Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Gonna name drop: I spoke to Phil Zimmerman about this yesterday. He says Hushmail had no choice, and they didn't willingly do anything. They had a well-known insecure access method which meant they had access to the content. The government simply required them to hand over content they had access to. So slamming them for this is not really appropriate.


> He says Hushmail had no choice

As Snowden, Manning, Assange and now the guy behind Lavabit are demonstrating, there is always a choice.

Hushmail could easily have just shutdown.


Right. "No choice" and "difficult choice" are not the same thing.


The case for hushmail is different then lavabit. Hushmail had some piece of information, legally they were required to hand that piece of information over. They may have had the option to shutdown shop after handing that over however.

For lavabit for all appearances did not have access to any information the government wanted and was not ordered to hand anything over. It seems like they were probably ordered to implement a method for the government to gain access to future communications. They choose to close up shop rather then implement this access and lie to their customers about the security of the service.


Well, not exactly.

HushMail strongly suggested that when given a court order and the targeted user was using the client-side Java applet, that Hushmail sent a backdoored applet. That technically could be detecting by checking hashes, but in practice...

It's an open question whether companies can be forced to build backdoor, but that sure looks like what happened to Hushmail and Lavabits.

(just noting that I'm the author of this more than 5 year old story).


Thanks for pointing that out. I was relying on a source that said otherwise, so for the future I will not trust it as much.

> can be forced to build backdoor,

It seems like they have the option of shutting down as an alternative to implementing a backdoor and lying to their customers about the level of security. If you know of examples of business forced to stay open and the owners forced to continue to work at a company for the purpose of government investigation I would be interested in learning more.


They could have shut down that method. (Server-side webmail access)

You _always_ have a choice.


Or they could have fixed it to the do the encryption client side. In this case that would be in JavaScript since it is a webmail client.


Did you read the article, which talks about the two options that Hushmail offers? The server side (weak) encryption and the client side Java option?

And the fact that even Hushmail said that they could be forced to serve malformed Java applets to targets.


Right. So why didn't they then close the insecure access method, and deny FURTHER content requests?


Because some people don't care about people with correctly-formed legal documents getting access to their email. They just want something quick and easy to prevent weaker attackers from having access.

EDIT: Not defending Hushmail here, but at least they have some warnings about the risks.


Hushmail was snake-oil from day one. Anyone who had spent more than 2 seconds reading about public key cryptography knew that. I was astounded to see Zimmerman defending Hushmail back then and saddened to hear that he is still defending them.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: