Encryption backdoors must never be allowed. To prove that Tuta is #free from any #backdoor, the entire client code is published as #opensource.

Encryption backdoors must never be allowed. To prove that Tuta is #free from any #backdoor, the entire client code is published as #opensource.

Let's fight against mass surveillance! ✊

https://tuta.com/blog/why-a-backdoor-is-a-security-risk

#privacy #encryption #surveillance

25 points · 2 comments · view on lemmy.world

2 Comments

x_cli@infosec.exchange · 2 pts · 1y

@Tutanota@mastodon.social
Web clients cannot be verified since they can be altered by the server sending the code to the browser. Standard protocols such as IMAP allow using ANY open source client, including those that are already well audited. Not just yours. From my PoV, you are doing it wrong.

squirrel@social.bau-ha.us · 1 pts · 1y

@Tutanota@mastodon.social Publishing something as Open Source does not prove that it's not backdoored, unless users cannot verify that the deployed software matches the published code. You need reproducible builds and independent distribution channels.