Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They could have shut down that method. (Server-side webmail access)

You _always_ have a choice.



Or they could have fixed it to the do the encryption client side. In this case that would be in JavaScript since it is a webmail client.


Did you read the article, which talks about the two options that Hushmail offers? The server side (weak) encryption and the client side Java option?

And the fact that even Hushmail said that they could be forced to serve malformed Java applets to targets.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: