3 ms·
Absolutely, but I don't see why it couldn't still manage public keys for verifying signatures and encrypting outgoing mail. Your private key could still be han
by koanarc 17y ago
Absolutely, but I don't see why it couldn't still manage public keys for verifying signatures and encrypting outgoing mail.
Your private key could still be handled locally. Hell, even if they left signing and decryption (the parts you'd need your private key for) entirely up to the browser or plugins or a full-blown mail client, you could still verify signed mail that you'd received and send out encrypted mail from within Gmail's interface. That alone could go a long way towards encouraging cryptography beyond the security-conscious crowd. At the very least, it spreads awareness.
EDIT: Also, as far as my more unimportant emails are concerned, I'd rather have them bouncing around the internet encrypted by a compromised/throw-away key (i.e., one that Google has access to) than not encrypted at all. But in common use, yeah, the illusion of security would be worse than no security at all.