Hacker News new | past | comments | ask | show | jobs | submit login

It would be nice if there was an extension to SMTP which allowed the receiving server to inform the sending server of the recipients public key, so that the message could be encrypted at the sending servers end before being passed on. That way, the receiving server wouldn't see the plain text.

Silent Circle had a feature where people could upload their public keys to their keyserver and then Silent Circle would encrypt any outgoing email to that person with their key if it wasn't already encrypted. Something like that, but more automated.

As for meta-data, when I looked at Silent Circles services, they were adding Received headers to email which contain the senders IP address. I know that's common, but it's certainly not required. Even Google don't do that with GMail. There was definitely plenty of room for improvement. How about a mail service which packs the entire message including headers into the MIME body of a new message before enrypting. So the original message headers are all secured too. It wouldn't look as nice in the receivers mail client, but it would be much more secure.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: