The best solution right now is probably to use a desktop app that encrypts e-mails locally with OpenPGP before sending them.
Can't someone make a Chrome extension that does the same for Gmail, though? There seem to be a few solutions for Firefox.
Can't someone make a Chrome extension that does the same for Gmail, though? There seem to be a few solutions for Firefox.
Basically, the server you're talking to, as well as any resources on that page, can undermine your javascript primitives and render your crypto useless (or just backdoor it).
If you trust the server to not backdoor your crypto... you can just trust the server to _do_ the crypto in the first place.
There is an effort underway to build better crypto APIs into browsers, but I'll bet you a bitcoin that it's super easy to fuck up the implementation of and most end up being insecure, and/or nobody ends up using it after all.
Google controls the key/cert that allows for Chrome extension updating...