdoored iMessage's end-to-end encryption via iCloud Backup plaintext/key escrow, automatically on by default, so if people did quit or threaten to quit, it didn't actually stop or change anything.

Apparently Apple was going to fix this glaring hole in their cryptosystem, but Apple Legal killed it as a favor to the FBI.

https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

Re: German court forces mail provider Tutanota to insert a backdoor

#87

Earlier quoted context omitted.

We generally accept that warrants are a reasonable solution when it comes to the state entering private property without permission for law enforcement purposes. This also seems like a reasonable solution for encryption. The state here is not making or trying to make encryption illegal; and it is open about the fact that court authorisation is required to enforce a backdoor.

> We generally accept that warrants are a reasonable solution "We" accept nothing. The state can't execute warrants to get at what's inside people's minds. Computers are extensions of people's minds and I expect them to be equally inviolable. Also, even if it does have lawful access to the system, the state is not entitled to finding usable evidence. > it is open about the fact that court authorisation is required to…

> Computers are extensions of people's minds and I expect them to be equally inviolable.

This is not a statement of fact and is generally a minority opinion.

Re: German court forces mail provider Tutanota to insert a backdoor

#88

Earlier quoted context omitted.

We generally accept that warrants are a reasonable solution when it comes to the state entering private property without permission for law enforcement purposes. This also seems like a reasonable solution for encryption. The state here is not making or trying to make encryption illegal; and it is open about the fact that court authorisation is required to enforce a backdoor.

> We generally accept that warrants are a reasonable solution "We" accept nothing. The state can't execute warrants to get at what's inside people's minds. Computers are extensions of people's minds and I expect them to be equally inviolable. Also, even if it does have lawful access to the system, the state is not entitled to finding usable evidence. > it is open about the fact that court authorisation is required to…

You misrepresented what I said by removing the conditional part of the sentence - that's a misquote.

>There mere possibility of a court-mandated backdoor means the entire system is already compromised and it's impossible to trust it.

So then you should trust literally no software or hardware.

Re: German court forces mail provider Tutanota to insert a backdoor

#89
post #5

I almost got Tutanota, I went with runbox. It is based off Norway, hopefully this ruling will not applicable for other email companies with EU.

Fun fact: Norway is not a member of the EU.

Norway is also a member of NATO which could subject it to additional pressures (same applies to other member states).

Re: German court forces mail provider Tutanota to insert a backdoor

#90
post #86
post #12

I was planning to migrate to Tutanota, I guess I will not be doing so after all

This vulnerability exists for all email hosts. There is no way for a provider to prove to you they didn't silently escrow your plaintext.

If I read Tutanota's explanation of encryption correctly, messages sent between users are encrypted on the client side. While it would be obvious in network traffic if they sent back plain text to their server, it is possible to encrypt txt with multiple keys, ie their key as well as the intended recipient's. Would something like that be able to be detected on the client side, in particular for one user? I'm guessing yes but it would require verifying the js everytime you used their service, right? (asking)

(added 'correctly')

Post reply on HN