There are now a wide variety of categories and projects on noailist.org, the list of projects that have specifically chosen not to use AI.

you are viewing a single comment's thread
view the rest of the comments
[–] 0 points 1 day ago (8 children)

i noticed you have tuta listed; fyi, see here for a recent commit in one of their repos which says it is "co-authored by claude". (tuta is shitty and shouldn't be advertised for various other reasons also...)

  • source
  • hideshow 8 child comments
  • [–] 4 points 1 day ago (7 children)

    Why is Tuta shitty?

    I switched from Proton a year ago or so because the CEO is a Trumper. But I haven't seen anything bad about Tuta, so I am curious if I need to switch again.

  • source
  • parent
  • hideshow 7 child comments
  • [–] 5 points 1 day ago (4 children)

    I dunno if it qualifies as shitty, but I've always been annoyed that they are in no way interoperable with email and calendar standards.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 1 point 20 hours ago (3 children)

    Kind of I guess? i don't use these features.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 3 points 11 hours ago* (2 children)

    Oh, also, they don't really implement e2e email encryption, which is kinda ironic. Your emails are stored encrypted, and e2e encrypted when sent to other tuta users, but to everyone else, the only way to send an e2e encrypted message is a normal email with a password protected link.

    Tuta argues that their system is more secure/private, since pgp doesn't encrypt metadata. I'd argue that not supporting pgp means you aren't serious about encryption. It might be in theory less private, but it's the one encryption standard people actually use for email, and not supporting it excludes their user from sending e2e encrypted mail in a sensible way, and from receiving it at all, unless all their contacts also use tuta. Which might be the point.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 4 hours ago (1 child)

    What would you recommend then?

    I have my own domain, so I need a provider that can have custom domains.

  • source
  • parent
  • hideshow 1 child comment
  • I'm with Proton for my private addresses right now, but while they do allow for pgp, they're guilty of many of the same practices as tuta is, and I might go elsewhere when my contract is up. The reason I'm still there is that they do implement pgp, so I haven't had strong enough incentive to switch.

    I have good experiences with Mailbox.org. I heard good things about Posteo, runbox, and start mail, but haven't tried either of them personally.

  • source
  • parent
  • [–] 4 points 1 day ago* (last edited 23 hours ago) (1 child)

    Why is Tuta shitty?

    here and here are two of my past comments about them with more links, but, tldr:

    • their email encryption is not interoperable
    • their encrypted email service encourages people to use a browser-based thing with an incoherent threat model: the server that the e2ee is supposed to protect you from is the same one that serves you the code each time, which means that it would trivial to subvert it on-demand for targeted users with a negligibly-small chance of anyone catching them in the act. this is an example of cryptographic snake oil.
      • note that whether (or how often) they actually do subvert their encryption for targeted users is unproven; it has been alleged in court testimony that they do, and that the entire service is in fact a honey pot for doing exactly this (see my other comments for a link about that), but the testimony is perhaps not the most credible. however, the fact that they have the ability to do this (and without much chance of being caught) is undeniable and obvious to experts while being very much not obvious to most of their users.
    • they are incessant blog spammers, writing advertorials about every vaguely-privacy-related news event to promote their products
    • and, a new item on the list (not particularly surprising, given their history of shameless hucksterism): their README claims a clear policy against AI contributions but if you click that link and scroll up and click the three dots next to the commit message ("test plugin kit and nextcloud plugin") you can see it says "Assisted-by: Claude:claude-sonnet-5". (This kind of dishonest bandwagon-jumping-on is very on-brand for tuta.)
  • source
  • parent
  • hideshow 1 child comment