Big Rick Rock
istrator
thx9000 said:
I know I am connecting to Hush, I know the MX record points to Hush, and I know that I no applet loads prior to me connection to Hush.
I was just going after the most paranoid scenario I could think of. That involves George learning Java, modifying Hush's applet to send our PW's or decrypted mail (after our login at hush) to some FBI.elitefitness.com server. Then he sends his doctored applet to Hush and asks then to use on mailserver1 for all EF customers.
That's kinda ridiculus though. Hush isn't going to enter into and SLA with someone that provides THEM modified code. Well at least I wouldn't. Furthermore, Hush probably wouldn't allow their reputation for secure communication to be risked this way even if they were open to the idea of allowing customers to modify their applet.
We've had customers ask us to simply allow them to do the branding changes to products they were reselling. Our answer was an adamant no, I am sure Hush looks at it the same way.
You answered your own question.