Webmail and Open Source
blog.whiteout.io
blog.whiteout.io
Really?
Edit: Just to be clear, I also agree it's a bit over the top.
What's the point then? Why not just use Thunderbird/K9Mail/dunno what's the Apple equivalent?
I find it extremely easy to use. And it should be quite secure.
- Is this different than using something like Roundcube over HTTPS ?
It might be misadvertised, but there is value in encrypting data at rest even if it's not encrypted in transit. The main benefit, of course, is forward secrecy.
If the government would like to read ed's email and he's using this technology, they can tap the wire or demand the mail host save an unencrypted copy. However, the government cannot read ed's past emails because they're encrypted.
Without this, anyone who compromises the server or takes out a warrant can get all past and future emails, not only all future emails.
If you want a better solution, simply have everyone who emails you gpg encrypt their messages. If your contacts aren't encrypting your messages there's little an email provider can do other than receive plaintext messages and, in rare cases like this one, encrypt them at rest.
My guess is that while there's some aspects of forward secrecy to the fact that you're using your GPG key to decrypt the e-mails client-side (which is significantly better than ProtonMail's approach, which is basically full-on snake oil), given the fact that a huge proportion of your non-PGP-using counterparties are going to be using Yahoo Mail, Hotmail and GMail anyway, anyone with a warrant will just get the full, unencrypted text of all your communications from them anyway.