Lavabit appeal against data handover
bbc.co.uk
bbc.co.uk
It would be nice to look back on this in 2 years with a "what were we thinking?" attitude towards email as it currently exists, as we all moved to a better solution invented by smarter people than me.
Most people won't know or care or know that they should care.
It would not be far-fetched at the moment to imagine that Google has been explicitly barred from implementing a feature in GMail that would prevent them from being able to provide the contents of a person's mailbox to the NSA or FBI if requested.
Indeed you have to wonder why not one major email provider has offered a paid option for secure mail. As others have pointed out, that still leaves meta-data in the open. But secure-payload plus pseudonymous, deniable identities makes targeting difficult and unreliable. That would be a big improvement.
Oh wait, there is such a way. It's absolutely decentralized, everyone is free to join and use it and add encryption on top, and it's called SMTP.
As much heat as cryptocat has taken - I think they have the right idea and are working on an important problem (whispersys too). Security should be built in and easily adoptable. It should be equivalently usable to what people are already communicating with or they won't use it.
At best, tor+pgp would allow you to create a pseudonymous email address (or series of addresses), but there would still be nothing stopping people from looking at your mailbox and seeing what other addresses you've communicated with, even if they can't decipher what those communications are.
The SMTP protocol itself needs rewritten to function more like tor, so that each intermediary is incapable of seeing the complete picture.