Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I guess I don’t understand why you would think that the following wouldn’t work: - use random email addresses - encrypt the content with something more secure than PGP (on the client) - receive the email and decrypt it (on the client)

Sure, it’s plaintext, but I don’t see the downside?



How do I securely communicate what the new email address is? How do I hide IP-level metadata? How do I hide time-level metadata? How do I do PFS?

At some point you're going to keep adding lipstick to the pig until eventually you have something morally equivalent to the pathological example I gave.


That's interesting. Thanks for taking the time to expand on it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: