Hacker News new | past | comments | ask | show | jobs | submit login

Now just for PGP support.



http://getfiregpg.org/

You don't want server side PGP support - you'd have to give your private key to Google. As much as I trust Google, I still don't trust them that much.

Much more secure to handle the crypto client side. Ideally, Google should work with the firegpg guy so that he has notice before they change the interface (FireGPG tends to break for a day or two whenever there is any change to the GMail UI).


Perhaps they could employ the HTML5 LocalStorage API to store keys.


While I agree that it would be best to not have to give your private key to Google, I think it would be a good start to get all email transmitted using the PGP protocol. Once the emails are being sent like that, those who don't want to trust Google, could more easily do it on the client side since it would be much more in use.

You would probably have to not use Google, since if they are unable to read your email, that kind of destroys their business model.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: