Ok, so you are saying that the main barrier to building this kind of system is essentially the difficulty of management on the side of the end user (rather than the IT dept). I understand that, and I do not disagree: there is more management required on the end user side, that is certain.
I do not consider a web page that uses Javascript, flash, or other scripting languages to be poorly written because the page uses those languages. On the contrary, I think that Javascript, flash, and others are terrific tools to enhance the web site user experience. Note the use of the words "enhance" and “toolsâ€. There are many cases in which I browse to a web site and it comes up as a blank white page because the site admin decided to code the entire thing in Javascript. Sure, NoScript users are a minority in the big scheme of things, but what about other users that simply do not have Javascript functionality? Javascript and others were meant to enhance the already existing functionality of a web page, not replace it.
I do have a problem with your assertation here:
'NoScript' and 'email default deny' requires constant management, which is not too easy to do if the users have IT knowledge below 'very skilled'.
My mother and my grandfather use NoScript. At first, I had to do a lot of teaching and explaining (and convincing!) before they were able to use their computers by themselves. Now, both of them cruise right along without even thinking about it. Niether of them are "very skilled" with regards to IT. I have not had to "fix" their computers from issues related to browsing for about a year, and I never had to re-teach anything about NoScript after the initial lessons. Both are still happy users of NoScript.
I mentioned at the beginning of this post that I worked at an organization that practiced this idea of "default deny" with email. It was a university that I worked at. Academia is not typically very accepting of things like this. However, 40+ year old men and women with no "skill" were able to understand that if they received an email and it was not from a source that they had added to their address book, it would go in their "junk" folder.
My point is that from prior experience, if the system is set up properly, it works without much (noticeable) management from the end user. In fact, in each case, I would say that users of NoScript and that email "system" were happier with the level of control that they had over their systems than the system that was in place before: if the browser allows a Javascript (or other) exploit, IT removes the virus, and if the inbox receives spam, just delete it manually. Everybody is better off when the end user receives some level of control in a default deny system.
Is there some level of wasted time? A learning curve? You bet. But from the way I see it, the time initially invested pays off immensely in the end.
Incidentally, I considered a proxy with a default block mechanism. Here is the problem with such a system: in situations in which the end user is not able to modify the whitelist for the proxy, management bureaucracy inevitably will take over and destroy the system. Think of those large companies or government agencies that employ such systems. Two main groups of people exist in such systems: one group which must submit to the system and either work around it or choose to go to a different system, and the other group, which is not controlled but is monitored. In order for a default deny system to work well, it absolutely must have end user controls, else it becomes a pain for everyone. I have worked in government, and I know this from experience.
Here is how such a proxy would function according to default deny but with end user control: each IP has a whitelist in the proxy (which could be made accessible to management). When a page is blocked, the end user can whitelist it and proceed. Eventually, the end user hardly ever sees the block page, and the company can begin building a "default" whitelist for new employees based on other employee whitelists.
Basic economics apply to computing as well: hands off government. NoScript and default deny email puts control in the hands of the end users. Complicated blacklisting systems put control in the hands of IT/management, the result being lost efficiency.
"Try to imagine how much time will take to tell every user how to whitelist a sender in an organization with more than 500 users."
Once one user (a manager) knows how to use the system, the news spreads like wild fire. Not to mention that if the system was already intuitive, the problem of lack of understanding is almost self correcting: if there is a big button next to every email in your junk/spam box that says "Not Spam!", people will eventually put 2 and 2 together.
"Before using postgrey, every user received more than ~4 SPAM messages / day."
I have seen statistics for a user at a company that I worked for regarding spam/junk. He had a great deal more spam than 4 messages per day. Perhaps your users are more careful about giving out their email address than he was. Either way, the system should work well regardless of the type of user (social butterfly vs quiet shut-in).
A default deny email system would work with individual email addresses: one email address at a time, you build your whitelists. Whitelist all of yahoo? Oh my.