This is a tragedy.<p>We need to reboot email. Encrypt everything, including metadata -- given current hardware, the client can easily bruteforce it from a list of known keys. Build some sort of easy key distribution tool (connecting via p2p, dns, whatever, just build a goddamn UI). Ask existing transports to relax their restrictions enough to let fully-encrypted mail through, and build some intelligent webmail interface for this (Mailpile, currently being kickstarted, is trying to do smt like that).<p>We've been dicking around with PGP since the 90s without making any real progress, we've traded security for convenience (GMail, Facebook), it's time somebody reverts the trend.