Secure email a "daunting challenge"

It isn’t merely an implementation problem, unfortunately: Getting people to securely store keys is… not really in the cards on most of the flyblown computers of today, and the classier brand of geek mercs (looking at you VUPEN) claims to have zero-days on tap for practically every OS you can buy, not just the usual windows trojans. Somebody needs to get non-backdoored HSMs down to a consumer price point, fast.

The other devil of the details is webmail. You want your email anywhere, nice and easy? Well, that means that your provider has to have the cleartext, so they can webpagify it and send it to you without any client software. Even today, setting up GnuPG isn’t that hard; but it more or less necessarily ties you to only those computers where you have an appropriate mail client and GnuPG set up. Even if the setup were effortless, encrypted email would still be garbage on any computer you don’t control and have time to install the client on.