Hushmail was founded by Cliff Baltzley in 1999 after he left Ultimate Privacy.
There is one type of paid account, Hushmail for Personal Use, which provides 10GB of storage, as well as IMAP and POP3 service.3
The standard business account provides the same features as the paid individual account, plus other features like vanity domain, email forwarding, catch-all email, user admin, archive, and Business Associate Agreements for healthcare plans. Features like secure forms and electronic signatures are available in specific plans.456
Additional security features include hidden IP addresses in e-mail headers, two-step verification7 and HIPAA-compliant encryption.8
An instant messaging service, Hush Messenger, was offered until July 1, 2011.9
Further information: E-mail privacy
Hushmail received favorable reviews in the press.1011 It was believed that possible threats, such as demands from the legal system to reveal the content of traffic through the system, were not imminent in Canada – unlike the United States – and that if data were to be handed over, encrypted messages would be available only in encrypted form.
Developments in November 2007 led to doubts amongst security-conscious users about Hushmail's security – specifically, concern over a backdoor. The issue originated with the non-Java version of the Hush system. It performed the encrypt/decrypt steps on Hush's servers, and then used SSL to transmit the data to the user. The data is available as cleartext during this small window of time, with the passphrase being capturable at this point, facilitating the decryption of all stored messages and future messages using this passphrase. Hushmail stated that the Java version is also vulnerable, in that they may be compelled to deliver a compromised Java applet to a user.1213
Hushmail supplied cleartext copies of private email messages associated with several addresses at the request of law enforcement agencies under a Mutual Legal Assistance Treaty with the United States:14 e.g. in the case of United States v. Stumbo.151617 In addition, the contents of emails between Hushmail addresses were analyzed, and 12 CDs were supplied to U.S. authorities. Hushmail privacy policy states that it logs IP addresses in order "to analyze market trends, gather broad demographic information, and prevent abuse of our services."18
Hush Communications, the company that provides Hushmail, states that it will not release any user data without a court order from the Supreme Court of British Columbia, Canada and that other countries seeking access to user data must apply to the government of Canada via an applicable Mutual Legal Assistance Treaty.19 Hushmail states, "...that means that there is no guarantee that we will not be compelled, under a court order issued by the Supreme Court of British Columbia, Canada, to treat a user named in a court order differently, and compromise that user's privacy" and "[...]if a court order has been issued by the Supreme Court of British Columbia compelling us to reveal the content of your encrypted email, the "attacker" could be Hush Communications, the actual service provider."20
Geist, Michael (2007-11-27). "Private E-mail Not Hush Hush". The Tyee. Archived from the original on 2020-01-02. Retrieved 2019-11-27. http://thetyee.ca/Mediacheck/2007/11/27/E-mailDropping/ ↩
Sutherland, Richard (17 November 2020). "Hushmail secure email review". TechRadar. Retrieved 2023-08-31. https://www.techradar.com/reviews/hushmail-secure-email ↩
"Hushmail for Personal Use". www.hushmail.com. Retrieved 2024-08-29. https://www.hushmail.com/plans/personal/ ↩
"Hushmail for Healthcare". www.hushmail.com. Retrieved 2024-08-29. https://www.hushmail.com/plans/healthcare-hipaa-compliant-email/ ↩
"Hushmail for Small Business". www.hushmail.com. Retrieved 2024-08-29. https://www.hushmail.com/plans/small-business/ ↩
"Hushmail for Law". www.hushmail.com. Retrieved 2024-08-29. https://www.hushmail.com/plans/legal/ ↩
"– Two-Step Verification". Archived from the original on 2014-06-25. Retrieved 2014-06-11. https://web.archive.org/web/20140625124114/https://help.hushmail.com/entries/63282756-Two-step-verification ↩
"Hushmail for Healthcare - HIPAA Compliant Encrypted Email, Web Forms & E-Signatures". hushmail.com. Retrieved 21 July 2022. https://www.hushmail.com/plans/healthcare-hipaa-compliant-email/ ↩
"Hushmail closes IM service". Archived from the original on 2013-10-27. Retrieved 2012-07-20. https://web.archive.org/web/20131027154541/https://help.hushmail.com/entries/20300582-Hush-Messenger-IM-service-to-close-July-1-2011 ↩
"Alternative Web Mail Review – Hushmail Premium, PC Magazine". Archived from the original on 2009-04-14. Retrieved 2017-08-31. https://web.archive.org/web/20090414204818/http://www.pcmag.com/article2/0,1895,1136652,00.asp ↩
E-Mail Encryption Rare in Everyday Use: NPR https://www.npr.org/templates/story/story.php?storyId=5227744 ↩
Encrypted E-Mail Company Hushmail Spills to Feds |Threat Level via Wired.com http://blog.wired.com/27bstroke6/2007/11/encrypted-e-mai.html ↩
Hushmail Privacy via Wired.com Archived 2007-11-10 at the Wayback Machine http://blog.wired.com/27bstroke6/hushmail-privacy.html ↩
bakersfield.com Archived 2008-07-24 at the Wayback Machine http://static.bakersfield.com/smedia/2007/09/25/15/steroids.source.prod_affiliate.25.pdf ↩
"Hushmail.com Privacy Policy". Hushmail.com. Archived from the original on 2001-02-15. https://web.archive.org/web/20010215021918/http://www.hushmail.com/privacy/ ↩
Hushmail – Free Email with Privacy – About Archived 2007-11-22 at the Wayback Machine http://www.hushmail.com/about-security ↩