3 ms·
This isn't surprising, but it does worry me. After some googling I found an e-mail service called hushmail (http://www.hush.com/ http://www.hush.com/) which pro
by marketer 17y ago
This isn't surprising, but it does worry me. After some googling I found an e-mail service called hushmail (http://www.hush.com/ http://www.hush.com/) which provides secure e-mail. Apparently it was started by the same guy who designed PGP. So if you want to send private e-mails, I'd use that account :)
- shrughes 17y agoHushmail? See http://www.wired.com/threatlevel/2007/11/encrypted-e-mai/ http://www.wired.com/threatlevel/2007/11/encrypted-e-mai/
- cryptnoob 17y agoAmazing how a single word and a question mark can convey the idea that somebody is crazy for mentioning something. Thanks for the link though. I had gotten a whiff, probably from statements like yours, that hushmail wasn't trustworthy, but hadn't known the source of this. Your link, actually, is very enlightening. For those not willing to read it, it turns out that hushmail provides two services, their original one, and one that is geared for people not willing to install a java applet. The 2nd one can be exploited by hushmail to decrypt your messages, and hushmail can be compelled by law enforcement to do that exploitation. However, if you use the java applet, you're golden.
- shrughes 17y agoCan't Hushmail still send you a bad java applet, though? I think Hushmail is trustworthy -- in the sense that they're not going to deliberately deliver broken code except when forced to by law enforcement.
- dablya 17y agoNot really... "But can the feds force Hushmail to modify the Java applet sent to a particular user, which could then capture and sends the user’s passphrase to Hushmail, then to the government?" ... "... The general point is that it is potentially detectable by the end-user, even though it is not practical to perform this operation every time. This means that in Java mode the level of trust the user must place in us is somewhat reduced, although not eliminated. The extra security given by the Java applet is not particularly relevant, in the practical sense, if an individual account is targeted."