3 ms·
I'm pretty sure that would be a wasted effort. Basically, you could be nearly NSA-proof only if you use your own cert and are prepared to shut down the whole th
by ds9 12y ago
I'm pretty sure that would be a wasted effort. Basically, you could be nearly NSA-proof only if you use your own cert and are prepared to shut down the whole thing when the Feds demand private keys. But then it wouldn't be useful for general email: it will get blacklisted by various parties you would want to exchange email with, unless you use a CA.
Really the only readily-practical approach for NSA-proofing will be something that's user-friendly in the UI and encrypts end to end. This prevents snooping in transit, but still exposes metadata, and of course there are endpoint attacks.