ScanRecords

Tuta (Tutanota) / Encryption

Tuta (Tutanota) changed its Encryption

Recorded 5 Aug 2026 — +5 lines added, −5 removed. This page shows the exact difference between the previous snapshot and the new one.

@@ -63,7 +63,7 @@ To secure the login password, Tuta uses Argon2 and SHA256. Thus, the login passw
  This is shown by the following picture and explained in the text below: -Argon2 modifies the password so that it becomes the “AES password key”. This AES password key is used to encrypt the private RSA-key (though via an indirection with the private symmetric “AES user group key”).+Argon2 takes the password as input to derive the “AES password key”. This AES password key is used to encrypt the private keys (though via an indirection with the private symmetric “AES user group key”).  The AES password key itself, however, is not used to authenticate the user with the server, but it is hashed to become the “password verifier”. 
@@ -78,11 +78,11 @@ The decryption process takes place locally on the device of the user once the us
 By encrypting the private key with the user’s password, Tuta can automatize the entire encryption process without ever having access to your private key.  Why does Tuta Mail not use PGP?-Tuta uses standard algorithms also being used by PGP (AES and RSA or ECC) for encrypting the entire mailbox. In addition, Tuta Mail already uses post-quantum cryptography (Kyber) for quantum safe accounts, which is still a work in progress for PGP. Furthermore, Tuta does not use an implementation of PGP itself because PGP lacks important requirements that we have for Tuta:+Tuta uses standard algorithms also being used by PGP (AES and x25519 with Kyber/ML-KEM) for encrypting the entire mailbox. Furthermore, Tuta does not use an implementation of PGP itself because PGP lacks important requirements that we have for Tuta: -PGP does not encrypt the subject line (already achieved in Tuta),+PGP does not encrypt the subject line (already achieved in Tuta). -PGP algorithms can't be easily updated, e.g. to post-quantum secure ones like in Tuta Mail,+PGP algorithms can't be easily updated (We were able to migrate to post-quantum secure encryption much faster).  PGP has no option for Perfect Forward Secrecy (already achieved for Tuta in a prototype). 
@@ -98,7 +98,7 @@ However, in May 2018, the Electronic Frontier Foundation (EFF) announced critica
 Post-quantum secure encryption Tuta is not only the most secure email service at the moment, it already offers post-quantum secure encryption. -Tuta was the first email provider to implement a protocol for post-quantum secure encryption. Since March 2024, we have been rolling out this protection to Tuta accounts. This lets us encrypt emails with a hybrid approach combining our proven encryption algorithms with post-quantum secure algorithms.+Tuta was the first email provider to implement a protocol, TutaCrypt , for post-quantum secure encryption, which has been formally proven secure. Since March 2024, we have been rolling out this protection to Tuta accounts. This lets us encrypt emails with a hybrid approach combining our proven encryption algorithms with post-quantum secure algorithms.  By already using post-quantum cryptography , Tuta protects your data against "harvest now, decrypt later" attacks and helps keep it secure when quantum computers are able to break today's commonly used encryption algorithms. 

Removed lines are how the document read before; added lines are how it reads now. Verify independently: the snapshot files and their history are in the public repository.

Independent copy: whenever a change is recorded, the Internet Archive is asked to capture the source page the same day — find the same-day Wayback capture.

Cite this record

ScanRecords. “Tuta (Tutanota) changed its Encryption.” Recorded 5 Aug 2026. https://scanrecords.org/change/2026-08-05-tuta-encryption/ — snapshot SHA-256 (after): 1d263130c9ccd709779eec51add3217aab484fb216160a6bdf5d0e5333078737.