This is a tragedy. We need to reboot email. Encrypt everything, including metadata -- given current hardware, the client can easily bruteforce it from a list of known keys. Build some sort of easy key distribution tool (connecting via p2p, dns, whatever, just build a goddamn UI). Ask existing transports to relax their restrictions enough to let fully-encrypted mail through, and build some intelligent webmail interfac…
The Direct Project is an email encryption scheme that hopes to replace the mail and fax currently used by American physicians to communicate patient health information. It is a requirement for Stage 2 (2014) Meaningful Use certified EHR software. So this is going to be adopted on a large scale in the next year or two. It uses SMTP to transmit SMIME messages signed with X.509. Public keys for recipients are discovered…
We have a version of the java reference implementation up and running, so I can vouch for it. I have been thinking about it in context of the privacy atmosphere for quite a while now. On one hand I'm excited that such a technology could also be used for secure communication and on the other I'm worried that health records will be susceptible to the same coercion.