Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gsreenivas
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
61.
▲
by
gsreenivas
8y ago
because it's forwarding packets to/from the Helm server in the home
62.
▲
by
gsreenivas
8y ago
Hi there - co-founder and CEO of Helm here. It covers domain registrations, DNS records, the security gateway with a static IP that works around residential ISP limitations and storage for offsite encrypted backups. None of these would be a
63.
▲
by
gsreenivas
8y ago
unfortunately DO does not seem to be as active as Amazon in maintaining the reputation of their IPs.
64.
▲
by
gsreenivas
8y ago
This is very consistent with what our experience has been with Elastic IPs combined with email authentication and blacklist monitoring.
65.
▲
by
gsreenivas
8y ago
We are using StrongSwan right now. We've taken a close look at WireGuard but have not yet completed our evaluation. We automatically configure SPF, DKIM and DMARC for our customers. We are also investigating MTA-STS. Device diagnostics
66.
▲
by
gsreenivas
8y ago
Amazon invests in ensuring their Elastic IPs are not on blacklists. Less than 2% of IPs we get through AWS are ever on a blacklist and when they are, we cycle through until we get one that isn't.
67.
▲
by
gsreenivas
8y ago
Two things: we will run the service in perpetuity as long as there are subscribers and we will be open sourcing what is required to run the service on your own.
68.
▲
by
gsreenivas
8y ago
Yes - we initiate a VPN connection first to the gateway, then inbound/outbound connections are over TLS. Over 92% of email traffic is over TLS and we will be exposing an option in the future where customers can require it or reject ema
69.
▲
by
gsreenivas
8y ago
We don't believe it does. ISPs will only see encrypted traffic (a VPN tunnel to the gateway) so it's unclear how they will figure it's associated with a server.
70.
▲
by
gsreenivas
8y ago
Thanks balladeer - we will definitely be launching the developer program in less than one year from now.
71.
▲
by
gsreenivas
8y ago
Hey bootsz, when your connection is down, you'll still have a local cache of your messages, contacts and calendar events. Email has retry built in and sending servers typically retry for at least 48-72 hours. The hardware has no moving
72.
▲
by
gsreenivas
8y ago
yes - we do! and DMARC as well
73.
▲
by
gsreenivas
8y ago
Hi lvh - it's not a proxy. The EC2 instance can't see your emails. The Helm server initiates and receives TLS connections through the instance so it's really an extra hop on the internet. We don't see or keep data on del
74.
▲
by
gsreenivas
8y ago
Hey paraditedc - thanks for your feedback. We will be launching a developer program next year. We are very interested in a community of people like you hacking on Helm to build new services/features.
75.
▲
by
gsreenivas
8y ago
Hi TrueDuality - Giri Sreenivas, co-founder and CEO of Helm here. We will be publishing more details to answer your questions in depth in a series of coming posts. I'll give you some quick answers right now. We use Yocto to spin our ow
76.
▲
by
gsreenivas
8y ago
We use duplicity for backups so there's nothing proprietary in our approach. There will be more transparency coming in a series of technical posts about how the product works, what open source software we use, etc. Appreciate the feedb
77.
▲
by
gsreenivas
8y ago
Thanks for your encouragement! I appreciate the feedback and keep tabs on our GitHub for what we open source down the road.
78.
▲
by
gsreenivas
8y ago
Thanks for the feedback!
79.
▲
by
gsreenivas
8y ago
Thanks for your comment! Yes - we are working on making the product available in Europe early next year. Please sign up for our mailing list on our website and we'll keep you posted!
80.
▲
by
gsreenivas
8y ago
We spin our own build of Linux using Yocto. We are using an ARM-based SoC from NXP. We chose this to ensure that the device can only run signed, trusted code by implementing secure boot and signature verification of software updates. We wil
81.
▲
by
gsreenivas
8y ago
Using a hardware root of trust, secure boot and a Secure Enclave for managing keys used for full disk encryption, it will be very difficult to extract decrypted data from a Helm server. The keys never leave the Secure Enclave, they aren
82.
▲
by
gsreenivas
8y ago
Hey cwyers - this is a good question. Our offsite backups use keys that only a Helm customer has access to. They are created during the setup process and stored on a USB thumb drive we include in the box as well as your phone. We will be pu
83.
▲
by
gsreenivas
8y ago
For now, a single domain per server. And yes, mirroring support is coming with 2 servers so you will have the fail over that you mentioned.
84.
▲
by
gsreenivas
8y ago
good point - I read it with the other connotation in mind. We plan to make a developer program available in the future. Stay tuned!
85.
▲
by
gsreenivas
8y ago
Sorry if that wasn't clear. We did not design our own ICs. We selected an SoC for its security capabilities and designed our solution to utilize it integrated with our firmware. We're using an SoC from NXP.
86.
▲
by
gsreenivas
8y ago
hey bachmeir - our Helm servers do not limit the number of users. For a family, for example, you'll typically come out ahead on cost with our product.
87.
▲
by
gsreenivas
8y ago
Hi keehun - thanks for posting this on HN! I'm the co-founder and CEO of Helm. 1 - First, we cross reference IP addresses we assign to gateway against known blacklists. This helps ensure emails will be delivered. We also fully support
88.
▲
by
gsreenivas
8y ago
You can request email sending support when you set up reverse DNS.
89.
▲
by
gsreenivas
8y ago
We will be making public the configuration for these instances as part of what we publish in open source. We haven't considered allowing customers remote access to the gateway but we will based on your suggestion. Thanks!
90.
▲
by
gsreenivas
8y ago
Hi tpetry - Giri Sreenivas, co-founder and CEO of Helm here. You raise an important issue with residential IP addresses not being trusted by email senders. This is why we use a static IP address assigned to a gateway for each customer. The
More ›