We think the user experience is pretty great - works inside gmail, users need to know nothing about security or keys and you can send to any other gmail user (you don't have to worry if they have the correct software installed).
With any attempt at security and encryption, you usually trade off ease of use with how secure it is. We decided to use symmetric encryption because it made the user experience better. The only downside of course is that the security is only as good as the password the user chooses to encrypt the message with.
- we're using the Stanford javascript crypto library here: http://crypto.stanford.edu/sjcl/
- we open sourced our extension here: https://github.com/StreakYC/StreakSecureGmail
There have been a few other attempts at this, but they usually require users to understand how encryption works and require that all the users you send emails to have signed up for something (or have a public key somewhere). We think our attempt is ridiculously easy to use.This is a super early experiment/alpha/whatever so we see this as a starting point. Would love to get feedback!