email encryption
a day ago
- Email was designed in an era of trust, lacking security features like confidentiality and integrity.
- MIME was created to handle non-ASCII content but added complexity and inefficiency.
- X.400 was a comprehensive but failed OSI standard for encrypted email, reliant on a global directory.
- PGP introduced end-to-end encryption with a 'web of trust' key model, but suffered from usability and scaling issues.
- S/MIME became the corporate standard using PKI and certificate authorities, yet remains complex and non-interoperable.
- Modern email encryption often relies on in-transit protections like STARTTLS, DANE, and MTA-STS, which are transparent to users.
- End-to-end encryption (PGP/S/MIME) has low adoption due to complexity, while service-provider encryption is more common.