Of course, an MITM attack could hide the STARTTLS option and there are questions around the strength of the CA cert infrastructure, but SMTP is not just plaintext.
So even if I setup and host my own SMTP server, and even if I verify the TLS certs on my side, I have no way to verify that I'll get (1) A TLS connection (2) with an authenticated cert all the way to the ultimate destination.
It's beyond my control to ensure that I'm secured when emailing to an arbitrary domain with arbitrary configuration.
Can the US serve a warrant to a server in Europe run by Europeans? I was assuming the answer was no, in which case you don't need violate any laws or worry about repercussions.
The whole protocol and mail delivery system is fucking hopeless.
As an ex-ISP mail architect and ex-operations guy, I hope the whole existing email protocol suite and architecture dies in a fire.
Companies could at least insist that intra-company email is encrypted, which would be a huge amount of their normal communications, and then extend that outside their boundaries with partners who also accept (say) S/MIME.
At present I sign my mails but like you have no clients who use encryption.
The core problem with widespread crypto use today is not encryption, it's trusted key exchange.
But as it happens, yes, I trust our crypto developers. They're much better at it than most of HN.
And the rest of the code is pretty shitty in places.