<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.2.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Committee to Protect Bloggers &#187; Hushmai</title>
	<link>http://committeetoprotectbloggers.org</link>
	<description>Free speech for bloggers worldwide</description>
	<pubDate>Fri, 21 Nov 2008 00:44:42 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.2</generator>
	<language>en</language>
			<item>
		<title>Hushmail Breaks Your Silence</title>
		<link>http://committeetoprotectbloggers.org/2007/11/08/hushmail-breaks-your-silence/</link>
		<comments>http://committeetoprotectbloggers.org/2007/11/08/hushmail-breaks-your-silence/#comments</comments>
		<pubDate>Thu, 08 Nov 2007 12:20:11 +0000</pubDate>
		<dc:creator>Curt</dc:creator>
		
		<category><![CDATA[Email]]></category>

		<category><![CDATA[Hushmai]]></category>

		<guid isPermaLink="false">http://committeetoprotectbloggers.org/2007/11/08/hushmail-breaks-your-silence/</guid>
		<description><![CDATA[Update: A further report by Threat Level indicates Hushmail will be admitting to its users its intention and ability to provide their information to anyone with a Canadian warrant.

Hushmail, the web&#8217;s leading provider of encrypted web mail, updated its explanation of its security model, confirming a THREAT LEVEL report that the company can and will [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Update</strong>: A further report by <a href="http://blog.wired.com/27bstroke6/2007/11/hushmail-to-war.html">Threat Level</a> indicates Hushmail will be admitting to its users its intention and ability to provide their information to anyone with a Canadian warrant.</p>
<blockquote><p>
Hushmail, the web&#8217;s leading provider of encrypted web mail, updated its explanation of its security model, confirming a THREAT LEVEL report that the company can and will eavesdrop on its users when presented with a court order, even if the targets uses the company&#8217;s vaunted Java applet that does all the encryption and decryption in a browser.</p></blockquote>
<p>According to <a href="http://mashable.com/2007/11/07/hushmail-offers-feds-a-peek-at-users-data/">Mashable</a>, <a href="http://hushmail.com/">Hushmail</a>, the Canadian web mail that has built its brand on being safe, has given up, and will continue to give up, information on its users to any hot young thing waving a warrant. </p>
<p>Hushmail &#8220;has turned over 12 CDs (full of information on ) three Hushmail accounts to US Federal authorities.&#8221;</p>
<blockquote><p>On their website, they say “not even a Hushmail employee with access to our servers can read your encrypted e-mail.” . . . Hushmail uses OpenPGP and AES 256 to encrypt the contents of messages server-side. Theoretically, with the contents of one’s emails encrypted on the server, even if Hushmail were compelled to turn over the contents of one email, brute-force decryption routines should make the cracking process time-prohibitive.</p></blockquote>
<p>&#8220;To date,&#8221; said Brian Smith, the company&#8217;s CTO in an <a href="http://blog.wired.com/27bstroke6/hushmail-privacy.html">email exchange with Wired</a>, &#8220;we have not challenged a court order in court.&#8221;</p>
<p>So, if you use Hushmail to avoid a security service&#8217;s scrutiny, trusting the manifold claims that it makes to being safe, think again. Any government, with enough time and money, can figure out who you are if you&#8217;re online. Any government that has the help of Yahoo or Google, or Hushmail, doesn&#8217;t need as much time, or as much money. </p>
<p>Thanks, Hushmail, for lowering the bar. </p>
<p>Read more on <a href="http://blog.wired.com/27bstroke6/2007/11/encrypted-e-mai.html">Wired&#8217;s Threat Level</a> blog.</p>
]]></content:encoded>
			<wfw:commentRss>http://committeetoprotectbloggers.org/2007/11/08/hushmail-breaks-your-silence/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
