> but can they actually force a company to spy for them, and change their service in such a way that makes it possible?
Hushmail is the standard example here. They provide encrypted email. Criminals used them for communications. Law enforcement went to hushmail with correctly formed legal documents, and Hushmail handed over plain text from users.
There are two ways that plain text is available: using the web client encryption is done on the server. There's a step where plain text is available to Hushmail.
Or if users are using the Java client Hushmail could push a malformed version to the user. This is something that Hushmail has said themselves.
This wasn't under any weird FISA or patriot act law either.
Hushmail is the standard example here. They provide encrypted email. Criminals used them for communications. Law enforcement went to hushmail with correctly formed legal documents, and Hushmail handed over plain text from users.
There are two ways that plain text is available: using the web client encryption is done on the server. There's a step where plain text is available to Hushmail.
Or if users are using the Java client Hushmail could push a malformed version to the user. This is something that Hushmail has said themselves.
This wasn't under any weird FISA or patriot act law either.
(https://en.wikipedia.org/wiki/Hushmail#Compromises_to_email_...)