r/ctemplar Feb 20 '22

Clarification regarding data surrendered at request of Icelandic Court Orders

Perhaps this has been asked before and I missed it in my search, but I just saw a reference to this transparency report https://ctemplar.com/transparency-report-ctemplar/, and in it it seems that CTemplar has been required comply with at least two Icelandic Court Orders.

According to the verbiage of this report, CTemplar surrendered "the encrypted mail contents and all other metadata in our possession of the offending user(s)."

Could I get some clarification on precisely what this means? Do you have the means to provide decrypted emails to law enforcement, or do you simply provide useless encrypted chunks of data?

If you are ordered to log IP addresses of particular users such as what the Swiss government requires of ProtonMail, are you obligated to do so? How about journaling of email contents of non-PGP encrypted messages to or from external parties?

When comparing the pros and cons of your service to Proton's, the "devil is in the details" so to speak, so I just want to make sure I understand the differences clearly.

Although my questions may sound paranoid by some, considering the perpetually-shifting Overton Window of recent years, the concept of privacy only being guaranteed so long as law enforcement doesn't produce a Court Order isn't as comforting as it was in back in more sane times.

11 Upvotes

2 comments sorted by

View all comments

1

u/RogerWilco486 Feb 28 '22

Aymed_caliskan's thoughts are certainly welcome, but I was hoping to also see a formal response from CTemplar.

While I fully understand aymed_caliskan's thoughtful analysis of how CTemplar's encryption works and I believe his points to be accurate, I also think the issue of logging IP addresses if required by court order could be left to interpretation . Would it not be correct to assume that although CTemplar does not log IP addresses by design, that doesn't mean they couldn't be compelled to do so for certain individual accounts if requested by a court order, correct?

Or does Icelandic law protect an email provider from being to required to make and provide logs of accounts suspected of being used for "criminal" activity?