Hacker News new | ask | show | jobs
by Tutanota 953 days ago
Key verification is an important part and we are working towards the goal to enable easy authentication. However, we are not happy how manual key verification works with Signal nor how it is implemented with GPG (Web of Trust). Most (at least 95%) don't verify keys with Signal because it is too cumbersome.

As a first step, we are currently addressing cyptographic authentication of incoming messages. Our development team is implementing this feature as part of the work on tuta crypt, our pq messaging protocol. It will be released within the next months. However, we have to admit that easy and automatic key verification will take some more time as we are still researching best options to implement this.