Hushmail turns out to be anything but

Powered by SC Magazine
 

A court document in a drug smuggling case has shown that the private email service Hushmail has been cooperating with police in handing over user emails..

Hushmail claims to offer unreadable email as it uses PGP encryption technology and a company specific key management system that it says will ensure only the sender and recipient can read the emails. However it seems the Canadian company has been divulging keys to the American authorities.

The document describes the tracking of an anabolic steroid manufacturer who was being investigated by the Drug Enforcement Administration (DEA). The document alleges that the majority of those engaged in the trade in anabolic steroids use Hushmail to communicate.

The DEA agents received three CDs of decrypted emails which contained decrypted emails for the targets of the investigation that had been decrypted as part of a mutual legal assistance treaty between the United States and Canada.

The news will be embarrassing to the company, which has made much of its ability to ensure that emails are not read by the authorise, including the FBI's Carnivore email monitoring software.

"Hushmail's security cannot be broken or weakened by this government sponsored snooping software," the company states.

"The only way to decrypt or unscramble Hush messages is by using your passphrase when you open up your Hushmail account. Carnivore cannot decrypt your mail, and is therefore, powerless against messages sent between Hush users."

Copyright ©v3.co.uk


 
 
 
Top Stories
ATO shaves $4m off IT contractor panel
Reform cuts admin burden, introduces KPIs.
 
Turnbull introduces data retention legislation
Still no definition of metadata to be stored.
 
Crime Commission prepares core systems overhaul
Will replace 30 year-old national criminal database.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
In which area is your IT shop hiring the most staff?




   |   View results
IT security and risk
  27%
 
Sourcing and strategy
  12%
 
IT infrastructure (servers, storage, networking)
  21%
 
End user computing (desktops, mobiles, apps)
  14%
 
Software development
  25%
TOTAL VOTES: 433

Vote
Would your InfoSec team be prepared to share threat data with the Australian Government?

   |   View results
Yes
  54%
 
No
  46%
TOTAL VOTES: 209

Vote