Legacy end-to-end encryption is too cumbersome for most people to adopt for mail. We still support those who want it, via OpenPGP, with the goal of interoperating cleanly with existing clients.
There is one tension worth stating in the open: to index an email, it has to be readable. Encrypt everything and search dies. Encrypt nothing and you have failed the people who actually needed protection.
It is not helpful to spend the resources encrypting newsletters. Bank receipts, yes.
We are working on automatic protection based on a more careful reading of what a message is. Higher protection when it is warranted; faster search and a lighter system when it is not. That is how you make private mail something people will actually live in.
Coming, not vapor
- Additional two-factor options
- SMS notification of urgent or rule-matched messages
- Our own webmail, without a third-party humanity check
- Our own mailing-list application, replacing an aging PHPList
The mailing list we run today is PHPList — popular, capable, and old. We are writing a replacement that can live on the same high-availability design as the rest of the service.