8 ms·
hey jawns, great question. I'm Giri Sreenivas, co-founder and CEO of Helm. To answer your question, ISPs block port 25 and email service providers typically rej
by gsreenivas 8y ago
hey jawns, great question. I'm Giri Sreenivas, co-founder and CEO of Helm. To answer your question, ISPs block port 25 and email service providers typically reject emails coming from residential IP blocks.
To build a plug and play solution, we knew that our server could not require listening for inbound connections on a residential internet connection. So we set about looking into how we could route traffic to and from a home server but we needed to do this in a way that prevented us from being able to spy on traffic. We investigated solutions like sshuttle and eventually settled on the combination of a simple iptables configuration combined with a VPN connection. Helm establishes an outbound VPN connection to a dedicated EC2 instance with an iptables configuration that routes packets to and from the connected Helm server. The EC2 instance also has a static IP address associated with it.
It's important to stop here and explain that the only way this architecture is viable while adhering to our design tenet of knowing as little about our customers as possible is because of the Let's Encrypt project. Every Helm server has a unique domain associated with it and trusted certificates for that domain are fetched from Let's Encrypt. We strive to ensure that all inbound and outbound traffic routed through the EC2 instance is using TLS with these certificates from Let's Encrypt. This way, our EC2 instance is effectively just an extra hop on the Internet.
I hope that answers your question, let me know!
- keehun 8y agoFor the most advanced of users, would you opensource the server so that we can host our own gateway servers instead of relying on Helm? That would solve the "what happens if Helm goes down" question and "how do we trust Helm" question. Still wouldn't solve "how do I know my emails won't end up in spam" but at least we're getting closer (to at least what I would want to pay for.)
- jethro_tell 8y agowouldn't that be postfix and a caldav server?
- jawns 8y agoThank you for this very informative reply. (I hope you'll put this information in a more prominent place on your site.)
- voidmain0001 8y agoI found the answer by clicking Technology from the top menu, and the explanation is the very first paragraph to be read.
- davidmr 8y ago“To a unique gateway” with a static IP is hardly an actual answer. Under whose AWS account is this server provisioned? Who has root?
- voidmain0001 8y agoIt was enough to answer user jawns' question.
- dagi3d 8y agoI thought that sending email from EC2 instance was not allowed and only option was using their SES service.
- Hello71 8y agoI'm pretty sure it's allowed, it's just that you'll get caught in every spam filter. I don't know if they've considered that problem, or they're just hoping that using the same IPs long-term will fix the problem in reputation-based blacklists.
- gsreenivas 8y agoYou can request email sending support when you set up reverse DNS.
- bpye 8y agoI guess email can be sent from the residential connection but recieved through EC2?
- specialp 8y agoYou can send email from an EC2 instance but good luck getting anyone to accept it. A lot of email providers block EC2 wholesale, or if they do accept it you are going to have to have a long standing reputation.
- CogitoCogito 8y agoWhat do you mean by blocking "wholesale"? I started hosting an email server in EC2 and the worst I've had is my emails going to a spam folder if that person hasn't received an email from my address yet (and never after they've marked me as not being spam). That happened surprisingly rarely and didn't feel like much worse than I would get by just sending people email from gmail with an address they don't know. I don't think things are as bas as you make them out to be. edit: I guess I should be clear that I have an elastic IP (which is free) and setup reverse DNS and DKIM and SPF, but I think those are fairly standard now a days (I don't know honestly I've only run an email server for a few months).
- nickdandakis 8y agoIt's interesting that Amazon is portrayed as the "massive corporate server" provider that stores your email "outside your home" on your homepage, yet you use AWS EC2 instances to pipe email traffic to/from Helm. I understand that it's just an encrypted VPN connection, and are not actually storing email on the EC2 instances. But is there any way for your customers to ensure that? Can your customers shell into the Helm and/or EC2 instance(s)?
- gsreenivas 8y agoWe will be making public the configuration for these instances as part of what we publish in open source. We haven't considered allowing customers remote access to the gateway but we will based on your suggestion. Thanks!
- bigiain 8y agoIf you _do_ "consider it", I hope you discard it as an awful idea pretty much immediately. I'd suggest allowing customers who're concerned to run their own instances with your code on it (perhaps a Docker image?) - but giving random customers shell access to gateways you're responsible for (at least to Amazon) - would be insane... Signal/WhisperSystems are doing some interesting work on how to prove the code running on their servers is identical to their published and auditable code - might be worth checking that out (for a post MVP roadmap idea).
- wmf 8y agoYeah, there'a a lot of confusion about "the cloud". Consumer SaaS (Gmail, Facebook, Alexa, etc.) is "evil" and privacy-invading but B2B IaaS (EC2, GCP, etc.) is not bad. Often these services come from the same companies so we can't simply claim that Amazon or Google are wholly good or evil when it comes to privacy.
- deleted 8y ago[deleted]
- specialp 8y agoIf you are proxying the content with a VPN with a static IP on an EC2 instance you cannot police people sending out spam as you cannot see and meter the SMTP traffic. So does everyone get a dedicated instance and IP? If that is the case people are going to have issues getting their email accepted by almost all providers due to the IP being new and on a cloud provider block. If it is a subset of IPs that you create a reputation for and comply with DKIM, SPF etc how are you going to keep it from getting ruined by bad actors? I am glad you are doing this because running a mail server is non trivial. I have done it for a long time now and love the fact that I own my email identity. It is one of the few things left you can own online.
- graybolt 8y agoI think this is the biggest problem. If there are a lot of bad actors, you drag down the whole system, but if you try to prevent bad actors you run into a lot of issues. A hard problem, and I don't envy anyone trying to solve it.
- heartles 8y agoNo offense, but given that you are making a product that has a much higher potential to enable bad actors than usual, isn't it kind of you/your company's job to try to solve it? EDIT: Just realized I responded to the wrong person :(
- jhabdas 8y agoNo, it's not. In fact it's your job to try and police yourself. But you probably on someone else to control you don't you?
- heartles 8y agoI mean, my thought is that if a high volume of spam causes other email servers to block Helm, then it makes it unusable to the good actors in the system. I didn't see the CEO address this. Or, maybe I just misunderstand smtp idk
- pmoriarty 8y agoSince most email's not encrypted, how is having each Helm user's email hop through your server any better for them in terms of privacy than just hosting their email on a remote mail provider in the first place? You could still record every incoming and outgoing email as it goes through your server, couldn't you? I really don't see the advantage of Helm.
- ryan-c 8y agoMost (gmail claims ~90%) email is encrypted with opportunistic TLS in transit and can't be passively monitored. https://transparencyreport.google.com/safer-email/overview?hl=en https://transparencyreport.google.com/safer-email/overview?h... Further, "the provider could intercept email" and "the provider stores all email" are very very different.
- A2017U1 8y agoWhat's going on there with the "Support for encryption in transit" section? Overwhelmingly at 0% in most regions which they say are: > domains in terms of volume of email to and from Gmail, in alphabetical order Something doesn't add up there.
- kukx 8y agoThe table does not include the "green" domains by default, you have to select it.
- gsich 8y agoThis is transport encryption, not actual email encryption.
- lvh 8y agoWhat else runs on that EC2 instance?
- rsingel 8y agoAlso the fact that we can't run servers from our home connections is ripe for a challenge if we ever get net neutrality protections back. The 2015 Order said this, "A person engaged in the provision of broadband Internet access service, insofar as such person is so engaged, shall not block lawful content, applications, services, or nonharmful devices, subject to reasonable network management." I would argue that banning personal email servers or personal servers at all is not reasonable network management (e.g. a nest thermometer or a smart microwave or an Alexa/Siri thing is a server), and if we're looking to explore home appliances that decentralize the web, we need to ensure that broadband providers' policies don't block them. Google Fiber screwed this up too.
- masukomi 8y agodoesn't matter if we are contractually allowed to run them or not. The dynamic IPs of consumer ISPs are all blacklisted by the spam blockers. So, you could receive mail, but no-one would ever receive yours.
- michaelmior 8y ago> hey jawns, great question. I'm Giri Sreenivas, co-founder and CEO of Helm. To answer your question, ISPs block port 25 and email service providers typically reject emails coming from residential IP blocks. > To build a plug and play solution, we knew that our server could not require listening for inbound connections on a residential internet connection. So we set about looking into how we could route traffic to and from a home server but we needed to do this in a way that prevented us from being able to spy on traffic. We investigated solutions like sshuttle and eventually settled on the combination of a simple iptables configuration combined with a VPN connection. Helm establishes an outbound VPN connection to a dedicated EC2 instance with an iptables configuration that routes packets to and from the connected Helm server. The EC2 instance also has a static IP address associated with it. > It's important to stop here and explain that the only way this architecture is viable while adhering to our design tenet of knowing as little about our customers as possible is because of the Let's Encrypt project. Every Helm server has a unique domain associated with it and trusted certificates for that domain are fetched from Let's Encrypt. We strive to ensure that all inbound and outbound traffic routed through the EC2 instance is using TLS with these certificates from Let's Encrypt. This way, our EC2 instance is effectively just an extra hop on the Internet. > I hope that answers your question, let me know! This doesn't seme to address the question of whether this violates the ToS, regardless of whether this is technically feasible.
- naber 8y agoGray area IMHO. Isn't Dropcam basically a server streaming video to my phone?
- Latteland 8y agoHa, but that's "okay" because it's a big company. They never have problems with being used for spam - of course I'm being sarcastic.
- johnmaguire2013 8y agoI'm pretty sure that video feed is actually sent to your phone through a Dropcam cloud server. Your Dropcam is a client which connects to the cloud server, as is your phone.
- cjbprime 8y agoOutgoing email from EC2 nodes isn't trusted by recipient domains either. That's why AWS wants you to use SES instead.
- gsreenivas 8y agoAmazon invests in ensuring their Elastic IPs are not on blacklists. Less than 2% of IPs we get through AWS are ever on a blacklist and when they are, we cycle through until we get one that isn't.
- codexon 8y agoI'm not sure how they can invest in that. I've seen amazon ec2 ips being used for ddos attacks and I blacklist the entire range for many of my websites/projects. The vast majority of visitors we get from there are abusive.
- lrvick 8y agoBut you pay for this EC2 instance, and all traffic flows through it. Honest question: What stops a malicious employee on your end sshing to this server and dumping plaintext messages from memory? What stops a court from ordering you to do that? Even if you disable remote access, what stops someone from adding a new LaunchConfiguation that enables it silently on the next instance rotation in spite of whatever configuration is in place today? At the end of the day it seems like you -can- spy on the traffic just as easily as you could if you were running the smtp services on an ec2 instance directly. Given that, what is the value proposition here? (Or if I am totally wrong, by all means call me out accordingly)
- dna_polymerase 8y agoWell the E-Mail server still runs locally. While they could intercept traffic on their VPN endpoint, the traffic should be encrypted (TLS). However, I am not to sure if all e-mail servers speak TLS to each other.
- lrvick 8y agoWell if it does VPN first, then initiates the SMTP connection with TLS on the local smtp server all the way to the RX mail server, then this works out fine. A lot of mail servers don't support this though, so it would be on the client to also be able to ensure it will not relay mail except to TLS endpoints verified by a well known CA. In my experience this is rarely the case, but if it is and Helm is willing to tell end users "sorry I can't safely send mail to this endpoint" then I could see some value to this approach.
- gsreenivas 8y agoYes - we initiate a VPN connection first to the gateway, then inbound/outbound connections are over TLS. Over 92% of email traffic is over TLS and we will be exposing an option in the future where customers can require it or reject emails.
- i2shar 8y agoIn all honesty, couldn't this be a question to Amazon for anything that ever runs on any EC2 instance? What makes you not distrust any cloud vendor when they manage every bit of your information including keys.
- ChuckMcM 8y agoI believe you will be more successful if you establish two things, first your own ASIN with a couple of class C IPV4 blocks and an IPV6 block. Then you create an infrastructure for relaying the mail from your boxes to the Internet. Then you work with the various spam agencies to create both a way to respond to spam complaints and to detect and throttle or cut off spam senders. You'll find that spammers will offer to pay you a premium to "look the other way" but don't take it, many good companies died going down that road. Without the spammers it will be harder to make your numbers but concentrate on keeping your efficiency high and ultimately you will be better off. You don't talk a lot about data protection on site for things like disk failure. What do you do in that regard to keep people from losing all of their mail if the disk goes tits up?
- le-mark 8y agoand to detect and throttle or cut off spam senders Isn't throttling outbound email count/day from the start the only real solution?
- ChuckMcM 8y agoIn my experience you can't know what is 'normal' until you have seen it, so fixing the rate at the start would be unduly onerous. People have lives which can sometimes look spammy, like you are made the coordinator of the school potluck and suddenly you're sending email to 150 parents asking them to volunteer to bring food. But after that event you go back to your regular rate. Because this isn't a "PC" in the sense that it is more difficult to be overtaken by a virus and start sending spam without your knowledge, and as a mail service provider you know that email originating from the device has to come from a specific domain, you have a lot more tools to detect that someone is being a bad actor or not.
- jethro_tell 8y agoNo, the way the big boys get around this is outbound email filtering. Limits yes, session and connection heuristics, reading your outbound email to see if you're selling dick pills.
- milesward 8y agoThat EC2 instance is going to need whitelisting and constant vigilance that you're not sending commercial email or they'll block that port too. What prevents me from deploying a few hundred Helms to send spam?
- Latteland 8y agocommercial means spam? I can't use this for my non-spam business? MyStartup.com? A few 100 helms would cost a lot (500*200 = 100k), no one will spend that much for spam farm, you'd do it on the cheap.
- woodrowbarlow 8y agoif your company folds and the cloud service goes offline, does that render my helm useless? that wouldn't make me feel like i "own [my] email".
- gsreenivas 8y agoTwo things: we will run the service in perpetuity as long as there are subscribers and we will be open sourcing what is required to run the service on your own.
- deleted 8y ago[deleted]
- lowry 8y agoI would first try using port 587 and only afterwards route through Amazon or something.
- newman314 8y agoWhat VPN solution are you using? Wireguard or something else? Do you have a plan to help make email security features easy to consume: SPF, DMARC, MTA-STS etc.? Is there a way to opt out on the information that is collected? I looked on your site but it does not show a logical architecture which might be useful for some of us.
- gsreenivas 8y agoWe are using StrongSwan right now. We've taken a close look at WireGuard but have not yet completed our evaluation. We automatically configure SPF, DKIM and DMARC for our customers. We are also investigating MTA-STS. Device diagnostics are opt-in by default so they are not collected. Customer data like shipping and billing information is not opt-out unfortunately as we need to be able to process payments, ship the unit and track warranty coverage. Appreciate the feedback on wanting more architectural details. This will be coming in a series of technical posts explaining how we designed and built the product. Stay tuned and thanks for your questions!