by Sergio » Thu Feb 25, 2010 11:58 am
We are using RSA 2048bits keys for public keys and Twofish 256 bit keys for symmetric encryption.
Hushmail's web mail is less secure, because hushmail web-mail gets your messages unencrypted and then encrypts it on server side, so hushmail, if pressed by government, will be able to divulge some messages (which was done before).
We don't have access to your messages, because encryption is done on client side and we even if pressed by somebody couldn't divulge your messages.
I think it will be difficult for any government to crack encryption used in ResoMail.