If someone modifies the server side of gmail they can still snoop the email before it gets encrypted.
That and being non-standard, so basically forces users to use the same service and gmail
That and being non-standard, so basically forces users to use the same service and gmail
Like we said, this is a starting point. It's open source. As with any type of security product that has a hope of being good, try and break it and let's fix it together :)
I believe that Google does releases of the entire application at once so this method should detect when a roll-out has occured.
In a comment on encrypting gtalk, I explained how this can be done: https://news.ycombinator.com/item?id=5858375