9 ms·
I never understand why people think having your files physically in their homes is somehow more secure than a data center. - You run the risk of hardware failu
by andr 8y ago
I never understand why people think having your files physically in their homes is somehow more secure than a data center.
- You run the risk of hardware failure, which would take days to recover. When your warranty expires, it'd cost you, too.
- Disk failure may lose all your data.
- Fire, theft, or hurricanes may destroy it.
- You still give access to your data to a company, which controls software updates and the EC2 proxy (in this case).
- Many home ISPs have shitty upload connectivity, so your email won't work that well on the go.
- Internet and power outages mean you won't send or receive any email.
- You lose the knowledge email providers get from scale, including ever-evolving spam filters, and a guaranteed clean outgoing IP.
If you really want to control your data, just spin up something like ownCloud (not sure if that's the best solution, just an example). Companies like DigitalOcean make it as simple as point and click.
- qwertay 8y agoI think just about every internet connection can run email just fine.
- icedchai 8y agoNot necessarily. Incoming email: port 25 is blocked on many residential connections. Outgoing email: If you send email from a residential IP block you're likely going to be flagged as spam.
- lvh 8y agoIf I understand correctly, incoming e-mail actually goes to some EC2 host.
- icedchai 8y agoWith this service, yes. That is because not every internet connection can actually successfully run an email server, which proves my point...
- lvh 8y agoI wasn't debating your point; I was pointing out how this service accomplishes it without tripping over that problem. FWIW: I'm not sure that's actually how it works.
- garry 8y agoThe device talks to an AWS EC2 proxy IP that Helm makes sure isn't on an IP blacklist. All traffic that goes through that is TLS encrypted using Lets Encrypt keys.
- lvh 8y agoLike Spamhaus? Elsewhere in the thread, Giri says it uses a VPN connection. Is it TLS + something else? helm.garrytan.com:3333 for example responds with a self-signed localhost cert, not LE keys. IMAPS (still not sure why that’s there but I asked that in a different comment so let's have that thread there) and 8443 do answer with LE though :)
- jimmy1 8y agoI fail to see the point here -- data centers suffer partially or entirely from each point you referenced
- andr 8y agoI mean, the risks exist in the sense they are not absolutely zero, but can you seriously compare an average home to a data center in terms of physical security, connectivity, fire suppression, etc.?
- cwyers 8y agoYeah, there is no convenient backup policy that doesn't obviate most of the purported benefits of this device. You have to store your backups somewhere off-site to have any kind of data safety, and unless you're dumping out to tapes or some other physical media and stashing your backups in a safety deposit box, that's going to be a server somewhere.
- garry 8y agoDevelopers and devops folks can certainly do this, I know I have had to do that before for my production data. Part of the point (and the impressive software that has been built here) is that backups happen transparently, and if anything ever happens to the Helm you can get another one and get back up and running by restoring from online backups. It's the same principle: things can happen to your iPhone but you can get up and running with a new one easily.
- lvh 8y agoI'm skeptical of this device, but don't follow your reasoning. One of the device's concerns is security and privacy -- what security or privacy am I giving up by giving my backups to Tarsnap?
- joshstrange 8y agoThis was my first thought as well. My email IS very important to me which is exactly why I will never host it locally. The only content I host locally-only is stuff I would be annoyed to lose but could replace, the only content I host locally with online backup is stuff I can do without for a couple of days while I recover. Email falls into neither of those categories, I need it to be up all the time. I have considered fastmail or similar but I will never trust my home connection.
- garry 8y agoI've been running my email on Helm for the past month with no dropouts of service - it's worked with no issues this whole time, and we use Comcast in SF, so it's not the best upstream there is.
- lvh 8y agoMind sharing your domain? I'd love to peek at what they do DNS-wise. lvh at latacora dot com if you don't just want to hand it to all of HN :) The e-mail in your profile is hosted by Google, which makes sense because it looks like work email.
- j45 8y agoThe cloud ultimately is someone else's computer, abstracted away to feel good. Data loss occurs in the cloud too and it sucks. It's also dangerous to say because you don't understand or see the value in something, that there possibly can't be any. Today's home connectivity + LTE fail over is reasonable to rely on. One could put a vps proxy in front of it if you really wanted. Running a home appliance is not out of the question or unreasonable. I have a Mac mini server that is coming on 8 years of age and zero issues. Today, the combination of Ubuntu, docker, and ready to go setups make it super easy. Offsite backups are not an issue anymore. Running owncloud is good for files locally, but email is worth it in some cases. We own a lot of appliances at home that have a lifecycle to maintain already. The reality is the above issues have a much lower chance of happening than 10-15 years ago. Hardware is far more reliable and than it was, my 15 year old servers pulled from my data center were still working when I virtualized. A discovery I made was owning a PDU (like an APC Masterswitch) cleans the electricity so much enough that attached equipment don't seem to fail. I ran my own email server in a datacentre for clients for a long time because it was the norm. With Home Automation adoption increasing I suspect a home appliance of some kind will become a reality anyways. If personal data became a feature of it, that would be useful.
- alphakappa 8y agoSo what happens when you are traveling and there's a power issue or maybe some other connection issue that knocks this box out of service? Looks like you'll be stuck without email until you can physically get back to this box. This isn't a scenario you worry about with regular email. The challenge with email is that once you give out any mail address to people, you are on the hook to ensure that it's a functional address. Not something you can just try for 6 months and then easily move on from. And if you decide to move on from this service, will the average person be able to easily migrate that custom domain to a different email provider? (Yes, technically this is possible, but can normal users do it easily? Is it part of the service that Helm provides?)
- garry 8y agoAn upcoming release should have continuity of service with a 2nd box, which is not a perfect solution I realize.
- garry 8y agoI'm the first and biggest investor in Helm and I'm on the board. I created email-based Posterous previously (YC funded) and was a YC partner for 5 years. I funded this team because they're high integrity software engineers first, and we built this out of need— a company like this needs to exist because for this to work, you need both great user experience as well as great software. Helm actually solves this exactly - they already have continuity of service coming in the pipeline, and the product as-it-ships will support encrypted backup/restore out of box, similar to how your iPhone supports iCloud backup. I've run my own mail servers for Posterous before and it was probably 2 to 10 hours a month of maintenance, software updates, etc. And that's not something normals can do. The company itself is run by folks who are committed to running this as a sustainable long term business that takes are of its customers and is super responsive to the community. As a board member I promise you we'll do that.
- sinnoh 8y agono one said you can only keep one copy of anything you own.
- moviuro 8y agoRedundancy redundancy redundancy. See e.g. Unison, rsync, sanoid or https://syncthing.net https://syncthing.net - runs on anything, does a good job. > You still give access to your data to a company, which controls software updates and the EC2 proxy (in this case). Because you read all code changes every time you `pkg upgrade` or `dpkg dist-update`. > Many home ISPs have shitty upload connectivity, so your email won't work that well on the go. Is that really an issue? I probably use <100kB personnal email per day anyway. Even in the US, 100kB/day upload is not unheard of. Also, the "on-the-go" issue is DL speed: from your device to your server. How long your server takes to send the mail is mostly irrelevant - instantaneous transmission should be done by phone. > Internet and power outages mean you won't send or receive any email. More comments around here about sending servers that MUST retry, and fail only after a few days. > You lose the knowledge email providers get from scale, including ever-evolving spam filters, and a guaranteed clean outgoing IP. That could be a real issue, but the ever-evolving filters at my ISP clearly can't spot (nor stop) the spam I receive anyway. The outgoing IP shouldn't be a problem if you've registered it in your DNS, and it matches the SMTP or whatever subdomain.
- nothrabannosir 8y ago> Also, the "on-the-go" issue is DL speed: from your device to your server. How long your server takes to send the mail is mostly irrelevant - instantaneous transmission should be done by phone. Not commenting on the rest: you download incoming mail from your server, i.e. your home uplink. If someone sends you a photo or zip file, that’s the bottle neck. Not to mention syncing email with the brain dead protocol that is IMAP…
- gambler 8y agoIt's hilarious how solvable most of these problems are, and yet they aren't even closed to be solved. Like, backups. Everyone knows how this can be done. Have automated scheduled backups. Encrypt them. Send to offsite storage. This should be handled through a generic backup protocol so you can choose your provider and be sure the app doesn't siphon your personal data. Users should not need to manually fuck around to set this up for every computer and every app they use. This should be absolutely standard. Preferably built at OS level. I know Ubuntu had something of this sort, but IIRC it wasn't based on an open standard where you could choose your own storage provider. Windows? Hah. Instead, developers strip users of all control over their data claiming it's for their own good, and push everything to a myriad proprietary cloud solution through random protocols with dubious security implications.
- garry 8y agoI agree with you absolutely here. Yes, literally Helm does this: encrypted automatic backups.
- rntz 8y agoYou say Helm literally does this. But what the grandparent was asking for wasn't just backups. They suggest (as I see it) an open standard for backups, ubiquitously implemented so it's easy to switch your provider and easy to set up new devices. Does Helm use one of those? I suspect not, because I don't know of any such ubiquitously implemented open standard for automatic encrypted backups. So: is Helm going to put in the effort to define such an open standard and push for it to become ubiquitous? Even if Helm implements automatic encrypted backups, it's still contributing to a fragmented world siloed into incompatible apps and platforms. Making your siloed service better than others won't fix that problem.
- gambler 8y ago>I don't know of any such ubiquitously implemented open standard for automatic encrypted backups Here is a question for the parent poster and anyone else. Do you think it would be worthwhile to gather some people and try to design such open protocol? Without having an implementation first? Or would that be just a waste of everyone's time?
- Guest9812398 8y agoAgreed. For a service that is about security, it honestly leaves me feeling very vulnerable, and I wouldn't consider it for that reason. I'm concerned about my emails being delivered, increased spam, a thief (or government employee) walking out of my home with my email server, my modem needing a reboot while I'm on vacation and not being able to send or receive emails, and my neighbor accidentally burning down my apartment, taking my email with it. I'm a Fastmail user and pretty happy with the service. But, what's the real world benefits of Helm over an encrypted email service, like ProtonMail?
- gsreenivas 8y agoUsing a hardware root of trust, secure boot and a Secure Enclave for managing keys used for full disk encryption, it will be very difficult to extract decrypted data from a Helm server. The keys never leave the Secure Enclave, they aren't available to the application processor or memory. Most cloud-based email services hold email in the clear - we believe this means you don't really own your data. Encrypted email services have challenges around search, access via proprietary protocols and the risks of running highly sensitive operations in client-side javascript.
- lvh 8y agoHang on: are you suggesting cloud e-mail services don't use FDE?
- lolc 8y agoThey may but they also hold the keys.
- lvh 8y agoI mean, sure? You can use encryption to get security and privacy features but "FDE" isn't it. FDE is more important for Helm but that's a problem of their own design: suddenly the e-mail is in a box in my kitchen and it's a lot easier to walk out with a box in my kitchen than it is to walk out with a drive from us-east-2a :-) For anything in the cloud it's a belt-and-suspenders/compliance thing.
- blablabla123 8y agoI think the only times I lost data in the last 10 years or so was because someone accidentally deleted stuff on a shared Dropbox (luckily I had a local backup, so only the most recent changes got lost). Oh and I lost some photos that I uploaded to a Facebook clone because they more or less shut down. Data loss is more or less a solved problem. You don't need Google for that. ;-) On the other hand, even without putting my tin hat on: I get customized ads best on my email contents, WTF?! Everybody can see based on the browser ads what kind of sites I'm surfing to. > Internet and power outages mean you won't send or receive any email. Except if you have a charged battery and LTE. ;-) In fact just a charged battery is needed when network is down to read old mails. > Fire, theft, or hurricanes may destroy it. Solved problem. Encryption...
- lolc 8y agoI'm not sure you understood how helm works. Your answers don't seem to relate to the concerns of a self-hosted solution.
- blablabla123 8y agoCan you be more specific?
- lolc 8y agoThe original post was about the perils of hosting your mails at home. I'm not clear what your answer is about. For example, in a power outage, Helm won't work. You say it's not a problem with a charged battery and LTE. I think you're talking about a cell phone and I don't understand how that's related. Sure, one could run Helm on a UPS with LTE backup. But then that's extra infrastructure against the promised simplicity. Also I don't see how encryption prevents the device from being physically destroyed.
- blablabla123 8y ago> For example, in a power outage, Helm won't work. I mean you can connect it to a Uninterupptible Power Supply "USP". It's not clear if they have a high power USB connector to connect USB batteries, however: "Built-in battery backup for safe shutdown On mode: 10 W Standby: 0.4 W" (https://thehelm.com/pages/technology https://thehelm.com/pages/technology) > LTE backup. But then that's extra infrastructure against > the promised simplicity. There are low-cost routers with USB ports that allow plugging in an LTE stick. > Also I don't see how encryption prevents the device from > being physically destroyed. You can create a backup and store it on an untrusted storage (cloud for instance). I'm surprised these devices didn't take off 5 years ago already, as this is technology wise almost a step backwards into the 90s. But I think it's worth it, and in fact you don't need helm to set up a system like this yourself. Get a Raspi, stuff an LTE stick and a juicy USB storage into it together with external USB-battery in passthrough and you even have a superior device.
- hawski 8y agoYou can always put your encrypted backup on a cloud storage. This way you're left with only the key to be concerned with.