http://www.wired.com/2007/11/encrypted-e-mai/
Technically, they were forced to collect the key which they would not have stored otherwise, so this does not count as "had evidence in their possession"
http://www.wired.com/2007/11/encrypted-e-mai/
Technically, they were forced to collect the key which they would not have stored otherwise, so this does not count as "had evidence in their possession"
Users connect to the service via a SSL (https://) connection and Hushmail runs the Encryption Engine on their side
Well, there we go. Right there they've got the Lavabit architecture, and all the same problems. The encryption and decryption is happening on the server, so the server has full access to the unencrypted messages.
I've been asking for a while and there are still zero instances of a company being forced to ship a backdoored product to customers. Companies can be compelled to turn over evidence inside their servers, which is why any "encrypt in the cloud!" architecture is fundamentally vulnerable to government demand.
Even if Hushmail didn't store the key at all, it was in their possession for some period of time. They can't be compelled to go back in time and retrieve things they threw out previously, but there is nothing unusual in the law about a court order compelling you to stop throwing out evidence about third-parties that temporarily passes through your possession.
EDIT I know wonder if a "encrypt in client-side Javascript" technique would be immune to this particular attack. It has all the usual problems 'tptacek and others point out, but if the company is providing the encryption code to the customer, and then the customer encrypts, the company has a very good argument that all that stuff is not in their possession. (A lot of this might turn on the specific reading of the license. Sometimes companies want to maintain possession of the code they ship to you. It's a technically unsafe architecture so I suspect we'll never get the answer to this legal question.)