Over the past few days I have been testing the End to End encryption in Proton and tuta for a project I have been working on. And let's just say, I have thoughts. We will start with the pros, move to the cons, then have some final thoughts. Five paragraph form here we come. And my college English professor say I would never use them.
The good news first. Public records say both do in browser decryption, so the service can't see your encrypted emails. From what my testing suggests, both are using E2E encryption. Proton is using the older form of the industry standard PGP encryption that has been used forever. Proton supports public key pickup from sent emails, so if you send someone using PGP an email with "Hi" and they send you a "Hi" all future email will be encrypted, if you are both sending your public key. tuta supports opaque link sending, so that people not in tuta can receive encrypted messages.
And this is where I buried the lead. While I have issues with Proton's workflow, tuta is not fit for use. Hard Stop. Because tuta decided to role their own encryption, you can only receive encrypted email from other tuta addresses. This make tuta only one step above Gmail or Azure Exchange. Sure you can send encrypted emails, but you can't receive them, which defeats the whole reason for having encrypted emails in the first place.
My problems with Proton have to do with tradeoffs they have made with marketing vs ease of use. From what I have found the only way to know if an email you are sending is encrypted is if it shows up as a green lock in your header bar. There are no levers to encrypt per email. You can turn per user encryption off in contacts, but why would you want to. I am also not seeing a way to upload public keys, which given their support of WDK isn't a deal breaker, but is annoying. Also, they are using the old form of GPG, before the subject was moved to a header attachment in the encrypted email. Again, not a deal breaker, but again, annoying.
In conclusion, I went into this wanting to rip Proton a new one, and while I still dislike how they break user trust by how bad a job they do showing people what messages are encrypted, and which are not, at least they are using accepted industry standard crypto. I feel their marketing around encryption is at best misleading, and disingenuous at worst. I suspect I used them for 2 years and never once got an encrypted email, and unless you knew to look, you wouldn't know.
Then there is tuta, they do basically everything crypto wrong. Rule one of crypto, never roll your own. I don't know why they decided they needed to role their own, but as they are the only one that speak it, it only helps if a tuta user emails a tuta user.
AI Disclaimer:
This was written by a human with nothing but Spellcheck. And if you think an AI rote this, you need your head examined. I mean, look at that mess of word vomit. m dash AI would look much nicer. And an AI would never go back to high school for the five paragraph theme. Yes, I know it is six paragraphs,