- What is HushMail?
Hush Mail is the world's first, fully encrypted, free
Web-based email service. Our patent pending, state-of-the-art
technology keeps private communication private. Free and
easy to use, HushMail works just like other Web-based
email providers, except HushMail offers the security of
1024-bit encryption between users.
HushMail implements patent-pending technology known as a
"Public Key Cryptosystem with Roaming User Capability."
That means that the only people who can read your HushMail
are the people that you send it to. It also means that you
can access your account from any computer that has a Web
browser and Internet access, anywhere in the world!
Remember that you can use your HushMail account to send
email to anyone on the planet, but to take advantage of
our 1024-bit encryption, all parties sending and receiving
email must be using HushMail.
Did we mention that it's free? Tell
all your friends and associates, so that you can begin
speaking freely with HushMail today.
- Can HushMail run on my Macintosh?
Currently, there's a limitation within the latest Java engine
for the Macintosh that doesn't permit our client to run on the
Mac. We believe that this situation will be remedied in the
near future, and we will keep you updated as to the availability
of HushMail for Macintosh users world-wide. If you would like to be notified
when a Mac version is available, please send an empty message
to mac@hushmail.com.
- I already have an email address.
Why do I need HushMail?
Email is fast becoming a mass media communication device,
as common as the telephone. But email is not a secure
communications medium. Lately, the media has been
full of stories that have
emphasized how insecure email is as a method of
communication.
For the first time, a product is available that is both
easy to use and provides state-of-the-art security. HushMail
provides the same functionality as any other Web-based
email service, but with the added protection of privacy,
security, and very powerful 1024-bit encryption.
If you need the assurance that your email will be
secure, then you need HushMail. For proof that you need
it, click here.
- How do I use HushMail attachments?
To use HushMail attachments, simply log in to your account as you usually
would, from the home page. Click on
"Compose" to make a new message, and in the top right corner of
the applet window you will see a box that says, "Attach File".
Click on "Attach File" and follow the directions. Clicking on
the "Browse" button will allow you to look through your PC to
find what you want to attach. You may attach more than one file, but there
is a 1.5MB total limit on attachment size. When you are done, click
"Finished" to return to the HushMail applet. Send your HushMail
message in the usual way, and the files you chose will be attached.
Remember, to take advantage of HushMail's 1,024-bit crypto-engine, you need
to be sending messages to other HushMail users. Attachments are a new feature
that we are testing. Please send your thoughts and suggestions to us at
info@hushmail.com.
- How much email can I store on
my HushMail account? Can I pay for more storage?
At this time, you are limited to 3 megabytes of storage
space on the HushMail servers. We will have Premium Accounts available soon.
- I've sent thousands of emails and
never encrypted any of them. Why do I need encrypted
email?
It is often assumed that email travels from sender
to recipient directly. This is absolutely not the case.
Because of the decentralized nature of the Internet, the
messages you send go through multiple mail servers. It
is at these points that your email can be intercepted,
copied, and stored for later retrieval. It may not even
be stored deliberately. Most systems do regular backups,
so a considerable portion of your email correspondence
probably still remains on your mailserver's backup tapes.
Weeks, months, even years after you've sent a message,
someone with a modicum of computer expertise can retrieve
your mail by using key word search strings. HushMail can
secure your email from prying eyes.
Who Needs HushMail?
- Doctors can send medical information to and from
patients or other healthcare providers.
- Lawyers and their clients can exchange privileged
information.
- Bankers can transfer account information to clients
or other businesses and banks.
- Journalists can communicate with editors and news
sources.
- Human rights workers and their clients can speak
freely to the rest of the world.
- Anyone who sends private email.
- Do I need special software to
use HushMail?
The quick answer is, NO. You just need a browser.
HushMail will run on most releases of Microsoft Internet Explorer 4,
but you should check the specific version by pulling down the "Help"
menu and selecting "About Internet Explorer." If the version indicated
is previous to 4.7, you may have problems. HushMail runs optimally on
Internet Explorer 5. HushMail is compatible with Netscape Communicator
4.04 or above. However, on versions before 4.07, some convenient
features will be unavailable. HushMail is completely compatible with
Windows 95, Windows 98, Windows NT, Linux, and many other operating
systems.
Unfortunately, HushMail does not work on the Macintosh OS at this
time. Team Hush is working with Apple and Microsoft to remedy the
situation.
- Do I need an Internet
connection to use HushMail?
HushMail is located on the World Wide Web. You must
have Internet access to use HushMail. There is no software
to buy and no dial-up account to register for. Once you're on
the Web, you can access HushMail.
- Can I send and receive email to
non-HushMail accounts?
Yes, you can send and receive email to and from any other email
address. HushMail works exactly the same as any other Web-based
email account. HushMail accounts can now send and receive attachments
as well as plain text messages. Remember, in order to have secure,
encrypted communication, your messaging partners need to have HushMail
accounts.
- When I try to send HushMail
to a non-HushMail account, the "Send Securely" box
becomes unchecked. What gives?
The system is telling you that the only way to send
a secure, encrypted message is to send it to another
Hushmail user. When you type in, "@hushmail.com", the
message is automatically encrypted and the "Send Securely"
box is checked. When you type in an address other than a
HushMail address, the box is automatically unchecked. Your
message will not be encrypted. In addition, you will see a
message at the bottom of your mailbox indicating that
your message is not being sent securely.
- How is HushMail different from all
of those other free email providers?
HushMail is the world's first fully encrypted, easy-to-use, Web-based
email service.
- No other service provides END-TO-END security.
- No other service is as EASY-TO-USE.
- No other service transparently exchanges PUBLIC AND PRIVATE KEYS.
We have a few major differences, the most important being
total and complete privacy and security! Most email systems available today are wide
open to snoops. HushMail's secure system allows you to communicate with other
HushMail users with the security of bulletproof 1024-bit
encryption.
Features of HushMail like the Address Book and Folders
are housed entirely within the Java applet that contains
HushMail. So, you don't have to wait to reload an entire
Web page when you use your address book or access your
folders, like you would on Yahoo! and HotMail.
- Can I attach files to my
email messages? Can I receive attachments?
Yes. Email attachments are available to all HushMail
users.
- How does HushMail transfer attachments?
Is the process secure?
HushMail Secure Attachments are as safe as any Web-based 'secure'
transmission process. The attachment feature uses SSL-based encryption,
a standard used in most secure transactions on the Internet today.
If you send attachments with HushMail, they will be protected by SSL
encryption between your computer and our server. If the recipient
is a HushMail user, SSL encryption will also protect your attachments
between our server and their computer. This is equivalent to the level
of security offered with most financial transactions on the Internet.
Keep in mind that the accompanying text will be completely encrypted
using our 1024-bit full strength technology. Since the current state
of browser technology doesn't allow it, HushMail cannot yet use our
ultra-secure end-to-end encryption for attachments. We will have a
full-strength attachment version in the near future. For the most
sensitive documents, we suggest that if it needs to be absolutely
and totally secure, you should send it inside the HushMail text
message.
No other Web-based service can match the complete security of a
HushMail message. Also, unlike other "secure" Web-based email,
the system uses your passphrase to open attachments and there is
no need to deliver a separate secret code to your recipient to
unlock the message. Additionally, it doesn't require you to "go
get" -- or link to -- your message sitting on another server.
It is all handled for you by the HushMail system.
- Is there a size limit on the messages
and attachments I send/receive? Why?
Yes. The size limit is 250 kilobytes for text messages. Attachments
can be 1.5 megabytes total.
HushMail caps the size of messages sent or received by a user to 250K.
This cap keeps attachments or graphics from accidentally making their
way into a HushMail account. HushMail users can also send and receive
attachments up to 1.5MB in size. So, between 250K for text and 1.5MB
for images, graphics, and other attachments, HushMail users have plenty
of room to communicate.
- When will you have (a) spell checking, (b) mail
forwarding (c) changeable fonts, etc.?
These features and more will be available soon.
- This is such a great service. How can HushMail be free?
HushMail is free because it is advertiser-supported. Please click through
to our sponsors!
- Why does HushMail ask
for personal information?
In order to keep HushMail free of charge, we need to provide
demographic information to our advertisers to give them an
idea about typical HushMail users.
Please be assured that 1) information is gathered only in the aggregate, and that personal
data is NEVER connected directly to an individual account, and 2) if
you prefer not to fill in the questionnaire, we have an option
for you to utilize HushMail via an "auto generated" account, in which case a user name
will be automatically generated for you, such as "auto12345@hushmail.com".
If you choose your own user name, you're asked to provide basic
demographic information including your name, email, zip code,
profession, and so on. For more information, please refer to
our Privacy Policy.
- Will my name and email address
be sold to other companies?
Absolutely not. Please refer to our Privacy
Policy for more information.
- Can I change my passphrase?
What if I forget my passphrase? Can Hush change my
passphrase?
Don't lose it! The HushMail system is so secure not even HushMail employees
have access to your messages or your passphrase. Unfortunately, this means
that if you forget or lose your passphrase you will not have access to
your message, and your account will eventually be deleted. So, be sure to
WRITE DOWN your passphrase. If you lose it, we cannot retrieve it for you.
In future versions of HushMail, you will have the option to change your passphrase.
However, if you have definitely lost your passphrase, the best thing you can do is
open another Hush account and let all your email partners know right away that you
have changed your address. (But this time, be sure to write down your passphrase and
store it in a safe place!)
- Is there a way to change my username?
The only way to change your username, at this time,
is to register for another account. Make sure to choose
something useful to you and that you can easily remember.
- How do I delete my HushMail
account?
At the present time, the only way to delete a
HushMail account is to let it be idle for 90 days.
At the end of ninety days, the inactive account will
automatically be deleted.
- Why can't I print from
HushMail?
In order to print from HushMail, the message would
need to access the hard drive. If it did, HushMail
wouldn't remain encrypted or secure. We recommend that
you use the Control/C (copy) and the Control/V (paste)
features on your keyboard. You can paste your HushMail
text into a document or onto your desktop, it's up to
you.
Utilizing the Control/C and Control/V buttons on your
keyboard is the only way to copy and paste text out of
a HushMail document.
- How can I save HushMail messages
on my hard drive?
See above.
- Where can I report HushMail users'
spamming other email systems through your servers?
Any spamming activity should be reported to our Abuse
account, abuse@hushmail.com.
- I have an Internet fax service
that directs all my incoming faxes to email. Can I get
this service to direct my faxes to HushMail?
You can have your fax service or anyone else for that
matter, forward email to your HushMail account. It is
perfectly acceptable to forward faxes as attachments to
your HushMail account.
- Can I use HushMail with Outlook
Express?
HushMail is a Web-based email system. This means you
need only access HushMail through a Web-browser. HushMail is not yet
compatible with Outlook.
- I'm having log-in problems -or-
I'm behind a firewall. Help?
If you are unable to connect, click the "Try an alternate connection"
box. Firewalls should not be a problem; however, Proxy-type software, such
as WinGate or Hummingbird, is not currently compatible with HushMail.
Team Hush is working on a solution to this problem. Team Hush will
contact you when we have a fix for proxy difficulties. Please email
proxy@hushmail.com.
- Internet Explorer is asking me security questions.
What should I tell it?
Depending on security setting in Microsoft Internet Explorer, users may
be prompted at certain points while they check their HushMail. Setting
the security level to medium will eliminate all these warnings. Here are
the prompts you may receive. Some users answer no to these and have
problems as a result:
Scripts are usually safe. Do you want to allow scripts to
run?
Click "Yes"
Do you want to allow scripts to access Java applets?
Click "Yes"
A script is accessing some software (an ActiveX control) on
this page which has been marked safe for scripting. Do you want to allow
this?
Click "Yes"
A bug in Internet Explorer ("IE") prompts these dialogue
boxes. This bug causes IE to think HushMail's Java applet is an
ActiveX control. HushMail does not use ActiveX controls.
- Can I send encrypted email to people using other
encryption systems, i.e. PGP?
It is possible to use PGP and HushMail together to protect your messages.
The key is to cut and paste your PGP protected message into a HushMail
message. The recipient will also have to cut and paste the message. This
time, the message will be cut and pasted out of HushMail and decrypted
using PGP.
It's not totally user-friendly, but it does work.
- Can I post to newsgroups from
HushMail?
Not yet, however HushMail will offer that feature in a future
release.
- If mail is sent to a non-HushMail
user, can you people read it?
If the mail is sent to your account from a non-HushMail
address, it is not fully secure. However, it is protected
by the standard 128-bit encryption that other freemail
services provide. Once it's in your account, on the
HushMail servers, the only way mail can be accessed is
by your passphrase.
- How do we know that you aren't
some conspiracy designed to steal our email
and spy on us?
No, HushMail is not part of some conspiracy or plot. It does not
matter anyway; if you and the people you correspond with are both
using HushMail, the text that you send is encrypted. No one but you
and your recipient can read your HushMail.
- Does HushMail have a "back door" that can be
accessed by government agencies?
No. With HushMail, your message is completely encrypted from point A (you)
to point B (your recipient). The inclusion of a back door would only allow
access to "gobbledygook," the encrypted message. Therefore, your message is
fully secure. Our state-of-the-art crypto engine provides end-to-end
security between HushMail users.
- What if my message is subpoenaed?
See above. A subpoena would only allow access to
"gobbledygook," the encrypted message.
- How can I be sure that intruders or hackers can't
break into my message?
Hush Communications has made our source code available to the cryptographic
community, privacy organizations and all of academia for full inspection
and review. Our 1024-bit encryption system is sound, and we prove it by
allowing full access to our source code for anyone to try and crack. For
your own review of the overall system, check out the
technical explanation provided on
our website.
- Are you pursuing partnerships with other companies or
organizations?
Yes, we are open to partnerships with quality organizations. For more
information, please write us.
- Do you offer stock in your company?
Right now, Hush Communications, the parent company of
HushMail, is a privately held company.
- When HushMail comes out of beta,
will there be a switch to a newer version that could
cause loss of user data?
We're "beta" only in the sense that we haven't completed the website and
wanted the technical community to have a chance to review our product
and to get any bugs worked out. The product is fully secure and operational.
- Will it be possible for HushMail
users to post suggestions?
Team Hush is creating a number of windows for comment,
suggestion and feedback. In the meantime, you can send
suggestions to the
info@hushmail.com
account.
- Where can I find a
high level technical description of HushMail account
creation and usage?
You can find such a description on this website by
clicking here.
- How many machines does my
mail go through as it crosses the Internet?
More than most people think! There is a way that you
can find out. To see the pathway of your sent email, open an
MS-DOS client while connected to the Internet and type in:
tracert computer.name
where computer.name represents the part after
the @ symbol of the computer you are emailing to. You will
then see a list of every machine the message will be routed
through. Each of these machines AND every machine on the same
local network of any of these machines has access to your
message. Considering that a network can have hundreds of
machines on it, the numbers can add up very quickly. You
can see how many routers your computer has to go through
to get to HushMail.Com's firewalls and servers.
- What role does Java play in the
HushMail solution?
Java allows Web-browsers to download and run small
applications, known as "applets", on the fly. HushMail
messages are encrypted right on your host machine,
within the Java applet. Your email does not have to
travel to a remote server before it's encrypted. The
Java applet is loaded directly into your browser to
encrypt your email before it's sent. You must be
sending and receiving mail to and from HushMail accounts
to fully utilize the security of this applet-based
cryptosystem.
- What is Blowfish, and how is
it involved in the HushMail solution?
Blowfish is a 128-bit symmetric block cipher. When
combined mathematically with your HushMail passphrase,
the Blowfish algorithm encrypts your private key. This
occurs before your key is stored on HushMail's very
secure key server. The only thing that can decrypt your
private key is your HushMail passphrase combined with
the Blowfish algorithm.
- How can it be proved that
the HushMail system is actually secure?
Team Hush is currently using a beta version of
HushMail. It is in this beta period that we expect
a variety of computer users to test the rigor of
our cryptosystem. The Java source code of HushMail
is available to everyone, free of charge. Security
experts and computer enthusiasts worldwide have
the unrestricted ability to try and find any holes
within our system. Our source code can be found at
http://www.cypherpunks.ai/~hush.
In addition, a full technical description of the
functionality of the system is available
here.
- What do the technical and cryptographic
communities think of HushMail?
HushMail welcomes the input of the cryptographic community. We
think we have the best email security in the world, and we want
the experts to see for themselves. The Java source code of our
HushMail applet is available to everyone, free of charge.
Recently, Bruce Schneier, one of the world's best known cryptographic experts,
reviewed our product in his
monthly newsletter to
security experts worldwide. We're happy he has taken the time to comment on our
system. Bruce Schneier's review and our response are both available via the Web:
http://www.counterpane.com/crypto-gram-9908.html#Web-BasedEncryptedE-Mail
http://www.hushmail.com/bruce_comments.htm
- When I set up an account, do I
need to send my public key to my messaging partner?
No. Both the public and private keys are kept on our
very secure servers. Your private key is encrypted by
your HushMail passphrase before it's stored. Your public
key is retrieved automatically by the applet when you
want to send a message.
- Since the encryption is done
locally, why can't the private key remain on my
computer?
If the private key were stored on a local machine,
it would not be possible to use HushMail from any other
client machine. One of the key features of Web-based
email is the ability to access your account from
anywhere in the world. This would not be possible if
you kept your private key on your computer.
- How do I enable Java on my
browser?
In Netscape:
- Pull down the "Edit" menu
- Next, select "Preferences"
- Select "Advanced"
- Check the box that says, "Enable Java"
- Must I turn off JavaScript?
No. Do not turn off JavaScript.
- My browser says I have an expired
Thawte certificate. How do I renew it?
Here's the procedure for installing a new Thawte Certificate in your browser.
Some of our users have older browsers, and when the certificates they contain
expire, they must follow this procedure to renew them.
For IE:
- Access
http://www.thawte.com/serverbasic.crt
- When prompted, choose to open the file from its current location.
- When the certificate information box appears, choose to "install" the
certificate.
- For the name of the certificate, enter "Thawte Server CA".
For Netscape:
- Access
http://www.thawte.com/serverbasic.crt
- Continue through the installation dialog.
- For the name of the certificate, enter "Thawte Server CA".
- Is there any way the person
you're messaging with will know the IP number you're
sending from?
No.
- Do you track IP addresses of
visitors and account holders?
No.
- Is there any way to create an
alias to map several email addresses?
Not at this time. That feature will be available
in a version soon to come.
- Do you keep logs of IP addresses
of people logging in?
No.
- Can people use App Trap (inspects
Java and Active X for malicious code) with HushMail?
HushMail uses a standard, Java applet, run on the
client. It should be compatible with all tools and
components that deal with Java applets. (We haven't
tried App Trap, yet.)
- Will there ever be a non-Java
version of HushMail?
Not yet, but we're planning all kinds of enhanced
features in upcoming versions of HushMail.
- Isn't there a little bit of
JavaScript in your entry page that checks your users
for browser versions? Couldn't this cause a security
breach?
Yes, there is JavaScript within the entry page, but
the initial browser check is as safe as the HTML it's
contained in. JavaScript is sometimes considered a
security risk because it can be used by malicious
websites to obtain information about you when you visit
their pages. HushMail's JavaScript is all completely
harmless.
- Is it possible to cut and
paste a PGP message into HushMail? Would this enhance
security?
Yes. It actually fosters a work-around that allows HushMail to
be used to send attachments. In order to crack such encryption, an
intruder would have to crack HushMail's encryption and then PGP's
encryption. This option only increases security by a constant factor
(a factor of 2, assuming a 1024-bit PGP key), which is practically
inconsequential, but it's an increase none the less. What you have
to do is to cut and paste your PGP protected message into a HushMail
message. The recipient will also have to cut and paste the message
out of HushMail and then decrypt it using PGP.
- What do I need to know if I want
to configure my proxy server to allow me to access HushMail?
Our applet needs to make a socket connection to our server on port 21.
Or, if the 'Try an alternate connection' box is checked, it will make a
connection on port 80. Your browser needs to be able to verify that the
applet came from our server, and not your proxy, or it will not allow this
outgoing connection. This is because applets can only make socket connections
to the location from which they were downloaded. Because of these requirements,
HushMail will not work with some proxy server setups. In the future, a
'proxy-friendly' version of HushMail will be made available.
- How can I use public key fingerprints
to verify that I am actually encrypting messages to whom
I think I am?
For those who desire extra assurance that a message
will only be received by its intended recipient, the
following public-key authentication procedure can be
followed.
- Add an entry in your addressbook for the address
associated with the public key you wish to verify.
- After saving the entry, click on the edit button
for that entry.
- You will see a public key fingerprint for that
entry appear on the status bar at the bottom of the
screen. (Note that fingerprints will only appear for
addresses @hushmail.com.)
- Have the person you intend to send the message to
go to his address screen and click "Show my fingerprint".
- Verify that the fingerprint he sees is the same
as the one you see.
- You can now safely send the message, knowing that
it can only be retrieved by the intended recipient.
- In the future, every time you use that public key,
it will be checked against that public key fingerprint,
and you will be warned if there is not a match. (As
long as that record remains in your addressbook.)
It is important to note that HushMail will never
send an improper public key, and so this procedure is
not necessary for secure communication. However, it
is a safeguard against misspellings of addresses and
other user errors, and a reassurance for those who
prefer not to trust any key-archiving institution.
The specifics of this procedure can be determined
by reading the source code.