I’ve been using Tutanota for a while now. Been interested in people’s opinions about Tutanota and Protonmail.
I’ve never used Tutanota but been a Proton Unlimited user for a few years now. I definitely like the mail service, and Drive and VPN are nice but can be slow, especially Drive. Everything else I don’t have much use for, and honestly I cringe when I see the new stuff they’re working on. Not that any of it’s bad, but it feels like they’re in the “can’t just make a good product” camp, constantly trying to add on new stuff instead of focusing on quality. Could have it all wrong, though, I’m just a person, not an analyst.
sanpo@sopuli.xyz 1 year ago
Tutanota doesn’t share their security audits, which Proton does.
Also, IIRC Tutanota uses their own custom encryption implementation, while Proton contributes to open source OpenPGP projects.
And when in the past the the Swiss gov ordered Proton to do some limited tracking for a specific user, after that they went to the court and succeeded in changing the law so it’s no longer possible to order this tracking.
Proton might not be ideal, but they seem to actually care about making the Internet a safer place.
Asudox@lemmy.world 1 year ago
I am sure that Tutanota does not use any custom encryption algorithm. It is clearly stated in the FAQ that they use RSA (with PFS) and AES to encrypt emails exchanged between Tutanota users.
sanpo@sopuli.xyz 1 year ago
I’m not really saying that what Tutanota does is insecure, but historically doing security on your own instead of using established standards has not been a winning move.
Plus their unwillingness to open source it and not sharing the audits just doesn’t inspire my confidence.
Overall they’re probably fine, but these are some of the main reasons I ultimately chose Proton instead.
BTW, they’re not “slowly developing” post-quantum encryption, they’re just saying they may do that at some point in the future - which everyone will have to do anyway when we get to this point.
dngray@lemmy.one 1 year ago
These are only primitive algorithms, the actual implementation is custom and specific to Tutanota, which mean it will only work with Tutanota as nothing else will implement it.
There is no way to do key distribution outside of Tutanota’s service.