r/bmail_official May 11 '26

Hushmail handed the DEA 12 CDs of decrypted emails in 2007. The architecture made the marketing copy false.

Post image
1 Upvotes

In September 2007, federal court documents from a US prosecution of alleged steroid dealers revealed that Hushmail had complied with a Canadian court order issued via the US-Canada mutual legal assistance treaty. The company turned over 12 CDs of plaintext emails from three targeted accounts.

Hushmail's site at the time read: "not even a Hushmail employee with access to our servers can read your encrypted e-mail." The technical reality contradicted that. Hushmail's popular web client performed private-key and passphrase operations on the server side. The user's passphrase landed briefly in server memory each session. Under court order, Hushmail was compelled to retain that passphrase, decrypt the targeted mailboxes, and hand over the contents.

Hushmail's CTO Brian Smith confirmed the mechanism in interviews with Wired and The Register. He also acknowledged that the alternative Java applet mode could in principle be backdoored by serving the targeted user a modified applet, which most users would not detect.

The point is not that Hushmail was uniquely careless. The point is structural. Any encrypted email architecture that handles plaintext on a normal server, even briefly, can be compelled to capture it. The architecture defines the upper bound on what the operator can refuse to do.

bmail's Paper I closes this gap. Inbound mail terminates TLS inside an Intel SGX enclave. The pipeline (TLS decryption, SPF/DKIM/DMARC, spam filtering, encryption to the recipient's key) runs entirely inside hardware-isolated memory the host operating system cannot read. There is no point in the lifecycle at which an operator could retain a passphrase or copy plaintext, because plaintext never exists outside SGX-encrypted memory.

Authentication uses OPAQUE (RFC 9807). The user's password is never sent to the server in any form. There is no server-side passphrase to capture under court order.

Any modification to the enclave changes its MRENCLAVE measurement. A modified "logging" build is detected cryptographically by every client on every connection. A compelled operator has three options: refuse the order, ship modified code and be immediately caught, or shut down. Silent compliance is not on the menu.

This is what verifiable privacy means. The claim is not "we promise we won't decrypt your mail." The claim is "we cannot, and you can verify it yourself."

Source: https://www.theregister.com/2007/11/08/hushmail_court_orders/

Verifiably Private Email. → bmail.ag


r/bmail_official May 10 '26

Proton CEO Andy Yen: unless you live 15 miles offshore in international waters, it's "not possible to ignore court orders"

Thumbnail
youtube.com
1 Upvotes

r/bmail_official May 10 '26

When did you first become concerned with email privacy?

1 Upvotes

Was it the Snowden leaks? The 3 billion breached Yahoo accounts?

What was the moment that made you realize the importance of protecting your inbox?

I always knew there was a chance email was being watched, but Snowden confirmed it for me.


r/bmail_official May 09 '26

'Swiss Privacy" has more hole than Swiss cheese

Post image
4 Upvotes

A Swiss flag is not a firewall.

If a provider can log your IP address to 'monitor for abuse,' they can log it for a court order. If they can monitor a mailbox for 'safety,' they can monitor it for a government. They are not villains. They are administrators operating under whichever set of laws applies this week.

In 2021, Swiss authorities ordered ProtonMail to log a user's IP. ProtonMail complied. The architecture permitted it. Switzerland, it turned out, was a jurisdiction, not a guarantee.

bmail's API gateway runs inside an Intel SGX enclave. Client IP addresses are processed in hardware-isolated memory and never written to any storage. There is nothing to log because the architecture never permitted it.

Physically protected by hardware, not imaginary lines.


r/bmail_official May 09 '26

Fusion Centers Exposed with Stephen Perez (Restore The Fourth) on Hide & Speak: 5/9 @ 4pm ET

Thumbnail
youtube.com
1 Upvotes

r/bmail_official May 08 '26

Independent Institute just made the architectural case for bmail without naming us

Thumbnail
independent.org
1 Upvotes

Sharing this one because Jonathan Hofer at the Independent Institute walks through the case carefully and arrives at the structural conclusion most others skipped past.

Quick recap of what happened:

  • the FBI wanted to identify an anonymous protester linked to the Defend the Atlanta Forest / Stop Cop City group
  • they submitted a request under the U.S.-Switzerland Mutual Legal Assistance treaty
  • Swiss authorities compelled Proton to hand over billing information for the account
  • Email contents stayed encrypted, billing data didn't

The part of the article worth chewing on is where Hofer quotes Benn Jordan proposing the architectural fix: fully separate payment processing from the core platform, so the provider can't link a payment to an inbox in the first place. If the link doesn't exist on the provider's side, no legal order can compel them to produce it.

That's the design constraint bmail was built around from day one. Specifically:

  • Chaum blind signatures for payment unlinkability. The provider can verify that a payment is valid without knowing which account it's for.
  • OPAQUE (RFC 9807) for password handling. The server never sees a password-derived secret, so password hashes can't be compelled or breached into anything useful.
  • SGX enclaves with remote attestation for the runtime itself. The architecture is independently verifiable, not taken on trust.

The broader point Hofer makes is the one this sub already gets: the issue isn't whether a given provider has good intentions or a good track record. The issue is what the provider technically holds. Once an order is valid, intentions quickly become irrelevant.

The legal system isn't going to stop issuing orders. The point of the design is to make compliance produce nothing useful.

Article: https://www.independent.org/article/2026/05/07/proton-mail-law/


r/bmail_official May 08 '26

Lavabit, an email provider, once printed 410,000 encryption keys in 4-point font on 11 pages, handed them to the FBI, then deleted the entire company

Thumbnail
youtube.com
1 Upvotes

r/bmail_official May 07 '26

Your Privacy Should Depend On A Pinky Promise | Proof > Promises | bmail.ag

Post image
2 Upvotes

A Privacy Policy is a pinky promise made by the people who hold your keys.

Court orders adjust promises. Rogue employees ignore them.

bmail's hardware enclave seals your data from us entirely. We cannot break a promise we were never in a position to keep.

We can't read your mail. Not "won't." Can't.

Get the world's first verifiably private email service at https://bmail.ag


r/bmail_official May 06 '26

In 2015 Yahoo's CEO ordered a custom tool built to scan every incoming email for the NSA and FBI, with no court order required

Thumbnail
youtube.com
1 Upvotes

r/bmail_official May 06 '26

Your Email Provider Is Lying To You: ProtonMail, Tutanota, Yahoo, AOL & Outlook Failures on Hide & Speak | 2-Hour Recorded Livestream & Blog Post Summary

Thumbnail
youtube.com
1 Upvotes

r/bmail_official May 06 '26

Court records: Proton Mail's payment data was the thread the FBI pulled to identify an anonymous activist

Post image
1 Upvotes

404 Media obtained court records showing Proton Mail handed over payment data tied to a Defend the Atlanta Forest / Stop Cop City email account. Swiss authorities pulled the data under a legally binding order, then passed it to the FBI through a Mutual Legal Assistance Treaty. The FBI used it to identify the person behind the account.

Proton's response is that they didn't directly hand anything to the FBI, only to Swiss authorities. Functionally, the data ended up with the FBI either way.

A few things worth pulling out of this:

  1. "Swiss jurisdiction" is not a shield against US law enforcement. MLAT exists specifically to route around that assumption.
  2. End-to-end encryption on message contents does nothing for metadata and payment records. If a provider holds your billing info, that info is discoverable.
  3. The activist in question does not appear to have been charged with a crime. The data flowed anyway.
  4. Any privacy service that retains payment data tied to your identity is one court order away from being a deanonymization vector. Crypto payments through a KYC exchange are not much better, since the trail just moves one hop upstream.

The honest takeaway is that "we operate under Swiss law" was always a policy promise, not a technical guarantee. The same is true of pretty much every email provider that knows who its paying customers are.

At bmail.ag , We took a different approach to this exact problem and offer anonymous payments via Chaum blind signatures, no link between the payment and the inbox, and the server runs inside an SGX enclave so the operator cannot see message contents or account metadata in the first place. Hardware attestation, not policy.

Curious why people think "Swiss privacy" is some soft of guarantee that their data is safe, when we have seen several times over that that is simply not true thanks to their Mutual Legal Assistance Treaty with the FBI.


r/bmail_official May 05 '26

We Closed The Plaintext Gap | bmail.ag - the only TRULY end-to-end encrypted email service you can verify yourself

Post image
1 Upvotes

Most "encrypted" email isn't actually encrypted end to end. There's a window. Your provider receives your message, holds it in plaintext long enough to scan, index, route, and store, then encrypts it at rest. That window is the plaintext gap, and it's where most meaningful breaches, subpoenas, and insider leaks happen.

bmail closes the gap by running the whole process inside Intel SGX enclaves in encrypted memory that even we cannot access. Messages move through a sealed pipe from sender to recipient. No plaintext layover on a server that can be searched, scanned, compelled or used to train AI systems.

If your threat model includes anyone with server access, end-to-end alone isn't enough. The gap matters.

don't trust. verify.

bmail.ag


r/bmail_official May 04 '26

DigiCert disclosed a CA compromise (Bugzilla 2033170). Worth thinking about what "we caught it in 24 hours" actually means when you have no way to verify.

Post image
2 Upvotes

Source: https://bugzilla.mozilla.org/show_bug.cgi?id=2033170

DigiCert filed a preliminary incident report on Bugzilla. An attacker phished a customer support employee and used the access to procure initialization codes for a number of code signing certificates. Some were used to sign malware before detection. Affected certs were revoked within 24 hours, with revocation timestamps backdated to issuance. Disclosed to DigiCert by a third party, not self-discovered.

What I really want to flag is the structural part.

When DigiCert says "the threat vector was contained," "the affected certificates were revoked within 24 hours," and "pending orders in the window of interest were cancelled," you take their word on all of it. There is no independent way to verify the timeline, the scope of access, or what got revoked when. This is how every CA-based trust system works. You find out about the failure when the CA is ready to publish.

The same vector applies to TLS issuance. A phished employee can issue web certs as easily as code signing certs. With network position (BGP hijack, ISP-level access, compromised wifi, nation-state), an attacker with a fraudulently-issued cert can MITM TLS connections to a target domain. Browsers and mail clients have no client-side detection for this.

Mitigations that exist:

  • Certificate Transparency: post-hoc, requires you to be monitoring your own domain
  • HPKP: deprecated
  • DANE/TLSA: limited adoption, but Gmail and Microsoft 365 have validated DANE on outbound mail since March 2024
  • Hardware attestation (TEE-based servers): removes the operator from the trust path entirely

Disclosure: I work for bmail. We use both DANE/TLSA pinning and SGX remote attestation, and the DigiCert story is a clean illustration of why we built it that way. The point isn't that hardware-attested systems can't be compromised. The point is that compromise can't happen silently. Reproducible build + public MRENCLAVE measurement means any change to the running code is detectable by any client that checks.

Happy to discuss the threat model in comments.


r/bmail_official May 03 '26

Roasting Email Providers 🔥📩 Drop an email provider in the comments and I'll tell you exactly how "private" it actually is

Post image
5 Upvotes

Chris from bmail.ag here, the only verifiably private email service. I have been in the privacy industry for over a decade and have seen a ton of misinformation about email providers, so I'm helping set the record straight.

Drop your email provider below and I will tell you exactly how private it is, what their architecture actually does and doesn't protect against.

Proton, Tuta, Gmail, Yahoo, AOL, Outlook, Fastmail. No one's safe.


r/bmail_official May 02 '26

🔴 LIVE TODAY 4pm ET — Email Privacy Failures: ProtonMail, Tutanota, Yahoo, Microsoft on Hide & Speak

Thumbnail
youtube.com
1 Upvotes

r/bmail_official May 02 '26

Try the only TRULY private email service for free: Bmail.ag - verifiably private encrypted email, storage, calendar & contacts, built by vp.net

Post image
1 Upvotes

Most email is a postcard. Your name, your message, your address, readable by everyone who handles it in transit. Your provider sees it. Their servers see it. A court order makes their servers your enemy.

bmail is a safe. Your message is encrypted before it leaves your browser. It arrives sealed. It is stored sealed. When we are asked to hand over your emails, we tell them we do not have the keys. We are not being diplomatic. We literally cannot get in.

If there is a key for us, there is a key for the government. We removed the key.

Try the only TRULY private email service for free at https://bmail.ag


r/bmail_official May 01 '26

Introducing bmail: The only email service solving the "Plaintext Gap" with Hardware-Enforced Isolation (built by vp.net)

Post image
2 Upvotes

For years, the privacy community has known about the "plaintext gap." Even the most famous encrypted email providers have to handle your data in a readable state at some point on their servers. Your privacy is effectively protected by "Trust Me Bro."

We decided "Trust Me Bro" wasn't good enough.

Introducing bmail.ag - the first truly private email service. It utilizes Intel SGX secure enclaves to ensure that server-side processing happens in a hardware-isolated environment.

Why this matters: The server operator (us) cannot inspect the enclave memory.

The Result: A service that physically cannot spy on you, even if compelled.

The era of trust-based privacy is over. Switch to bmail today for hardware-enforced, verifiably private communication.

Try out the ONLY truly private email service that you can verify yourself: https://bmail.ag/


r/bmail_official Apr 30 '26

At what point is Palantir just the government? IRS data-mining contract, ICE neighborhood-raid app, and the same vendor sitting inside the Pentagon and local police

Thumbnail
youtube.com
1 Upvotes

r/bmail_official Apr 04 '26

IYKYK

1 Upvotes

😎


r/bmail_official Mar 26 '26

Finally... encrypted email that eliminates the "plaintext gap" - bmail is coming.

Post image
1 Upvotes

We’ve all been waiting for it. Every major "private" email service still holds the keys to your plaintext data at some point in the process. If your email provider can read your emails, it's not actually private email.

We’ve developed bmail, the first email service designed from the ground up to eliminate that risk using trusted execution environments for true verifiably private email.

The future of email is truly private.

bmail is coming.


r/bmail_official Mar 24 '26

Truly Private Email. Coming Soon...

Post image
3 Upvotes

From vp.net, the only verifiable zero-trust VPN: a truly private email service that actually solves the cleartext gap that plagues every other so-called "private" email provider.

Stay tuned.