Email encryption is fundamentally flawed and cannot be made safe due to plaintext defaults, metadata leakage, and design limitations that allow unencrypted replies. The article argues that encrypted email provides false security for most users and that secure messaging platforms are superior alternatives.
A security researcher disclosed multiple vulnerabilities in GPG discovered in 2025, including signature spoofing and memory corruption bugs. While some issues were patched, others remained unaddressed despite advance notice, prompting a detailed talk at 39c3 examining the vulnerabilities, GnuPG's response, and broader implications for responsible disclosure and security.
In 1997, PGP Inc. published encryption source code in book form to circumvent U.S. export controls, arguing that selling books is protected speech under the First Amendment. After a copy was secretly exported via FedEx, the company faced investigation but ultimately prevailed, leading to cryptography's removal from the Munitions List and establishing that code qualifies as free speech.