Note that the initramfs is stored without encryption or signing. So while your data won't be leaked when your phone gets stolen, it should be considered compromised if you get it back.
How does flashing work, who controls the writes? I remember reading about hacking the controller of an SD card to override the read/write functionality.
I think if the bootloader is overwritable, it could lie to you about reflashing the boot partition...
Tutanota is one of the uglier and at the same time pretentious projects. As far as I'm concerned, this crap can't be called e-mail at all. This is some crookedly made homemade work. They don't support the usual protocols for receiving mail, the search is just terrible, all kinds of freaks use them for their dark business, so these left-handed idiots have even started to be added to ban lists. I recently spent half a month persuading the bank because I stopped receiving notifications. And I would also like to see the "engineer" who invented encrypting letters to other providers using a "password". Well, that is, this whole team of developers, managers - they were not upset by such an idea at all. Implement PGP? Let everyone post public keys and write to each other? No! What nonsense! It's better to go somewhere through a browser and enter some crappy password. And should I trust these bastards with my mail? I would spit in their face. I think this row should be filed for bankruptcy.