Hacker News new | ask | show | jobs
by zaarn 2744 days ago
That's no longer the case, you can set PM to send PGP encrypted mail directly, in which case the mail won't be in cleartext on their servers.

Sending a link with a symmetrically encrypted mail is still possible for users without PGP but those aren't in cleartext on the server either (they are encryped and decrypted) in the client.

(in theory, PM could swap code in the webclients but you can use the Bridge or Android/iOS app to circumvent that hole easily)