No, not really. It's hard to see how any service on top of Internet email will ever be more secure than gpg (with the possible exception of a scheme similar to gpg that ensures forward secrecy).
Mixmaster remailers might add a little something wrt meta data -- but not enough to trust that difference IMNHO (assuming a large part of mixmaster servers are run by, or grants access to, various NATO-allied intelligence services).
In essence, secret keys and trust in public keys needs to be managed by the participants -- no third party can meaningfully manage it.
Not that GPG is particularly secure in the real world -- but it is much more secure than not using any form of encryption.
As have been mentioned elsewhere, a scheme where a provider encrypts email for you can never be provably secure, because it's almost impossible to show that the session keys used to encrypt data aren't selected from some predictable subset of the keyspace (say 1M keys derived from every date stamp with hour precision, keyed up with creation time?).
By that analogy so called secure email providers would receive plain letters and put those into envelopes before handing them to you, and conversely ripping your envelopes open before sending out your mails. Because the rest of the world doesn't know how to use envelopes.
These are great if you understand and accept the risks.
If one of your risks is a well-funded agency of the US / UK government then these probably aren't a suitable option. Also, you'll want to change your OS to something hardened; and also your computer; and also put better locks on the doors; and also move to a building with no ground floor windows and some nice high fences with CCTV and good access controls.
Comments
so apparently there's no reason for lavabit, silent mail, hushmail ...?
No, not really. It's hard to see how any service on top of Internet email will ever be more secure than gpg (with the possible exception of a scheme similar to gpg that ensures forward secrecy).
Mixmaster remailers might add a little something wrt meta data -- but not enough to trust that difference IMNHO (assuming a large part of mixmaster servers are run by, or grants access to, various NATO-allied intelligence services).
In essence, secret keys and trust in public keys needs to be managed by the participants -- no third party can meaningfully manage it.
Not that GPG is particularly secure in the real world -- but it is much more secure than not using any form of encryption.
As have been mentioned elsewhere, a scheme where a provider encrypts email for you can never be provably secure, because it's almost impossible to show that the session keys used to encrypt data aren't selected from some predictable subset of the keyspace (say 1M keys derived from every date stamp with hour precision, keyed up with creation time?).
There is if you still care about keeping the contents of your message secure.
Or in a simpler sense; do you put your letters in an envelope, or do you just put a stamp on the paper?
By that analogy so called secure email providers would receive plain letters and put those into envelopes before handing them to you, and conversely ripping your envelopes open before sending out your mails. Because the rest of the world doesn't know how to use envelopes.
These are great if you understand and accept the risks.
If one of your risks is a well-funded agency of the US / UK government then these probably aren't a suitable option. Also, you'll want to change your OS to something hardened; and also your computer; and also put better locks on the doors; and also move to a building with no ground floor windows and some nice high fences with CCTV and good access controls.