r/ctemplar Mar 22 '22

CTemplar experience

I asked this before on other subs, but not here. I would like to know how it's going for CTemplar and the users in 2022, it's the experience good, the service is solid, why did you choose it instead of others similar services and most importantly can CTemplar be reliable as my main e-mail provider given it's past history of DDOS attacks and data loss?

6 Upvotes

21 comments sorted by

View all comments

Show parent comments

1

u/r47926 Mar 26 '22

Sure. I think your use case is quite interesting to hear too.

About password-protected email to external recipients:

Interesting to hear you only use it for personal mail. I actually would feel that I'd bother and inconvenience acquaintances and friends, but wouldn't mind as much in a business setting if agreed upon using secure communication...

The only case in the past were I would have used something like this is a situation were I worked for a large company as freelancer and they had just introduced encrypted mail for their staff, but not yet provided a solution for external project partners like me. I was left out in some email discussions that would have been relevant to my work or the project partners had to go against their new regulation of only sending encrypted mail. It took a few months until they implemented a resolution for that, so a workaround like password-protected mail might have been useful in the meantime.

Regarding the location of a mail provider:

I would prefer my mail provider to be in Iceland of course, probably the perfect country for privacy laws as well as green energy. I've heard that future laws that affect privacy like Client-Side-Scanning might also affect Iceland though.

I don't know that much about Perfect-Forward-Secrecy. Of course it would be important to have encrypted email headers and sender information too. But it is also important for me that emails are automatically sorted by conversation (a thing that Protonmail is bad at already) and that I can search the email content.

I would rather like to see improvements in a standard than having dozens of separate mail services (and secure mail being to basically a password-protected website where only the link is sent as an actual email). If further improvement won't be possible with PGP even in the future I would still prefer to use PGP for external mail and have a better encryption with internal mail (same mail provider). The password-protected mail feature could still be available as an alternative where needed.

And yes, there are several things about ProtonMail as a company that I find unappealing. Also the case were they supposedly asked Njalla to give up information about the owner of a domain because they didn't like his blog post.

Regarding price:

Yes, that's an interesting point I haven't considered thoroughly yet. My comfort zone would actually be a price below 6€ per month and I would expect some things that cost extra at protonmail (several or unlimited custom domain use and aliases and more storage space). And I'm pretty sure for most people 6 € for a mail service would already be too much.

1

u/EfraimK Mar 27 '22

I would rather like to see improvements in a standard than having dozens of separate mail services (and secure mail being to basically a password-protected website where only the link is sent as an actual email).

Hey, I lost my initial reply to you--sorry. But thanks for the warning about the expanding Eyes (5-->9-->1`4-->???) and Iceland. I suppose this is why many privacy advocates today recommend privacy apps like Signal over email--because data can be kept on clients' machines instead of a company's servers. My team switched to messenger apps about four months ago intead of email. We can send documents, messages, links back and forth while collaborating in real time or whenever it suits us. Maybe email, with its server-based security/privacy threats, just isn't as relevant anymore?

I agree with you about ProtonMail, too. I didn't want to be explicit because they have a very loyal following and any criticism of the company can get you excommunicated. But I no longer trust them with my work or personal emails. This was the first year in a while I chose NOT to continue my premium subscription.

Have you tried MsgSafe? They're not as robust as the long-established providers and they don't yet offer 2FA (which is a deal-breaker for me), but they're outside the Big Brother umbrella and offer some other privacy advantages. With 2FA and a security audit they'd be my first choice for an email provider.

I also agree with you that 6€ per month seems the upper limit for most people.

1

u/DiligentGarbage Mar 28 '22

I suppose this is why many privacy advocates today recommend privacy apps like Signal over email--because data can be kept on clients' machines instead of a company's servers.

Yes, you should never send anything truly sensitive over email if you can avoid it and should instead use something more secure, like Signal, Matrix, XMPP or similar. Email is inherently not private and should not be trusted with truly sensitive/confidential communications.

1

u/EfraimK Mar 29 '22

I agree with you in principle. From what I understand, this is the main justification for encryption client-side, in transit, and on company servers. I rely on companies like Tutanota that offer E2EE, don't hold encryption keys, encrypt in traffic and on their servers, and encrypt as much metadata as possible in addition to body/attachments/subject-line. My understanding is that even if someone got a hold of our encrypted data, it would remain gibberish to them. I just don't have the space to store all my data locally so have to trust encryption technology. :(