Tutanota likes to tell everyone that they are literally Signal in the email world in terms of security. But there is a known vulnerability in their "E2EE": https://github.com/tutao/tutanota/issues/768 There is no way to verify key fingerprint of your recipient right now. So server can just man-in-the-middle you providing third-party key and read all messages silently. It is not e2e encryption if you have to trust the…
It all comes down to truth in advertising. Such misrepresentations are very common these days. Even Signal is not entirely innocent here. Signal only has the potential to have end to end authentication/encryption. By default you trust Signal, Twilio and the phone company. The app/documentation does not make it entirely clear to the user that verifying the "Safety Number" is critical to establishing an end to end conn…
Understatement.
Tutanota published a ranty blog post accusing Microsoft of suppressing competition in the email space. Because they didn't understand how fucking Azure works or even how corporate security works.
They literally let users register email addresses for @tutanota.com At the same time, they are using @tutanota.com for internal corporate and such they had an Azure AD Tenant already registered for that domain.
They complained that their tutanota.com email users couldn't register Microsoft accounts and this was all part of Microsoft's ploy to eliminate them.
No, they compromised themselves and unless they grew a brain, are still compromised for corporate communications.