Live data from Hacker News

Helm: Personal Email Server

thehelm.com

491–500 of 592 posts

Re: Helm: Personal Email Server

#491

I have no idea who this is for. Non-technical people don't care, and this is still too complex for them. Technical people can use Fastmail or other secure, hosted options. $500 for proprietary hardware is so steep, there are software options for the Rpi that do something similar for $40!

Well I might be a good example. I’m highly technical and I never want to try configuring an email server again. Did that once and no thanks. I can do it, but since it’s not a particular technical subdomain I have much experience with and its difficult and time consuming. And doing maintenance is just an ongoing headache I don’t want.

However, I recognize the value of having my email served and saved on premises. If I could have a fairly secure and automated backup from my local files, that’s great.

If I can also use a self hosted webmail interface then I want that too.

I agree that $500 is a lot, but it’s not an absurdly large amount.

Re: Helm: Personal Email Server

#493

Earlier quoted context omitted.

Canada. 100$/month for 150down/12 up residential. Never seen more than 50 down. Regular outages (for 30min every few days). If the US is third-world in terms of service, canada is an uncontacted amazon tribe.

In Canada. 100 CAD/month. 150 both up and down. If you are in a major city, it might be time to check the other ISP in town. I'm glad I did.

I'm on Vancouver island. The provincial capital. There is only the one cable provider (shaw). No other landline options in my neighborhood.

Re: Helm: Personal Email Server

#494
I'm sorry, but I'm pessimistic about this. 99% of people just don't care about privacy, and those who do would probably prefer to set up their self-hosted email by themselves.

I really hope to be proven wrong.

Re: Helm: Personal Email Server

#495
post #494

I'm sorry, but I'm pessimistic about this. 99% of people just don't care about privacy, and those who do would probably prefer to set up their self-hosted email by themselves. I really hope to be proven wrong.

It’s not even that. It’s that the flipside of decentralization or even federation is SPAM. How do you prevent getting SPAM from people you don’t know, while at the same time having others accept YOUR emails?

That’s why today ANTISPAM on the net has all but shut down the option of having email outside the big boys or edu.

Re: Helm: Personal Email Server

#496
post #190
post #163

Earlier quoted context omitted.

One key principle for Helm is that you always hold your encryption keys to all your data— Helm and outside parties should never get access to that. So the backups are encrypted, and the Helm device itself stores your data in an encrypted fashion on its storage, and has a secure enclave such that those keys never enter user memory space. Hosted services like protonmail (great option) support some key management but th…

> You can take down individual nodes but you can't take down millions of them. This statement indicates a lot of passion (and I side with it in spirit), but it feels irrelevant and out of place wrt/ this product. My data is only (available from) my own private Helm server. If mine gets taken down, the existence of millions of other "nodes" doesn't help me. Helm the company can help me with new hardware and my backups…

I mean, assuming we’re talking about a government trying to shut down or snoop on an email service –

They’re probably not going to go door to door confiscating millions of devices; the cost to do that would be astronomical. You’d still be at risk if they were targeting you personally, but not if they were targeting all Helm users en masse. That’s a big improvement. And even if you were targeted personally, you’d at least be in a position to defend against surreptitious snooping, assuming that took the form of agents physically entering your home to hijack the device.

Of course, there’s a lot of counterfactuals baked into that scenario. Helm does not currently have millions of users, for one. For another, the EC2-based proxy service run by Helm is a single point of failure that someone could take down, though supposedly Helm will release tools to replace it with your own server. And most problematically, the closed-source software could be silently subverted by Helm in an update, with no reasonable means for the user to detect this, even in theory.

Still, it’s a lot better on that front than most cloud email services.

Re: Helm: Personal Email Server

#497
post #239
post #203

Earlier quoted context omitted.

So, we're in agreement that this sort of thing should 1) be paid for, 2) not readable by the provider, and 3) maintenance-free for the user. I still don't understand why this is a hardware play. There are advantages to owning the hardware but none of those advantages seem to apply here. The hardware feels like a bit of an albatross.

If you want to truly control your data, you've got to control your hardware too. See: Lavabit.

But with Helm, we don't control the hardware, do we?

Re: Helm: Personal Email Server

#498
post #203

Earlier quoted context omitted.

So, we're in agreement that this sort of thing should 1) be paid for, 2) not readable by the provider, and 3) maintenance-free for the user. I still don't understand why this is a hardware play. There are advantages to owning the hardware but none of those advantages seem to apply here. The hardware feels like a bit of an albatross.

How could it NOT be a hardware play? Then how else can you verify and trust that you know what code is running in some datacenter in who knows where?

It doesn't matter what code is running server side, as long as decryption happens client side and the keys are never transmitted to the server.

Re: Helm: Personal Email Server

#500
post #233
post #155

Earlier quoted context omitted.

"You know what would be a better product? A relay SMTP server that works with Google/Microsoft/Amazon/Fastmail et. al. to pump e-mail from personal servers and ensures it won't get caught in spam filters." That's basically Sendgrid or Mailgun or even Fastmail itself. They can all relay SMTP for arbitrary domains.

It's actually a totally different product vs Sendgrid/Mailgun/etc. Such a product would need to have a ToS that states it can only be used for low volume personal and business correspondence, and have per-account rate limiting to enforce that. Doing it this way is necessary to avoid having mail treated as bulk. I've tried relaying through mailgun to get mail to outlook.com, it does not work.

But this is exactly what I use mailgun for. The free price point kind of enforces that.

Maybe it's just been so long I'm whitelisted?

Post reply on HN