vertoe
Three of Nine
What do you mean by stopped doing sign ups?It's a shame bitmessage has stopped doing sign ups. I really wish I could test it out as an email service
What do you mean by stopped doing sign ups?It's a shame bitmessage has stopped doing sign ups. I really wish I could test it out as an email service
That's just the mail gateway. Don't even bother to use itThis is the current situation: https://bitmessage.ch/register/NA.html
The private key is saved encrypted in our highly secure data center in Germany. The password that you use upon registration for authentication also secures your private key. An automatic password check on the client makes sure that you use an adequately strong password.
To protect your password Tutanota uses the hashing algorithm bcrypt and additionally SHA256. Bcrypt remains to be the safest method and was confirmed and highlighted during the extensive penetration test by the SySS GmbH.
The private key of the user and the hashed password for authentication are cryptographically separate from each other so that nobody can deduct the key from any password data. The key is encrypted so strong that only the user can use the key for encrypting and decrypting data."
Thanks yibble. You probably know more than I do in this area. (It wouldn't take much.) My understanding is that using gpg for any content would keep it safe from Tutanota. That would mean that at best they would have the headers, and be no worse than any other service (except Bitmessage that I know of). Their crypt between their servers and sender and recipient sound reasonable, and the elimination of headers in transit seem to me to make them worthy of consideration--especially at no cost. That and the German legal protections seem better than many other venues.
Am I missing something here? Any counsel is appreciated.