
Originally Posted by
CounterMail
This is true only if we have the users password,
because a private PGP-key is always encrypted using strong encryption with
the personal password, a private PGP-key without the knowledge of the
password is basically useless (unless the password is very easy), and in our
case the user password is never sent to our server. Hushmail have two login
types, Java and non-Java. In the non-Java version the password is sent to
their server, in that case it's possible for them to collect the password.
We only have one login type, the Java-version, and the password never leaves
your computer.