Monday, January 31, 2011

The Hushmail Myth

According to their website:

Hushmail is the most secure web-based free email service in the world. Since 1999, millions of people and thousands of businesses have trusted Hushmail to safeguard their secrets.

Hushmail looks and feels just like any other web-mail site, but adds strong encryption to your emails to protect your secrets from prying eyes.

It sounds Great; until you get to the Hushmail terms of service and the disclaimer.

"Hush does not guarantee that the uses of its Service, or the materials provided within the Service, are accurate, without error, or reliable"

https://www.hushmail.com/terms/business/

It sounds like they do not even guarantee their encryption.

Then there is the other problem:

Encrypted E-Mail Company Hushmail Spills to Feds

Hushmail, a longtime provider of encrypted web-based email, markets itself by saying that "not even a Hushmail employee with access to our servers can read your encrypted e-mail, since each message is uniquely encoded before it leaves your computer."

But it turns out that statement seems not to apply to individuals targeted by government agencies that are able to convince a Canadian court to serve a court order on the company
http://www.wired.com/threatlevel/2007/11/encrypted-e-mai/

As we state: Email is not for secure confidential business communications.