orbitalflower

An idea for secure e-mail

Posted in Opinion on

This is a naive idea for a way to make e-mail more secure.

Problem

E-mail is ubiquitous, but not secure. The decentralised model makes it easy to forge a sender’s e-mail address, giving users no guarantee that their e-mail is secure. It’s radically easy for an attacker to send a user a link to an infected website or an attachment in a vulnerable document format like .doc or .pdf, which is common in business.

Solution

1. Browsers manage user keypairs

2. E-mail services run PGP keyservers

3. Webmail supports PGP

4. Public key also used for login

5. Key backup and revocation