Live data from Hacker News

An analysis of the Nomx secure communications device

scotthelme.co.uk

41–50 of 77 posts

Re: An analysis of the Nomx secure communications device

#41

I really can't tell whether this is an outright scam, or an earnest attempt by someone completely unqualified (and completely unaware that they're unqualified, per Dunning and Kruger).

At the very least there was bad faith from trying to stall and making false claims about updates and disclosure to costumers in the e-mail chain between Scott and them.

I'd also doubt they "had two of the largest security firms provide remote and "in hand" vulnerability assessments on nomx", or else they just completely ignored their advice.

Re: An analysis of the Nomx secure communications device

#42
Many years ago, I've been working on similar (but better ?) SMTP security device [1], that was doing on-the-fly email encryption by catching outgoing SMTP connections and encrypting their content. One only had to setup some keys and stick in in the outgoing network and it worked - like PGP, but without the need to setup it on every device. But, they are already out of business now...

[1] https://www.scmagazineuk.com/securecoms-launches-sme-encrypt...

Re: An analysis of the Nomx secure communications device

#43

The real story here, is that if you try to set up your mail server so that you can send mail to a microsoft email server such as live or hotmail, you eventually end up here where they ask for a bribe: https://returnpath.com/solutions/email-deliverability-optimi... Nomx may be terrible, but it's not their fault you can't send mail to hotmail.com Edit: here is the price list for sending mail to hotmail.com https://retu…

For Microsoft/Hotmail, you'll want to register your IP with their feedback loop (Junk Mail Reporting Program):

https://postmaster.live.com/snds/JMRP.aspx

It's free. A bonus of this is that you get reports about emails from your IP that their users mark as spam.

Re: An analysis of the Nomx secure communications device

#44

I really can't tell whether this is an outright scam, or an earnest attempt by someone completely unqualified (and completely unaware that they're unqualified, per Dunning and Kruger).

I'm feeling it's an earnest attempt by someone to set up a p2p email system (that will also send email normally), that wasn't quite finished (like: how will we handle certs, what about dynamic IPs) but was picked up by someone good at marketing who convinced then it was awesome and has created a tidy looking package, etc..

I actually like the idea: a plug-and-play email device that will do p2p with your known contacts.

Just needs more development to make it work, and then some more to make it work securely!?

With IPv6 some issues could be solved.

Are there other examples of similar systems?

Re: An analysis of the Nomx secure communications device

#46
post #34
post #19

I find these kinds of stories infuriating (and just a bit frustrating). Charlatans repackage, rebrand, and repurpose FOSS, then sell them at an unrealistic markup to unsuspecting dupes. Anything from PABX or VoIP systems based on Asterisk, through overly complex CMS's based on Wordpress. I'm not sure what riles me more: consumers being ripped off by these products, or the fact that my strengths lie in tech rather tha…

If the software package they sell wouldn't be utterly useless crap and instead worked as advertised, I don't think the price would be too high.

Definitely. The problem is that consumers (especially small business) so often end up buying an overpriced and badly configured black box, when a decent expert would have been able to set up the same software properly.

Re: An analysis of the Nomx secure communications device

#47
post #5
post #4

I don't understand the point of this, even if it worked correctly. If I understand correctly what it does is create some kind of secure tunnel between two nomx devices if you tell it to. But doesn't starttls do that already if you configure your mail server that way? And it already just works with any compliant email server? So unless I'm missing something there's absolutely no doubt in my mind that this is a scam. K…

It would have a better life as a Pi-hole since you can use the fancy case it came in :)

Agreed. That's a pretty nice injection molded case for a Pi. Too bad it costs ~$180.

Re: An analysis of the Nomx secure communications device

#48
post #4

I don't understand the point of this, even if it worked correctly. If I understand correctly what it does is create some kind of secure tunnel between two nomx devices if you tell it to. But doesn't starttls do that already if you configure your mail server that way? And it already just works with any compliant email server? So unless I'm missing something there's absolutely no doubt in my mind that this is a scam. K…

The software side looks like someone just executed an ancient Postfix + Squirrelmail + Dovecot tutorial[0] and cobbled together a horrible UI for it. [0]: https://www.exratione.com/2012/05/a-mailserver-on-ubuntu-120...

Is it squirrelmail, or just IMAP(s)/POP3(s)?

I guess, at least it isn't running it in conjunction with sendmail https://threatpost.com/no-fix-for-squirrelmail-remote-code-e...

Re: An analysis of the Nomx secure communications device

#49
"30 March 2017 22:28: Will claims to have a sent a response and has forwarded the same email to me again which doesn't arrive."

"31 March 2017 16:52: Asked for confirmation of receipt of earlier email given apparent email issues.

4 April 2017 11:13: Asked for confirmation of receipt of earlier email given apparent email issues. "

Wonder why...

Post reply on HN