Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why make unencrypted the default? For https, encrypted has become the default. Users don't need to understand certificates at all, but it works. We should have the same for email.

But that does require all clients to make this easy for the user.



We should have the same for email.

But we don't. And while we don't, users have a reasonable expectation that they can send an email and the other person can read it.


HTTPS is transport-level encryption. If that's your benchmark, email is encrypted by default today – in that most SMTP connections are TLS-encrypted.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: