ProtonMail and the like do more to protect you from the government, if that's your threat model, but you're going to lose out on a lot of features as well, because a lot of common expectations in email don't work with end-to-end encryption.
Using Thunderbird plus Enigmail for GnuPG, I can use any email provider, and be ~certain that they can't read my stuff.
Yes but no one can either :( In the last 5 years I received 2 encrypted emails, and thousands of non encrypted emails. The problem with PGP is that almost no one is using it.
Maybe the people you email with do use it though.
But whatever. The ability to use GnuPG serves as a filter ;)
This means that maybe now the private keys are on your device, at any point in time they can update their frontend javascript code to get your private key and read all your emails.
> The ability to use GnuPG serves as a filter ;)
Yes definitely, I wouldn't get any emails at all anymore. Works great for Inbox Zero I guess.
That's the risk. By default, the filesystem isn't accessible to Javascript. But here, you've authorized key access for encryption and decryption. I suppose that Thunderbird and Enigmail could be modified to do much the same. But arguably that would be discovered quickly.
Ideal case is one end-to-end protected in a country with stronger, legal protections for customers. ProtonMail fits that bill but lacks maturity. Some of us want our mail to definitely be delivered with a provider that will stick around long time. FastMail has the edge there over ProtonMail.
i.e. I want paid G Suite to work like Office 365 Personal (which I do pay for), not Office 365 Business.