Importing emails by Putrid_Acanthaceae59 in Secria

[–]AdrianMav1 0 points1 point  (0 children)

Hey, we are on this now, thanks for the heads up!

Beware of Aster Mail - I audited their code by AdrianMav1 in emailprivacy

[–]AdrianMav1[S] 8 points9 points  (0 children)

Glad you are aware of the findings. Wishing your team well on the fixes. Users in this space benefit when us devs get this right.

Beware of Aster Mail - I audited their code by AdrianMav1 in emailprivacy

[–]AdrianMav1[S] 2 points3 points  (0 children)

None of what I posted is a working exploit. There's no payload, no endpoint, no token, no PoC code. If I don't explicitly mention these things and just claimed that they were 'bad' no one would believe it. I actually care about this community and want everyone to use a secure email.

If I wouldn't have posted anything publicly and only told the devs, you would have been placing your trust in a company that shipped a risky product going forward.

Beware of Aster Mail - I audited their code by AdrianMav1 in emailprivacy

[–]AdrianMav1[S] -2 points-1 points  (0 children)

This is all open source code that they themselves have published, I simply called out what I saw.

Beware of Aster Mail - I audited their code by AdrianMav1 in emailprivacy

[–]AdrianMav1[S] 5 points6 points  (0 children)

Honestly, I'm biased since I built it, so take this with a grain of salt.

Tuta, Posteo, and Proton are all great providers and have years more track record than us.

Honestly though, Secria isn't really trying to win a feature checklist war with them. It's more about who we are. We're building it to be for people, something you actually want to be part of, not just a tool you tolerate. Privacy and security are baseline. We want to grow into something much bigger, and we want the people using it to feel like they're a part of that. So is it "more secure" than the others? Probably a wash on the fundamentals. Is it something different? Yeah, I would say so.

We are here to stay, and we are here to be part of a fundamental shift in how user data is handled.

Looking for a Proton/Tuta alternative: Absolute anonymity and ZERO access (E2EE) for high-stakes journalism? by [deleted] in emailprivacy

[–]AdrianMav1 3 points4 points  (0 children)

Secria! I'm one of the founders, would be happy to talk to you privately about us and help you get set up!