fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

11K
active users

Skyper 💻🎧☕📖

I hope to hear from @Tutanota very soon. Lack of key verification is a major flaw in the technical design of the platform, allowing a malicious Tuta server to read end-to-end encrypted exchanges (both emails and shared calendars).

github.com/tutao/tutanota/issu

The issue was opened 6 years ago.

@Skyper Thanks for your comment. We agree that key verification is important & we have it on our roadmap. We are working on it already & we want to implement it in a way that works nicely together with key rotation. We enabled post-quantum encryption for new customers by the beginning of the year, now we are in the process of upgrading existing customers & then we will deploy key verification. We already mentioned key verification when releasing post quantum encryption tuta.com/blog/post-quantum-cry.

TutaTuta Launches Post Quantum Cryptography For Email | TutaTuta Mail enables TutaCrypt, a protocol to exchange messages using quantum-safe encryption.