Tester guide
Trying out CryptPad
About 20 minutes. Six short tasks.
Thanks for helping. The chapter is looking at three ways to replace Google Drive, and you are trying one of them.
You are not being tested. The software is. If something is confusing, that is the most useful thing you can tell us. If you cannot work out how to do one of these tasks, give it two minutes and then say so. "I could not find it" is a real answer and we want it.
Read this before you sign up
CryptPad works differently from the other two, and two of the differences will catch you out if nobody says them first.
You choose your own password, and nobody else can ever see it
There is no password to send you, and no public sign-up page. The personal invitation link you were sent is the only way in, and it creates one account, for you.
Write your password down before you finish signing up. CryptPad encrypts everything in your browser, which means the server genuinely cannot read your documents. It also means nobody can reset your password or recover your documents if you lose it. Not the person who sent you this, not an administrator, not anyone. That is not a limitation we are working around. It is the exact property we are testing.
Your browser may block it without telling you
CryptPad loads its editor from a second address,
cryptpad-sandbox.odsapilot.com. That is deliberate, and it is a security
boundary. You never visit that address yourself, but your browser does, and privacy
tools often read it as tracking and block it. What you see is a blank pane, or a sign up
that hangs on "Hashing password" forever, with no error message anywhere.
Fix it once, before you start:
- Open cryptpad.odsapilot.com.
- Click the shield icon in the address bar.
- Turn Enhanced Tracking Protection off for this site. That is the only toggle you need, and it applies to CryptPad only.
If you use an ad or content blocker such as uBlock Origin, Privacy Badger or Brave
Shields, allow both cryptpad.odsapilot.com and
cryptpad-sandbox.odsapilot.com in the blocker's own settings.
Tell us if you hit this. Nearly everyone does, it comes back on every new browser, and it is unpaid work the chapter would be doing forever. It is not a mistake on your part, and we are counting it.
One more ground rule
Do not put anything real in here. No member names, no phone numbers, no actual chapter business. The whole server is deleted at the end of the pilot.
Getting in
- Open your invitation link.
- Choose a username and password, and write the password down.
- Open Teams in the left-hand menu. You have been added to the ODSA Pilot team, and the documents are in its drive.
- You may also see your own chapter's team. That one belongs to your chapter, and the tasks below do not use it.
The six tasks
1. Upload a file
Add any harmless file to the team's drive. A photo or a PDF is fine.
2. Share a link
- Create a link to a document.
- Send it to whoever asked you to do this.
Tell us: could you tell, from what was on screen, who would be able to open that link? Look closely at this one. CryptPad's links work differently from the other two platforms', and noticing how is worth more than finishing the task.
3. Co-edit a document
- Open the team's Committee meeting notes.
- Ask one other person to open it at the same time.
- Both type into it.
Tell us: did you see the other person's cursor and their words as they typed?
4. Comment on a document
Leave a remark about a document rather than a change to it. If you conclude there is no way to do that, say so. It is a fair answer and a useful one. Do not spend more than two minutes hunting.
5. Find a file
Search two ways.
- Search by name for the meeting notes from July.
- Search for the word Kestrel, which is inside two of these documents.
Tell us: did the second search find anything? On a system that encrypts everything before it reaches the server, the answer here may differ from the other two platforms, and that difference is one of the most important things this pilot can learn.
6. The two-system question
You also have an account on Nextcloud or OpenCloud, where the chapter's ordinary files live. This system is the one holding the sensitive document.
Tell us, having used both: did having the sensitive document somewhere else feel sensible, or did it feel like being made to do the same job twice?
This mirrors something the chapter already does. Ordinary business happens in the open, and anything sensitive happens on Signal instead. We want to know whether that works for documents, or whether people would quietly stop bothering.
If you get stuck
Try the tasks without help first. Whether an ordinary member can do them unaided is the single thing this pilot is measuring, so a task you could not finish is worth more to us than a task you finished by reading the manual.
Once you have had a go, the people who make CryptPad publish their own instructions:
If you needed it, say which task sent you there. That is a result about the software, not about you.
What to send back
Fill in the feedback form once for this platform, ideally straight after your session while it is fresh. Cover:
- which of the six tasks you finished without asking anyone for help
- which task you gave up on, and roughly how long you lasted
- whether you hit the blank-page problem, and how long it took to get past it
- the one thing that annoyed you most
- your answer to task 6
One extra question, only on this platform: did knowing that nobody can recover your password change how you felt about using it? Some people find that reassuring and some find it alarming. Both are useful, and there is no right answer.
Questions go to the Tech Committee Co-Chairs, currently Esteban and Sebastian, on Discord or Slack.