As for the other option, it would be a minor inconvenience to have no contents at all, as the majority of the security bugs are not marked private. Since I already use LP to do the security bug reviews (email notifications tend to just be a "reminder" to go check the bug lists), it wouldn't be too bad for me. (As long as there's still a bug URL in the email, I'm happy.)
I wouldn't mind emails getting encrypted.
As for the other option, it would be a minor inconvenience to have no contents at all, as the majority of the security bugs are not marked private. Since I already use LP to do the security bug reviews (email notifications tend to just be a "reminder" to go check the bug lists), it wouldn't be too bad for me. (As long as there's still a bug URL in the email, I'm happy.)