Skip to main content


I hope to hear from @Tutanota very soon. Lack of key verification is a major flaw in the technical design of the platform, allowing a malicious Tuta server to read end-to-end encrypted exchanges (both emails and shared calendars).

github.com/tutao/tutanota/issu…

The issue has been opened 6 years ago.

#Security #Privacy #Crypto #Cryptography #Email #FOSS

in reply to Skyper πŸ’»πŸŽ§β˜•πŸ“–

Thanks for your comment. We agree that key verification is important & we have it on our roadmap. We are working on it already & we want to implement it in a way that works nicely together with key rotation. We enabled post-quantum encryption for new customers by the beginning of the year, now we are in the process of upgrading existing customers & then we will deploy key verification. We already mentioned key verification when releasing post quantum encryption tuta.com/blog/post-quantum-cry….
⇧