All of these are good points. You make a strong argument that there might be little need for a web interface.
A few other thoughts, though:
- You could still do spam filtering, of course. If it scores highly as spam and the user trusts the spam filtering, it could be deleted or moved into a likely spam folder. (I'm assuming plaintext email is encrypted automatically right away.)
- If the encryption is handled on the client side, Google would NOT be technically capable of decrypting your mail. They would not be able to comply with a court order demanding they decrypt your mail. This is what the original version of Hushmail did, before they added the flawed later version that was exploited by FedGov in, if I recally properly, precisely the way you describe.
A few other thoughts, though:
- You could still do spam filtering, of course. If it scores highly as spam and the user trusts the spam filtering, it could be deleted or moved into a likely spam folder. (I'm assuming plaintext email is encrypted automatically right away.)
- There are provably secure techniques to perform searches on encrypted data assuming an untrusted server, such as: http://www.cs.berkeley.edu/~dawnsong/papers/se.pdf
- If the encryption is handled on the client side, Google would NOT be technically capable of decrypting your mail. They would not be able to comply with a court order demanding they decrypt your mail. This is what the original version of Hushmail did, before they added the flawed later version that was exploited by FedGov in, if I recally properly, precisely the way you describe.