Having the list re-encrypt and re-sign each message is a good idea
if the list of activities you are seeking to forestall includes
traffic analysis.

If the server re-encrypts and re-signs each message, and the
moderator forwards messages to other recipients in batches
only once a day or so, then it becomes less obvious which
sender was responsible for writing which message.

Of course it's only a small part of the job.  If you really
want to defend against traffic analysis, you have to generate
cover traffic sufficient to (and in the complementary pattern
to) make the real traffic indistinguishable from noise.


