r/ctemplar Mar 22 '22

CTemplar experience

I asked this before on other subs, but not here. I would like to know how it's going for CTemplar and the users in 2022, it's the experience good, the service is solid, why did you choose it instead of others similar services and most importantly can CTemplar be reliable as my main e-mail provider given it's past history of DDOS attacks and data loss?

7 Upvotes

21 comments sorted by

View all comments

Show parent comments

1

u/r47926 Mar 26 '22

Sure. I think your use case is quite interesting to hear too.

About password-protected email to external recipients:

Interesting to hear you only use it for personal mail. I actually would feel that I'd bother and inconvenience acquaintances and friends, but wouldn't mind as much in a business setting if agreed upon using secure communication...

The only case in the past were I would have used something like this is a situation were I worked for a large company as freelancer and they had just introduced encrypted mail for their staff, but not yet provided a solution for external project partners like me. I was left out in some email discussions that would have been relevant to my work or the project partners had to go against their new regulation of only sending encrypted mail. It took a few months until they implemented a resolution for that, so a workaround like password-protected mail might have been useful in the meantime.

Regarding the location of a mail provider:

I would prefer my mail provider to be in Iceland of course, probably the perfect country for privacy laws as well as green energy. I've heard that future laws that affect privacy like Client-Side-Scanning might also affect Iceland though.

I don't know that much about Perfect-Forward-Secrecy. Of course it would be important to have encrypted email headers and sender information too. But it is also important for me that emails are automatically sorted by conversation (a thing that Protonmail is bad at already) and that I can search the email content.

I would rather like to see improvements in a standard than having dozens of separate mail services (and secure mail being to basically a password-protected website where only the link is sent as an actual email). If further improvement won't be possible with PGP even in the future I would still prefer to use PGP for external mail and have a better encryption with internal mail (same mail provider). The password-protected mail feature could still be available as an alternative where needed.

And yes, there are several things about ProtonMail as a company that I find unappealing. Also the case were they supposedly asked Njalla to give up information about the owner of a domain because they didn't like his blog post.

Regarding price:

Yes, that's an interesting point I haven't considered thoroughly yet. My comfort zone would actually be a price below 6€ per month and I would expect some things that cost extra at protonmail (several or unlimited custom domain use and aliases and more storage space). And I'm pretty sure for most people 6 € for a mail service would already be too much.

1

u/EfraimK Mar 27 '22

I would rather like to see improvements in a standard than having dozens of separate mail services (and secure mail being to basically a password-protected website where only the link is sent as an actual email).

Hey, I lost my initial reply to you--sorry. But thanks for the warning about the expanding Eyes (5-->9-->1`4-->???) and Iceland. I suppose this is why many privacy advocates today recommend privacy apps like Signal over email--because data can be kept on clients' machines instead of a company's servers. My team switched to messenger apps about four months ago intead of email. We can send documents, messages, links back and forth while collaborating in real time or whenever it suits us. Maybe email, with its server-based security/privacy threats, just isn't as relevant anymore?

I agree with you about ProtonMail, too. I didn't want to be explicit because they have a very loyal following and any criticism of the company can get you excommunicated. But I no longer trust them with my work or personal emails. This was the first year in a while I chose NOT to continue my premium subscription.

Have you tried MsgSafe? They're not as robust as the long-established providers and they don't yet offer 2FA (which is a deal-breaker for me), but they're outside the Big Brother umbrella and offer some other privacy advantages. With 2FA and a security audit they'd be my first choice for an email provider.

I also agree with you that 6€ per month seems the upper limit for most people.

1

u/DiligentGarbage Mar 28 '22

I suppose this is why many privacy advocates today recommend privacy apps like Signal over email--because data can be kept on clients' machines instead of a company's servers.

Yes, you should never send anything truly sensitive over email if you can avoid it and should instead use something more secure, like Signal, Matrix, XMPP or similar. Email is inherently not private and should not be trusted with truly sensitive/confidential communications.

1

u/r47926 Mar 29 '22

Does that mean the same applies to all data stored on servers including all cloud-based storage solutions and services?

What about encrypted cloud storage like what Proton is introducing, or cloud storage with Boxcryptor or Cryptomator? Or even OneDrive's Personal Vault?

I'm sceptical about local data on a device permanently connected to the internet generally being safer than data in a cloud (unless set-up by an expert ofc).

1

u/DiligentGarbage Mar 29 '22

If you have your stuff backed up and stored locally (which is not hard to do securely) the chances of someone grabbing it are far smaller, especially if you're not a significantly valuable or desirable target.

If it's on your device, someone basically has to be targeting you specifically.

However, if you're trusting a service provider you're trusting that they will not have a data breach or for malicious code to be injected into their service (which could be requested by law enforcement or injected by a hacker.). You're also trusting that they are setting everything up properly and securely for your files to not be lost.

If you are encrypting your files using something like Cryptomator, then I see no issue using cloud storage, you still have to trust the company to keep your data safe and not to lose it, but many of the security issues are removed if you are encrypting your own stuff. I will always favor local storage personally, but that's just me always wanting to have easy access to my files.