Live data from Hacker News

Helm: Personal Email Server

thehelm.com

541–550 of 592 posts

Re: Helm: Personal Email Server

#541
post #427

Earlier quoted context omitted.

I think the only times I lost data in the last 10 years or so was because someone accidentally deleted stuff on a shared Dropbox (luckily I had a local backup, so only the most recent changes got lost). Oh and I lost some photos that I uploaded to a Facebook clone because they more or less shut down. Data loss is more or less a solved problem. You don't need Google for that. ;-) On the other hand, even without puttin…

I'm not sure you understood how helm works. Your answers don't seem to relate to the concerns of a self-hosted solution.

Can you be more specific?

Re: Helm: Personal Email Server

#542
This is cool guys. Kicking things off at the right time as well. However think I might be missing a few things.

1) Wasn't the whole point of email moving to the cloud to enable access on any device anywhere? If I move my email to Helm can I still access it on the go?

2) Assuming I can access it on the go. I'd need pretty fast upload speeds right? I live in Australia, and our internet is god awful.

Re: Helm: Personal Email Server

#543
post #536
post #436

Earlier quoted context omitted.

I mean, sure? You can use encryption to get security and privacy features but "FDE" isn't it. FDE is more important for Helm but that's a problem of their own design: suddenly the e-mail is in a box in my kitchen and it's a lot easier to walk out with a box in my kitchen than it is to walk out with a drive from us-east-2a :-) For anything in the cloud it's a belt-and-suspenders/compliance thing.

How many people have access to drives in us-east-2a? Do you know? Can you verify? Assuming the software works flawlessly (if it doesn't, it doesn't matter where it runs) you'll need RAM and storage access to recover the keys and the data. If you're in the cloud, you won't notice when insiders or state agencies take a peek. If the device is in your home, you can set it up so you notice. It all depends on the threat mo…

> How many people have access to drives in us-east-2a? Do you know? Can you verify?

AWS, like every non-clownshoes provider, is transparent about the security controls on its datacenters. It has those verified by independent third parties and auditors (for relevant compliance standards). They have published whitepapers and compliance/audit reports, and continue to.

The odds that someone compromises a Helm update and the odds that someone walks out of us-east2a with a drive are not in the same ballpark.

To reiterate, because somehow I'm in the "FDE is an important threat model!" corner: it is not. Walking away with a Helm is not the easiest way to read e-mail on that thing, especially not for an organization capable of dragnet surveillance in general.

Re: Helm: Personal Email Server

#545
post #304

Earlier quoted context omitted.

I disagree. Seizing data stored on a server in your house is much, much more difficult that seizing data stored on a cloud server.

Not really. If you are under investigation, seizing your server is as simple as a search warrant. The challenge is accessing the data - if you've encrypted it well, it's impossible to access. However, on your own server, you may get complacent and allow some data leakage. Major providers like Gmail and ICloud will have a longer and more convoluted process to provide your data to state actors, but analysing that data…

On a VPS, full disk encryption is not effective because the keys can be dumped from the hypervisor.

Re: Helm: Personal Email Server

#546
post #516

Earlier quoted context omitted.

But this is exactly what I use mailgun for. The free price point kind of enforces that. Maybe it's just been so long I'm whitelisted?

More likely you actually set it up correctly, with DKIM and stuff, and the parent didn’t.

I had everything set up correctly, including DMARC. I've been doing this a long, long time.

Re: Helm: Personal Email Server

#547
post #55

Earlier quoted context omitted.

Holy crap, US ISPs are completely absurd. This definitely isn't a thing (or at least not enforced in any way) in Canada; most of my friends run on-prem web services out of their basements or closets.

It's not enforced. I've had HTTP and SSH available on Comcast and Verizon lines for... decades, I guess. No one cares. SMTP is more problematic because of spam: outbound traffic on port 25 is blocked, so a true home mail server won't work without a reachable gateway mail server somewhere else. That's basically what the linked product is: they manage the protocol side of the service on your behalf, and forward all the…

Ironically it doesn’t look like they restrict sending mail in the above quote, only serving it. If that’s a violation, so would be using your browser.

Re: Helm: Personal Email Server

#549
post #522
post #3

Interesting product with great potential. Their website doesn't seem to address my two main concerns: 1. How do they ensure high, non-spam delivery rates to the main email services like Gmail, Fastmail, Yahoo, and Microsoft? 2. How would the product work in case Helm the company/service goes away (or even just service outage)? Can the device work on its own without the need for their web service (perhaps with lower d…

> 1. How do they ensure high, non-spam delivery rates to the main email services like Gmail, Fastmail, Yahoo, and Microsoft? I run mail servers. I believe the idea that mail delivery is a problem for small mail providers is largely a myth. If you act somewhat reasonable (that is: if someone complains to you don't ignore it, don't send spam, check your logs for indications someone might put you on a blocklist) it's no…

In my personal experience, it was certainly a problem for a while when lists like SORBS and their notoriously hostile de-listing procedures were all over the place. Listed an entire IP block assigned to a data center I had hardware in as "residential" and it took weeks to get it addressed.

And more recently, I'm still unable to send email to Verizon.net email addresses from a VPS because they too insist it's in a residential IP block. (it's not.)

For the first few weeks I had a VPS and moved a small business to it, sending anything to Gmail was a hassle as it was all automatically going to the spam folder. The typical responses from others was "find a new provider" even though checking blacklists showed the one I chose was just fine.

I too have run mail servers, and have seen enough to realize that it's definitely not a myth. It's just that there are enough spammers making a mess of things for the rest of us, which is unfortunate.

Re: Helm: Personal Email Server

#550
Interesting idea, but i'm not going to lie - I hate the case design. it reminds me of how obnoxious the Boxee Box was. Needs its own footprint, can't stack it or anything else, and it is anything but unobtrusive.

the NUC form factor would be great.

Post reply on HN