I'm not a fan of Tuta, mainly because of their disingenuous advertising where they keep calling themselves "open source" when they in fact only open source their clients but keep anything server-side under wraps -- but for this reason this also makes me skeptical; if their clients are indeed open source (which I assume is true, I haven't verified), and all encryption happens client-side before being sent to the server (also an assumption), how would it even be possible for this to be true?<p>In my understanding, anything that Tuta potentially did to compromise e-mails would necessarily have to shine through in their open source client code -- unless they willingly serve binaries that are not actually built from that code, which of course would be a scandal.<p>So even if I don't like them, I'm going to need something more concrete than someone simply <i>saying</i> they have "intelligence ties" to be willing to believe that they are somehow duping their users.