Live data from Hacker News

Tutanota is now Tuta

tuta.com

71–80 of 137 posts

Re: Tutanota is now Tuta

#71

Earlier quoted context omitted.

The main ones for me: - (To my knowledge) Tuta doesn't have secondary services like VPN, etc. - Tuta intentionally does not provide a bridge for email. So everything with their service has to be done through their apps. If you want to use your own email client or command line tools (such as for submitting patchsets to mailing lists), that's not an option.

"So everything with their service has to be done through their apps." What sane person would do this? Use infomaniak instead (Switzerland). Tuta seems to be a German company. There is another one, I forgot the name but a few friends of mine were using it. I used google, could not find it but I am actually surprised that there are many providers. E.g. https://www.qualityhosting.de/hosted-exchange/hosted-exchang... htt…

posteo has good pgp support and employs wkd for easy key discovery

Re: Tutanota is now Tuta

#72

I did search for E-Mail provider alternatives recently and came across a blog post by Drew DeVault: https://drewdevault.com/2020/06/19/Mail-service-provider-rec... He used to recommend mailbox.org and migadu. Two questions: 1) Does anyone know why he does not recommend Tuta(nota)? Edit: I missed the footnote > Do they make unfounded claims about security or privacy, or develop techniques which ultimately rely on trus…

cock.li is a pretty good E-Mail/VPS provider from what I heard. From their homepage:

> How can I trust you? You can't. Cock.li doesn't parse your E-mail to provide you with targeted ads, nor does cock.li read E-mail contents unless it's for a legal court order. However, it is 100% possible for me to read E-mail, and IMAP/SMTP doesn't provide user-side/client-side encryption, so you're just going to have to take my word for it. Any encryption implementation would still technically allow me to read E-mail, too. This was true for Lavabit as well -- while your E-mail was stored encrypted (only if you were a paid member, which most people forget), E-mail could still technically be intercepted while being received / sent (SMTP), or while being read by your mail client (IMAP). For privacy, we recommend encrypting your E-mails using PGP using a mail client add-on like Enigmail, or downloading your mail locally with POP and regularly deleting your mail from our server.

Also, there's this quote from /g/:

Administering a mail host is sort of like being a nurse; there's a brief period at the start when the thought of seeing people's privates might be vaguely titillating in a theoretical sense, but that sort of thing doesn't last long when it's up against the daily reality of shit, piss, blood, and vomit.

Now that I think about it, administering a mail host is exactly like being a nurse, only people die slightly less often.

--------------------------------

They also publish all emails/call recordings when dealing with law enforcement on their transparency page.

Re: Tutanota is now Tuta

#75
post #50

Earlier quoted context omitted.

What is $normalemailprovider? I have been looking for an alternative that is more standard, but it seems like only Fastmail is big in this space. The rest are small shops that don't convey a lot of confidence.

Not sure what qualifies as "normal", but I've been happy with mailfence.com for a few years now. I rarely see them mentioned in privacy lists, which I appreciate, as I don't want them to get too much attention. :) They're based in Belgium, and have a solid stance on privacy and security. They provide IMAP/SMTP access, calendar/CalDAV, contacts/CardDAV, custom domain names, filters, spam blocking, etc. It's a pretty w…

Yeah, no way mailfence is that privacy friendly. https://www.hindustantimes.com/cities/mumbai-news/how-cops-c...

The police were able to get a lot of info from mailfence to catch a stupid student who thought using a vpn and mailfence would enable him to send threats easily to the richest man in india. The police got info on how many accounts were from this country, how many of them were active, monitor the mail account for new mails etc..

Re: Tutanota is now Tuta

#76

I did search for E-Mail provider alternatives recently and came across a blog post by Drew DeVault: https://drewdevault.com/2020/06/19/Mail-service-provider-rec... He used to recommend mailbox.org and migadu. Two questions: 1) Does anyone know why he does not recommend Tuta(nota)? Edit: I missed the footnote > Do they make unfounded claims about security or privacy, or develop techniques which ultimately rely on trus…

Tuta is just weird. It's not really email, it's more like an encrypted chat. If you send a "mail" to someone who does not have tuta, guess what, they are invited to tuta xD

Not true! This only applies, if you sent an encrypted mail. Which makes sense I guess?

Re: Tutanota is now Tuta

#77
post #69

Earlier quoted context omitted.

Thanks for your feedback. We're planning to re-do the search implementation completely as it needs a major overhaul to quickly search larger mailboxes. We're constantly improving the service, for instance we've just added unlimited email addresses with your own domain ( https://tuta.com/blog/summer-releases-2023 ) so always happy to hear feedback and how we can meet your needs!

You are conveniently ignoring the comment mentioning your bad E2E implementation and commenting on other comments. Why?

Anyone could have registered an account with the name "Tutanota". It does not make sense to converse.

Re: Tutanota is now Tuta

#78

I did search for E-Mail provider alternatives recently and came across a blog post by Drew DeVault: https://drewdevault.com/2020/06/19/Mail-service-provider-rec... He used to recommend mailbox.org and migadu. Two questions: 1) Does anyone know why he does not recommend Tuta(nota)? Edit: I missed the footnote > Do they make unfounded claims about security or privacy, or develop techniques which ultimately rely on trus…

cock.li is a pretty good E-Mail/VPS provider from what I heard. From their homepage: > How can I trust you? You can't. Cock.li doesn't parse your E-mail to provide you with targeted ads, nor does cock.li read E-mail contents unless it's for a legal court order. However, it is 100% possible for me to read E-mail, and IMAP/SMTP doesn't provide user-side/client-side encryption, so you're just going to have to take my wo…

Ah yes the alt-right paradise. "@hitler.rocks" and "@nuke.africa" are really nice domain to have :) The administrator of cock.lu also famously hosted with oVo systems some more than sketchy boards.

Re: Tutanota is now Tuta

#80
post #61

Tutanota likes to tell everyone that they are literally Signal in the email world in terms of security. But there is a known vulnerability in their "E2EE": https://github.com/tutao/tutanota/issues/768 There is no way to verify key fingerprint of your recipient right now. So server can just man-in-the-middle you providing third-party key and read all messages silently. It is not e2e encryption if you have to trust the…

You can slap PGP on top Presto

Can you? It's arguably much more annoying than other providers because you can't use a normal email interface. I've been trying to switch off it for a while and just use a normal provider with simplelogin slapped in front. Also, the spam filter isn't very good.
Post reply on HN