I think there is an easier way: most of your friends probably use Google
servers for their mail, there is no need for the NSA to get packets from
your ISP to have these mails.

GPG keeps the text of your mails (i.e. usually some MIME parts) secret,
not the headers: the server knows the sender and receiver of the mail.
It's enough to learn the social network of the user, it does provide
some information about you.  (See e.g. the MIT gaydar study, it had
similar data from Facebook users.)

If you trust the servers, TLS (technically, SMTP with STARTTLS) prevents
the ISPs from learning the text or headers of the mail, they know only
who sends to what server.  It doesn't seem safe if the server usually
has only one user.  It's not secure: TLS isn't enabled for many mail
servers and there is usually no verification of certificates: an ISP/NSA
can make a man-in-the-middle attack to get the mail.  (Details:
http://www.postfix.org/TLS_README.html#client_tls_limits.)

Attachment: pgpe8SHMxogoL.pgp
Description: PGP signature

Reply via email to