Software for encrypting email messages has been widely available for more than 15 years, but the emailusing public has failed to adopt secure messaging. This failure can be explained through a combination of technical, community, and usability factors. This paper proposes a new approach to email security that employs opportunistic encryption and a security proxy to facilitate the opportunistic exchange of keys and encryption of electronic mail. While it appears that this approach offers less security than established systems that employ certificates, the security is in fact equivalent to today’s systems based on PGP, PGP/MIME and S/MIME.
Simson L. Garfinkel