Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
MatthiasPfau
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
by
MatthiasPfau
11y ago
> Why is there so much resistance to implementing authenticated encryption? We already stated that we are going to implement authenticated encryption. But when we do it we have to do it right. We have to keep everything backwards compati
2.
▲
by
MatthiasPfau
11y ago
Thanks for clarifying. > an attacker can keep sending forged messages until it decrypts successfully There is simply no way for an attacker to find out if his forged messages decrypt successfully besides having full control of the recipi
3.
▲
by
MatthiasPfau
11y ago
> They seem to confuse digital signatures with message authentication. Why do you think that? Of course we (I am one of the founders of Tutanota) understand the difference of the two. > They're using PKCS5 which means that, yes,
4.
▲
by
MatthiasPfau
12y ago
Thanks for your feedback! Hosting directly from github might be a good idea for the ones that regard github as a trusted third party. However, github would gain the possibility to manipulate the code to gain access to your accounts... We pl
5.
▲
by
MatthiasPfau
12y ago
I am one of the founders, thanks for your discussion. We only load the app into your browser cache upon an update of which the app notifies you. However, we are very aware of the challenges that come along with making browser-based encrypti
6.
▲
by
MatthiasPfau
12y ago
I am one of the founders. Thanks for your feedback. We will fix this early next year!
7.
▲
Privacy 2.0: We Need Weapons, Not Words
(medium.com)
6 points
by
MatthiasPfau
12y ago
|
2 comments
8.
▲
by
MatthiasPfau
12y ago
You can try out our beta-app by sending your email address for the Google Playstore to support@tutao.de All data in Tutanota is encrypted with the user’s password. With Tutanota we want to protect our human right to privacy, particularly as
9.
▲
Show HN: We’ve created Tutanota, an encrypted email App (GPLv3)
(tutanota.com)
5 points
by
MatthiasPfau
12y ago
|
2 comments
10.
▲
by
MatthiasPfau
12y ago
Crypto within the browser is a challenge, but possible. Here are some points to consider: 1. You need strong random numbers. 2. The browser automatically downloads the client application on each reload. 3. XSS attacks are a problem for all
11.
▲
Show HN: Exchange end-to-end encrypted emails with anybody
(github.com)
8 points
by
MatthiasPfau
12y ago
|
2 comments