User avatar
tungfa
Gold Bitcoiner
Gold Bitcoiner
Posts: 1825
Joined: Mon Oct 05, 2015 5:09 am

Donate BTC of your choice to 19j972c9zC2Gg7VGdSt6ujkCqvo2EBtj63

Contact: Website Facebook Twitter Telegram

Are you using Tutanota email ?

Sun Feb 07, 2016 3:01 pm

Are you using Tutanota email ?
please join the conversation:
https://tutanota.uservoice.com/forums/2 ... our-platfo

User avatar
BitcoinNewsMagazine
Nickel Bitcoiner
Nickel Bitcoiner
Posts: 217
Joined: Thu Sep 24, 2015 5:03 pm
Contact: Website Facebook Twitter

Re: Are you using Tutanota email ?

Sun Feb 07, 2016 5:25 pm

Email services like Tutanota may be convenient but you need to be aware of the security tradeoffs. Tutanota only uses 2048 bit encryption while experts like Snowden recommend 4096. You can easily use 4096 bit PGP yourself with a utility like gpg4usb.

As important as the strength of your encryption is metadata in email headers. Three letter agencies love collecting metadata which can often help identity the sender of an email. If you want to eliminate metadata you need to look into a provider like sigaint which strips metadata from your email headers and sends your email over the Tor network.

User avatar
BitcoinNewsMagazine
Nickel Bitcoiner
Nickel Bitcoiner
Posts: 217
Joined: Thu Sep 24, 2015 5:03 pm
Contact: Website Facebook Twitter

Re: Are you using Tutanota email ?

Mon Feb 08, 2016 6:57 pm

To reiterate that services using 2048 RSA encryption are no longer secure see the FAQ recently published by the NSA.

According to the NSA the following are no longer secure:
  • ECDH and ECDSA with NIST P-256
  • SHA-256
  • AES-128
  • RSA with 2048-bit keys
  • Diffie-Hellman with 2048-bit keys
All the popular auto PGP email providers like Tutanota and ProtonMail still use 2048 bit RSA and should be avoided. Use PGP yourself with a key strength of 4096 (stronger keys are possible to create but commercial PGP clients have trouble handling.)

User avatar
bitkilo
Platinum Bitcoiner
Platinum Bitcoiner
Posts: 3210
Joined: Sat Sep 26, 2015 4:08 am

Donate BTC of your choice to 1DJcTrvdGsmKr7LdriVizkVmkcXWoG12nt

Re: Are you using Tutanota email ?

Tue Feb 09, 2016 12:01 pm

To reiterate that services using 2048 RSA encryption are no longer secure see the FAQ recently published by the NSA.

According to the NSA the following are no longer secure:
  • ECDH and ECDSA with NIST P-256
  • SHA-256
  • AES-128
  • RSA with 2048-bit keys
  • Diffie-Hellman with 2048-bit keys
All the popular auto PGP email providers like Tutanota and ProtonMail still use 2048 bit RSA and should be avoided. Use PGP yourself with a key strength of 4096 (stronger keys are possible to create but commercial PGP clients have trouble handling.)
Thanks for pointing this out, i don't keep on top of this stuff like i should.

I signed up with ghostmail not long ago for a new email address but just checked and they are still using RSA 2048.

Can you recommend another free client that is still safe?
Please help Ross and his family during this hard time by donating to the https://freeross.org/ fund. Play at the best provably fair Bitcoin games site here: games.bitcoin.com Need a fantastic Bitcoin wallet Pick up some great Bitcoin.com swag here

User avatar
BitcoinNewsMagazine
Nickel Bitcoiner
Nickel Bitcoiner
Posts: 217
Joined: Thu Sep 24, 2015 5:03 pm
Contact: Website Facebook Twitter

Re: Are you using Tutanota email ?

Tue Feb 09, 2016 3:50 pm

To reiterate that services using 2048 RSA encryption are no longer secure see the FAQ recently published by the NSA.

According to the NSA the following are no longer secure:
  • ECDH and ECDSA with NIST P-256
  • SHA-256
  • AES-128
  • RSA with 2048-bit keys
  • Diffie-Hellman with 2048-bit keys
All the popular auto PGP email providers like Tutanota and ProtonMail still use 2048 bit RSA and should be avoided. Use PGP yourself with a key strength of 4096 (stronger keys are possible to create but commercial PGP clients have trouble handling.)
Thanks for pointing this out, i don't keep on top of this stuff like i should.

I signed up with ghostmail not long ago for a new email address but just checked and they are still using RSA 2048.

Can you recommend another free client that is still safe?
I do not know of any free email services using automatic PGP encryption at 4096 strength yet. I also have some concerns storing private keys in the browser. Really, gpg4usb is pretty simple to use, just check their online manual. Because gpg4usb is portable you can take it with you on a flash drive or store it in a Veracrypt container to protect your private key from snoopers.

While it is a good idea to use an email provider that does not log your IP and minimizes metadata you would be better off just using local PGP with Gmail than one of those email providers who encrypt and decrypt in your browser.

For a good comparison list of free and paid email providers check out privacy conscious email services one should work for you. One thing everyone agrees on is to stay away from Safe-Mail and Hushmail.

Return to “Dash”

Who is online

Users browsing this forum: No registered users and 2 guests