Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gsreenivas
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
gsreenivas
6y ago
This is a key reason for why I started Helm - thehelm.com. There's a lot of talk here about the hassle of self-hosting and while many HN folks are perfectly capable of running their own servers/services, it can be very time consum
32.
▲
by
gsreenivas
6y ago
check out Helm - thehelm.com
33.
▲
by
gsreenivas
6y ago
check out Helm - https://thehelm.com
34.
▲
by
gsreenivas
6y ago
would have loved to see a secure element in this iteration/design to enhance the security of the hardware platform
35.
▲
Dyson Lightcycle
(dyson.com)
1 points
by
gsreenivas
7y ago
|
0 comments
36.
▲
Binary Hardening in IoT Products
(cyber-itl.org)
1 points
by
gsreenivas
7y ago
|
0 comments
37.
▲
by
gsreenivas
7y ago
yep - co-founder of Helm here here's another review from Micah Lee at The Intercept for anyone who's interested: https://theintercept.com/2019/04/30/helm-email-server/
38.
▲
by
gsreenivas
7y ago
You may want to check out Helm - https://thehelm.com (I'm a co-founder)
39.
▲
by
gsreenivas
8y ago
This public review isn't be accident. For several years, an advocacy group that I was involved with briefly helped with achieving important milestones like a getting a chief privacy officer and a privacy advisory committee.
40.
▲
by
gsreenivas
8y ago
Fastmail users should be on notice with this legislation if they chose this service for privacy/security purposes.
41.
▲
by
gsreenivas
8y ago
Hey everyone, co-founder and CEO of Helm here. This post is a follow up to the thread keehun posted here: https://news.ycombinator.com/item?id=18238581 Looking forward to feedback and questions, thanks!
42.
▲
by
gsreenivas
8y ago
You missed some other ports including 25.
43.
▲
by
gsreenivas
8y ago
1.) it is globally accessible through the gateway it connects to 2.) for email services, you don't need much in the way of bandwidth for this to work very well.
44.
▲
by
gsreenivas
8y ago
There is no cable for stacking. The expansion units expose a USB-C male connector and plug into the base unit's USB-C female connector.
45.
▲
by
gsreenivas
8y ago
there is no remote administrative access from the EC2 instance or anywhere
46.
▲
by
gsreenivas
8y ago
There's an easy way to make Helm entirely uninteresting to spammers and that is for the server to limit the number of outbound emails that can be sent at a number that normal people would never exceed but that doesn't allow enough
47.
▲
by
gsreenivas
8y ago
Yes - these ports are forwarded so customers can reach the server in their home from anywhere in the world.
48.
▲
by
gsreenivas
8y ago
Good question - tightly integrated hardware based security. To support secure boot, full disk encryption and ensure keys are well protected, we utilize a security chip in the SoC. This protects your data in the event of theft.
49.
▲
by
gsreenivas
8y ago
Quite a bit more transparency is coming - we will be publishing a series of posts going into more detail of how this works. In addition, we will be open sourcing quite a bit.
50.
▲
by
gsreenivas
8y ago
Because traffic to and from the server will be over TLS, there won't be plaintext messages in memory on the gateway. We specifically designed to avoid the problems you have outlined.
51.
▲
by
gsreenivas
8y ago
gotcha - thanks for clarifying
52.
▲
by
gsreenivas
8y ago
Hey mrgalaxy - thanks for your note. We will take a look at how we can support this more efficiently. Right now we don't because we support reverse DNS for all our customers.
53.
▲
by
gsreenivas
8y ago
Thanks for the feedback stevehawk. We'll look to support multiple domains - right now costs scale with the number of domains due to the simple fact of supporting reverse DNS.
54.
▲
by
gsreenivas
8y ago
It's possible but not something we would ever do. We are looking at STARTTLS Everywhere from EFF as means to help ensure that any cert changes would be tracked transparently. #1 is something we will support via open source.
55.
▲
by
gsreenivas
8y ago
Not to mention having to wake up in the middle of the night when the VPS provider decides to reboot your VM so you can decrypt the volume on boot. Been there, done that for years.
56.
▲
by
gsreenivas
8y ago
The last bullet isn't intended to be a catch-all but to reflect the fact that we can't control what customers provide us via customer support.
57.
▲
by
gsreenivas
8y ago
I'm curious about how you arrived at the conclusion that we are capable of dragnet surveillance. Connections to/from the Helm server use TLS end to end.
58.
▲
by
gsreenivas
8y ago
Good guess and we looked at the i.MX but did not select that line of SoCs. We are using the Layerscape line of SoCs from NXP
59.
▲
by
gsreenivas
8y ago
Thanks!
60.
▲
by
gsreenivas
8y ago
Thanks for the feedback - we will take this into consideration.
More ›