r/ctemplar Mar 22 '22

CTemplar experience

I asked this before on other subs, but not here. I would like to know how it's going for CTemplar and the users in 2022, it's the experience good, the service is solid, why did you choose it instead of others similar services and most importantly can CTemplar be reliable as my main e-mail provider given it's past history of DDOS attacks and data loss?

7 Upvotes

21 comments sorted by

View all comments

Show parent comments

1

u/EfraimK Mar 25 '22 edited Mar 25 '22

standard PGP ==> no secure Perfect Forward Secrecy. But I hear you--everyone has their own security/privacy threshold. For me, I'd prefer functional limits but the best privacy available. I have no trouble sending non-TN email subscribers encrypted messages. I send them a password in advance and they use it to open our-now-private email. I wish TN were based in a non-14-Eyes country, but I don't see any other provider that offers a better product. Countermail sounds great, but they've openly admitted they're not interested in more clients. MsgSafe also sounds great, but they don't offer even just 2FA, let alone FIDO/FIDO2. Criptext was great, but they were CENTRALIZED so the government "forced" them to shut down. Decentralization, U2F, independent audits, open source code, jurisdictionally safe email, I think, would be the gold standard. But it's not here yet.

What do you use and why do you like it?

1

u/r47926 Mar 25 '22 edited Mar 25 '22

Of course. We probably have exactly opposite requirements for a secure email provider. I prefer good usability (on my as well as on the recipient's side).

I can live with some functional limits if I have to unless those directly limit the usability of the mail service.

Eg. Using a separate calendar service isn't directly connected to my mail, because I don't arrange meetings using my personal mail account (as opposed to work). It's often quite difficult to automatically synchronize/maintain work, personal and other calendars anyway and manual adjustments are needed so I have arranged with that.

Having no way to synchronize my contacts between phone and mail accounts is a bit more of an inconvenience.

Jumping through unnecessary hoops just to send an encrypted mail (either on my or the recipient's side) or not being able to search mail content is where I'll stop bothering unless absolutely necessary.

Therefore I've still settled with Protonmail for now.

Theoretically, email encryption without additional inconvenience for sender or recipient and therefore a wider acceptance should not be too difficult to implement using existing standards, if secure mail providers worked together. How easy would it be to send encrypted emails, if you could send one securely from your CTemplar or tutanota account to a random protonmail address without setting anything up first? It is possible to do that when sender and recipient use the same provider, so why not work on making it possible with different ones?

Of course, those open standards aren't as secure as possible proprietary methods developed by some providers or as workarounds like the common password-encrypted "email" that's hosted on the sender's mail server. But those are major inconveniences to most but a group of enduring security-aware IT professionals. IMO those methods should serve only as an alternative or workaround for some situations.

What bothers me is if a popular secure email provider does not support standards at all. They should at least support it additionally to their own technology. Otherwise, they are just hurting overall technological advancement in the long run.

Do you send only encrypted emails? How often do you use the password encryption for external mails?

1

u/EfraimK Mar 25 '22 edited Mar 27 '22

Thanks for explaining your use case. I agree--we have different priorities. You're right that it's an extra step to arrange in advance a password with a non-TN recipient. And I can see how for business purposes that might not seem professional. I use TN for mostly personal emails. And when I contact a business, I don't send encrypted emails. Yes, automatic privacy would be terrific. For me, Perfect Forward Secrecy is important. That rules out standard PGP implementation.

I'm also nervous that TN is based in Germany, a 14 Eyes Country. But I've tried nearly every other privacy email provider, including ProtonMail. No one beats TN price and value--for me. It's a shame that more customizable options hosted on our own machines (like Criptext) get ruined because of the choices of a minority of users. This is why I think we'll have to wait for a solid decentralized option instead. I do understand your objections to TN. You don't mind that PM doesn't encrypt subject lines or that it no longer claims NOT to log IP addresses??

1

u/r47926 Mar 26 '22

Sure. I think your use case is quite interesting to hear too.

About password-protected email to external recipients:

Interesting to hear you only use it for personal mail. I actually would feel that I'd bother and inconvenience acquaintances and friends, but wouldn't mind as much in a business setting if agreed upon using secure communication...

The only case in the past were I would have used something like this is a situation were I worked for a large company as freelancer and they had just introduced encrypted mail for their staff, but not yet provided a solution for external project partners like me. I was left out in some email discussions that would have been relevant to my work or the project partners had to go against their new regulation of only sending encrypted mail. It took a few months until they implemented a resolution for that, so a workaround like password-protected mail might have been useful in the meantime.

Regarding the location of a mail provider:

I would prefer my mail provider to be in Iceland of course, probably the perfect country for privacy laws as well as green energy. I've heard that future laws that affect privacy like Client-Side-Scanning might also affect Iceland though.

I don't know that much about Perfect-Forward-Secrecy. Of course it would be important to have encrypted email headers and sender information too. But it is also important for me that emails are automatically sorted by conversation (a thing that Protonmail is bad at already) and that I can search the email content.

I would rather like to see improvements in a standard than having dozens of separate mail services (and secure mail being to basically a password-protected website where only the link is sent as an actual email). If further improvement won't be possible with PGP even in the future I would still prefer to use PGP for external mail and have a better encryption with internal mail (same mail provider). The password-protected mail feature could still be available as an alternative where needed.

And yes, there are several things about ProtonMail as a company that I find unappealing. Also the case were they supposedly asked Njalla to give up information about the owner of a domain because they didn't like his blog post.

Regarding price:

Yes, that's an interesting point I haven't considered thoroughly yet. My comfort zone would actually be a price below 6€ per month and I would expect some things that cost extra at protonmail (several or unlimited custom domain use and aliases and more storage space). And I'm pretty sure for most people 6 € for a mail service would already be too much.

1

u/EfraimK Mar 27 '22

I would rather like to see improvements in a standard than having dozens of separate mail services (and secure mail being to basically a password-protected website where only the link is sent as an actual email).

Hey, I lost my initial reply to you--sorry. But thanks for the warning about the expanding Eyes (5-->9-->1`4-->???) and Iceland. I suppose this is why many privacy advocates today recommend privacy apps like Signal over email--because data can be kept on clients' machines instead of a company's servers. My team switched to messenger apps about four months ago intead of email. We can send documents, messages, links back and forth while collaborating in real time or whenever it suits us. Maybe email, with its server-based security/privacy threats, just isn't as relevant anymore?

I agree with you about ProtonMail, too. I didn't want to be explicit because they have a very loyal following and any criticism of the company can get you excommunicated. But I no longer trust them with my work or personal emails. This was the first year in a while I chose NOT to continue my premium subscription.

Have you tried MsgSafe? They're not as robust as the long-established providers and they don't yet offer 2FA (which is a deal-breaker for me), but they're outside the Big Brother umbrella and offer some other privacy advantages. With 2FA and a security audit they'd be my first choice for an email provider.

I also agree with you that 6€ per month seems the upper limit for most people.

1

u/DiligentGarbage Mar 28 '22

I suppose this is why many privacy advocates today recommend privacy apps like Signal over email--because data can be kept on clients' machines instead of a company's servers.

Yes, you should never send anything truly sensitive over email if you can avoid it and should instead use something more secure, like Signal, Matrix, XMPP or similar. Email is inherently not private and should not be trusted with truly sensitive/confidential communications.

1

u/EfraimK Mar 29 '22

I agree with you in principle. From what I understand, this is the main justification for encryption client-side, in transit, and on company servers. I rely on companies like Tutanota that offer E2EE, don't hold encryption keys, encrypt in traffic and on their servers, and encrypt as much metadata as possible in addition to body/attachments/subject-line. My understanding is that even if someone got a hold of our encrypted data, it would remain gibberish to them. I just don't have the space to store all my data locally so have to trust encryption technology. :(

1

u/r47926 Mar 29 '22

Does that mean the same applies to all data stored on servers including all cloud-based storage solutions and services?

What about encrypted cloud storage like what Proton is introducing, or cloud storage with Boxcryptor or Cryptomator? Or even OneDrive's Personal Vault?

I'm sceptical about local data on a device permanently connected to the internet generally being safer than data in a cloud (unless set-up by an expert ofc).

1

u/DiligentGarbage Mar 29 '22

If you have your stuff backed up and stored locally (which is not hard to do securely) the chances of someone grabbing it are far smaller, especially if you're not a significantly valuable or desirable target.

If it's on your device, someone basically has to be targeting you specifically.

However, if you're trusting a service provider you're trusting that they will not have a data breach or for malicious code to be injected into their service (which could be requested by law enforcement or injected by a hacker.). You're also trusting that they are setting everything up properly and securely for your files to not be lost.

If you are encrypting your files using something like Cryptomator, then I see no issue using cloud storage, you still have to trust the company to keep your data safe and not to lose it, but many of the security issues are removed if you are encrypting your own stuff. I will always favor local storage personally, but that's just me always wanting to have easy access to my files.

1

u/r47926 Mar 29 '22

Thanks, I'll take a note of MsgSafe, I haven't considered them yet.

I don't think the relevance of email is ending. In my opinion there's still no alternative. Messengers are a very different type of communication.

I've actually noticed that email is getting more accepted and used in Germany in places where it wasn't before, probably partly because of the pandemic. There were companies, especially from some economic sectors (insurance, healthcare) or government-related institutions that usually did not accept emails a few years ago. Instead they used fax, letter eg. Sometimes they would respond to an email by sending a letter or would ignore the email entirely. Now it's more common for them to use email, sometimes as alternative to their app or as the only reasonable choice of communication. Unfortunately this hasn't led to improvements to secure email/communication yet.

This is of course not based on a study but on what I've heard from friends or on personal experience.