Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Since we need to know who to send the e-mail to, we should encrypt everything except the recipient address.

I would argue all that should be unencrypted us the recipient domain, just like https



I agree this would be a good thing. Problem is that then the access of the public key needs to be encrypted too, which in turn means you need to make sure you use HTTPS. I think this would be a good thing, but I'm hesitant to make it an requirement.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: