Its not about convenience.
its about money. Like everything really.
Using GPG/PGP for example (which IMO is the best solution) is nice. It has a good, convenient design.
The clients, UI, etc are terrible. Theyre extremely inconvenient.
That can be fixed. This needs some time and a little dedication.
Nobody will pay for a product that has proper, easy, fast PGP support across the board. Nobody.
Since it's not a trivial task, and the benefits are "only" privacy, it didn't happen yet.
If anything, people re-code their own, incompatible and generally lesser version of PGP, because they will get financial gain, or popularity from it (patching GPG doesn't give you as much popularity as making your own, you see.. and we're quite ego-driven / NIH-happy)
So, here we are. And I'm to blame too, I haven't worked on this either.
I'm secretly hoping things like PRISM will actually help making this move forward.
You could build a Chrome (or Firefox) extension that added GPG/PGP/SMIME to Gmail, you would have to intercept the emails before they were stored as drafts in order to protect the message in the inbox. You could use a plugin or native client to interface with the OS or desktop environment's keystore to keep the private key out of Javascript.
The key passphrase could double as the passphrase for symmetrically encrypting the message stored in the inbox.
Add to this a keyserver for automatically discovering public keys of contacts and you have a "good" solution between interested parties, without compromising recoverability of the majority of your messages.
You could do the same for Gtalk/Hangouts chats with OTR.
Using GPG/PGP for example (which IMO is the best solution) is nice. It has a good, convenient design. The clients, UI, etc are terrible. Theyre extremely inconvenient. That can be fixed. This needs some time and a little dedication. Nobody will pay for a product that has proper, easy, fast PGP support across the board. Nobody. Since it's not a trivial task, and the benefits are "only" privacy, it didn't happen yet. If anything, people re-code their own, incompatible and generally lesser version of PGP, because they will get financial gain, or popularity from it (patching GPG doesn't give you as much popularity as making your own, you see.. and we're quite ego-driven / NIH-happy)
So, here we are. And I'm to blame too, I haven't worked on this either. I'm secretly hoping things like PRISM will actually help making this move forward.