5 ms·
Hi keehun - thanks for posting this on HN! I'm the co-founder and CEO of Helm. 1 - First, we cross reference IP addresses we assign to gateway against known bl
by gsreenivas 8y ago
Hi keehun - thanks for posting this on HN! I'm the co-founder and CEO of Helm.
1 - First, we cross reference IP addresses we assign to gateway against known blacklists. This helps ensure emails will be delivered. We also fully support email authentication (DMARC, DKIM, SPF) and configure reverse DNS as well. Lastly, the IP address for a gateway stays fixed so the domain and IP will build reputation over time. Helm servers require the service to work to get around the residential internet connection challenges in the US (port blocking, dynamic IPs, untrusted IPs)
2 - We will be doing 2 things - first, we will publish as open source what is required for people to be able to run their own gateways with their own AWS account in the event Helm has to shut down. Second, the unit economics on the service are positive so as long as we have customers, my co-founder and I are dedicated to running the service. We take a page from Garry Tan and Posthaven in this regard.
3 - The way this works for sending emails, your devices that you compose emails on will connect directly with your Helm server over TLS. Your Helm server will then initiate a TLS session with the server hosting your recipient's email. So we as a company have no visibility to any of that data - at rest, or in transit. I hope this helps - I'm happy to explain this in more detail as needed.
- forapurpose 8y ago> Your Helm server will then initiate a TLS session with the server hosting your recipient's email I'm not sure how Helm doesn't see the metadata: * For outbound (as described) and inbound mail, do all mail servers support TLS connections? I was under them impression that many still communicate unencrypted. * How does Helm avoid seeing the metadata, who is communicating with whom and when?
- ryan-c 8y agoWRT to TLS, see here: https://transparencyreport.google.com/safer-email/overview?hl=en https://transparencyreport.google.com/safer-email/overview?h... It seems that Helm has no obligation or business need to log any metadata if they are providing each customer with a dedicated relay. Any abuse will come from that relay IP and can trivially be attributed to the correct customer.
- forapurpose 8y ago> Helm has no obligation or business need to log any metadata The point of Helm is to provide privacy (and end-user control) through technical means, if I understand correctly. If it's just a matter of trusting motives, I don't need a home server.
- ryan-c 8y agoI disagree. Seizing data stored on a server in your house is much, much more difficult that seizing data stored on a cloud server.
- bigiain 8y agoI can see that going both ways. The feds know that Apple (for example) are fully lawyered up, and that they need all their legally required paperwork with it's "i"s dotted and "t"s crossed before Apple will even look at their request for your data. While we know they _will_ hand over legally required data when they can and the paperwork is OKed by their legal department, they also very publicly go head to head with law enforcement when those requests are legally questionable or technically impossible. I suspect an overly broad probable cause warrant to seize all the electronic devices in your house is gonna be much easier to slip past an leo friendly judge and whatever legal representation you can muster up when they dawn-raid you - than "slipping one past" Apple's legal team. Having said that, if you've got the feds interested in your digital comms, you probably want to be getting your security advice from a much more private and trustworthy source than randoms on Hackernews...
- danilocesar 8y agoAlso, if the feds raide your home you will know that your data was compromised. Apple won/can't tell you..
- dragonwriter 8y ago> Also, if the feds raide your home you will know that your data was compromised. Not necessarily: https://en.m.wikipedia.org/wiki/Sneak_and_peek_warrant https://en.m.wikipedia.org/wiki/Sneak_and_peek_warrant
- beojan 8y agoIt sounds like the hardware device is an SMTP server that sends the email itself directly over encrypted SMTP. So, what's the subscription for?
- newman314 8y agoRegarding #3, let's work through two use cases. A) I'm at home and B) I'm on the road. A) I can connect directly, no biggie. B) I am assuming that you would require a port opened/forwarded in the firewall to work in this case. Is this correct?
- dsigurds 8y agoHi newman314, we have a gateway server that we as a company manage the gives you remove access back to your Helm. We do this without requiring you to poke holes in your firewall because the Helm establishes an outbound VPN connection to the gateway.
- newman314 8y agoThanks. Please see my other questions here. https://news.ycombinator.com/item?id=18243685 https://news.ycombinator.com/item?id=18243685
- jethro_tell 8y agoA) I can connect directly Can you? you'll probably need your own DNS resolver because if the clients are configured for my.custom.domain.com, it's not going to resolve to 10.10.10.10 and your connection is down. So you can have the box do that, but generally, split horizon DNS is a thing you don't want to set up in a set it and forget it install.
- chaitanya 8y ago>> 3 - The way this works for sending emails, your devices that you compose emails on will connect directly with your Helm server over TLS. Your Helm server will then initiate a TLS session with the server hosting your recipient's email. If my helm server connects directly with the recipient's email server won't it create problems with SPF validation? Home networks usually don't have a fixed IP address so I am not sure how SPF will work.