The Register® — Biting the hand that feeds IT

Feeds

Hushmail warns users over law enforcement backdoor

Still secure, up to a point

Agentless Backup is Not a Myth

Hushmail has updated its terms of service to clarify that encrypted emails sent through the service can still be turned over to law enforcement officials, providing they obtain a court order in Canada.

September court documents (pdf) from a US federal prosecution of alleged steroid dealers reveals that Hush Communications turned over 12 CDs involving emails on three targeted Hushmail accounts, in compliance of court orders made through the mutual assistance treaty between the US and Canada. Hushmail is widely used by privacy advocates and the security-conscious to send confidential emails.

Hush Communications, the firm behind Hushmail, previously claimed "not even a Hushmail employee with access to our servers can read your encrypted email".

However an updated explanation states that it is obliged to do everything in its power to comply with court orders against specified, targeted accounts. Unlocking targeted accounts involves sending a rogue Java applet to targeted users that captures a user's passphrase and sends it back to Hush Communications. This information, when passed onto law enforcement officials, allows access to stored emails and subsequent correspondence sent through the service.

The possibility that law enforcement officials can tap targeted accounts exists whether or not Hushmail users use the supposedly more secure Java applet option or a simpler web server encryption set-up. The updated terms of service explain:

Hushmail is a web-based service, the software that performs the encryption either resides on or is delivered by our servers. That means that there is no guarantee that we will not be compelled, under a court order issued by the Supreme Court of British Columbia, Canada, to treat a user named in a court order differently, and compromise that user's privacy.

International criminals and terrorists ought to look elsewhere for their encrypted email needs, Hush Communications explains.

"If you expect to engage in activity that might result in a court order issued by the Supreme Court of British Columbia, Canada, Hushmail is not the right choice for you," it said, adding that stand-alone desktop encryption packages such as PGP Desktop provide higher levels of security than web-based services.

PGP creator Phil Zimmermann has long fought to keep the software free of backdoors. Even after the September 11 attacks his convictions about privacy and civil liberties were strong enough to withstand pressure to tamper with the software, despite evidence it was been used by terrorists as well as its intended audience of human rights activists.

However, Zimmermann has defended Hushmail compliance with court orders, arguing that users who pick web-based products for their ease of use can't expect absolute security. Zimmermann, who sits on Hushmail's advisory board and helped found the service, told Wired: "Just because encryption is involved, that doesn't give you a talisman against a prosecutor. They can compel a service provider to cooperate."

Zimmermann explained that Hushmail has little option but to comply with Canadian court orders, adding that the service remained far more secure than other webmail services. ®

Steps to Take Before Choosing a Business Continuity Partner

Latest Comments
Anonymous Coward

Ah - but one can maketh a mess..

The entertaining thing is that data access still does not equal data quality. The more Big Brother invades, the more deception becomes an entertaining passtime.

That is a rather weak point in any data collection system: it lacks the brains to detect deception (which is why, for instance, data corruption is such a menace - it's not detected until the damage is so great that it's even obvious to an algorithm).

A bit of martial arts knowledge helps here: to avoid getting hit, block, deflect or avoid. Avoid is impossible here, blocking means your force against an unknown counterpart. Deflection seems thus the better approach, not to mention the most entertaining one..

0
0
Anonymous Coward

@ The Auditors

that makes 90%...

0
0

Privacy

... "at least thoughts ... are still private" ...

Hah! We, The Auditors, have been unencrypting humans' thoughts for aeons. Frankly, most of them are rubbish! About 55% are about sex and 35% about food.

0
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Internet fraud still stings suckers
Australians twice as gullible as Americans
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?