Helm: Personal Email Server
thehelm.com
thehelm.com
1. How do they ensure high, non-spam delivery rates to the main email services like Gmail, Fastmail, Yahoo, and Microsoft?
2. How would the product work in case Helm the company/service goes away (or even just service outage)? Can the device work on its own without the need for their web service (perhaps with lower delivery rate/higher spam score)?
They claim:
>> We’ve designed your Helm to ensure as little information about you as possible is communicated back to us. That’s why the only account you create is directly with your server, not with us, and why only encrypted data passes through our servers.
But how does that work with sending emails? (Please excuse my ignorance on this matter.)
1 - First, we cross reference IP addresses we assign to gateway against known blacklists. This helps ensure emails will be delivered. We also fully support email authentication (DMARC, DKIM, SPF) and configure reverse DNS as well. Lastly, the IP address for a gateway stays fixed so the domain and IP will build reputation over time. Helm servers require the service to work to get around the residential internet connection challenges in the US (port blocking, dynamic IPs, untrusted IPs)
2 - We will be doing 2 things - first, we will publish as open source what is required for people to be able to run their own gateways with their own AWS account in the event Helm has to shut down. Second, the unit economics on the service are positive so as long as we have customers, my co-founder and I are dedicated to running the service. We take a page from Garry Tan and Posthaven in this regard.
3 - The way this works for sending emails, your devices that you compose emails on will connect directly with your Helm server over TLS. Your Helm server will then initiate a TLS session with the server hosting your recipient's email. So we as a company have no visibility to any of that data - at rest, or in transit. I hope this helps - I'm happy to explain this in more detail as needed.
If my helm server connects directly with the recipient's email server won't it create problems with SPF validation? Home networks usually don't have a fixed IP address so I am not sure how SPF will work.
I'm not sure how Helm doesn't see the metadata:
* For outbound (as described) and inbound mail, do all mail servers support TLS connections? I was under them impression that many still communicate unencrypted.
* How does Helm avoid seeing the metadata, who is communicating with whom and when?
A) I can connect directly, no biggie.
B) I am assuming that you would require a port opened/forwarded in the firewall to work in this case. Is this correct?
Another big one for me is the failure modes. What do I do when my home connection is down? How about when my connection is down and I'm traveling? What happens when the hardware fails? How about when the hardware fails 5 years from now?
Having email just down for a couple days while you wait for new hardware to would be a very bad experience.
https://penguindreams.org/blog/how-google-and-microsoft-made...
The way most of these providers deal with spam is they slowly white-list IP addresses. When a company like Mailchip or Mailgun spin up a new server, it's always in a large subnet range they've purchased and they slowly start sending low priority e-mail through it to existing/known receivers and throttle it up to full speed.
If you're running a personal server that sends like 5 or 6 e-mails a days, well that's an issue.
The big players make it difficult to run a small personal server, but running a dedicated business or corporate server that sends 100s of e-mails per day is typically fine once it's well established.
You know what would be a better product? A relay SMTP server that works with Google/Microsoft/Amazon/Fastmail et. al. to pump e-mail from personal servers and ensures it won't get caught in spam filters.
> While offline, emails sent to you will not be delivered. This does not, however, mean that they are lost. If your email server becomes unreachable for any reason, the sender’s email server will periodically retry sending the email at a later time. Email servers are generally configured to retry rapidly at first and then back off and increase the time between retries.
> Once your email server comes back online and a retry is performed, you will successfully receive the sent email. If your email server is offline for an extended period of time, the sending server will eventually give up and send a bounce message to the person who sent you the email.
This is the big obstacle preventing me (and I assume others) from moving away from cloud. Cloud services just work, everywhere, all the time (effectively). I'd love to get the privacy benefits of bringing my data "in-house" but I'm not sure I want to take on the equivalent of a part-time sysadmin job.
Perhaps relay the email out via your ISP account? I do that and it works well.
> Having email just down for a couple days while you wait for new hardware to would be a very bad experience.
Perhaps set up a fallback MX that directs traffic to e.g. a Mailfence account when your primary MX is down? Works for me. Also, mail servers can be cheap hardware (an old x220 will do).
I run mail servers. I believe the idea that mail delivery is a problem for small mail providers is largely a myth. If you act somewhat reasonable (that is: if someone complains to you don't ignore it, don't send spam, check your logs for indications someone might put you on a blocklist) it's no big problem.
I think the myth comes largely from people who are actually spammers, but don't see themselves as that.
Some ISPs allow you to pay for a proper static IP to get around this problem, but again some of the ranges are still in the block lists. The only way I could guarantee that my IP wasn't blacklisted was to switch to a business account with my ISP and thus have IPs from a different range.
If you are stuck on a non-static IP, the easiest way around the problem is to send via the SMTP smarthost that your ISP hosts.
---
[1] They are technically dynamic IPs, but are sticky in that you keep the same IP unless your router goes offline for more than a couple of hours.
And more recently, I'm still unable to send email to Verizon.net email addresses from a VPS because they too insist it's in a residential IP block. (it's not.)
For the first few weeks I had a VPS and moved a small business to it, sending anything to Gmail was a hassle as it was all automatically going to the spam folder. The typical responses from others was "find a new provider" even though checking blacklists showed the one I chose was just fine.
I too have run mail servers, and have seen enough to realize that it's definitely not a myth. It's just that there are enough spammers making a mess of things for the rest of us, which is unfortunate.
We end up on Hotmail/Outlook's blocklist about once a year. They remove it within 1-2 hours after opening a ticket.
I suspect whatever this Helm thing is, they manage to do things right on that front as well; everything else I don't know.
Open up the hardware component as a platform for anyone to extend (allowing direct ssh, or using my own hardware). It's fine to not open source the email server code. But I would like to utilize the hardware to do other things, like file storage, etc. Instead of waiting for your company to build other features, I would rather have community contributed (preferably open source) plugins that integrates with your ecosystem and runs on the hardware.
When the iPhone came out, it didn't support apps - just built-in features like Mail and Mobile Safari. I agree with you that an app store for Helm could be valuable.
I know Nylas tries to do this, but their model doesn't really work for me.
Also, it is not clear how it works without a static IP from my ISP.
Comcast terms:
> use or run dedicated, stand-alone equipment or servers from the Premises that provide network content or any other services to anyone outside of your Premises local area network (“Premises LAN”), also commonly referred to as public services or servers. Examples of prohibited equipment and servers include, but are not limited to, email, web hosting, file sharing, and proxy services and servers
Verizon terms:
> You also may not exceed the bandwidth usage limitations that Verizon may establish from time to time for the Service, or use the Service to host any type of server.
AT&T terms:
> using such account for the purpose of operating a server of any type;
Sources:
https://www.xfinity.com/corporate/customers/policies/highspe...
https://www.verizon.com/about/terms-conditions/verizon-onlin...
To build a plug and play solution, we knew that our server could not require listening for inbound connections on a residential internet connection. So we set about looking into how we could route traffic to and from a home server but we needed to do this in a way that prevented us from being able to spy on traffic. We investigated solutions like sshuttle and eventually settled on the combination of a simple iptables configuration combined with a VPN connection. Helm establishes an outbound VPN connection to a dedicated EC2 instance with an iptables configuration that routes packets to and from the connected Helm server. The EC2 instance also has a static IP address associated with it.
It's important to stop here and explain that the only way this architecture is viable while adhering to our design tenet of knowing as little about our customers as possible is because of the Let's Encrypt project. Every Helm server has a unique domain associated with it and trusted certificates for that domain are fetched from Let's Encrypt. We strive to ensure that all inbound and outbound traffic routed through the EC2 instance is using TLS with these certificates from Let's Encrypt. This way, our EC2 instance is effectively just an extra hop on the Internet.
I hope that answers your question, let me know!
I am glad you are doing this because running a mail server is non trivial. I have done it for a long time now and love the fact that I own my email identity. It is one of the few things left you can own online.
I understand that it's just an encrypted VPN connection, and are not actually storing email on the EC2 instances. But is there any way for your customers to ensure that? Can your customers shell into the Helm and/or EC2 instance(s)?
Then you create an infrastructure for relaying the mail from your boxes to the Internet. Then you work with the various spam agencies to create both a way to respond to spam complaints and to detect and throttle or cut off spam senders. You'll find that spammers will offer to pay you a premium to "look the other way" but don't take it, many good companies died going down that road. Without the spammers it will be harder to make your numbers but concentrate on keeping your efficiency high and ultimately you will be better off.
You don't talk a lot about data protection on site for things like disk failure. What do you do in that regard to keep people from losing all of their mail if the disk goes tits up?
> To build a plug and play solution, we knew that our server could not require listening for inbound connections on a residential internet connection. So we set about looking into how we could route traffic to and from a home server but we needed to do this in a way that prevented us from being able to spy on traffic. We investigated solutions like sshuttle and eventually settled on the combination of a simple iptables configuration combined with a VPN connection. Helm establishes an outbound VPN connection to a dedicated EC2 instance with an iptables configuration that routes packets to and from the connected Helm server. The EC2 instance also has a static IP address associated with it.
> It's important to stop here and explain that the only way this architecture is viable while adhering to our design tenet of knowing as little about our customers as possible is because of the Let's Encrypt project. Every Helm server has a unique domain associated with it and trusted certificates for that domain are fetched from Let's Encrypt. We strive to ensure that all inbound and outbound traffic routed through the EC2 instance is using TLS with these certificates from Let's Encrypt. This way, our EC2 instance is effectively just an extra hop on the Internet.
> I hope that answers your question, let me know!
This doesn't seme to address the question of whether this violates the ToS, regardless of whether this is technically feasible.
Still wouldn't solve "how do I know my emails won't end up in spam" but at least we're getting closer (to at least what I would want to pay for.)
The 2015 Order said this, "A person engaged in the provision of broadband Internet access service, insofar as such person is so engaged, shall not block lawful content, applications, services, or nonharmful devices, subject to reasonable network management."
I would argue that banning personal email servers or personal servers at all is not reasonable network management (e.g. a nest thermometer or a smart microwave or an Alexa/Siri thing is a server), and if we're looking to explore home appliances that decentralize the web, we need to ensure that broadband providers' policies don't block them. Google Fiber screwed this up too.
Honest question: What stops a malicious employee on your end sshing to this server and dumping plaintext messages from memory? What stops a court from ordering you to do that?
Even if you disable remote access, what stops someone from adding a new LaunchConfiguation that enables it silently on the next instance rotation in spite of whatever configuration is in place today?
At the end of the day it seems like you -can- spy on the traffic just as easily as you could if you were running the smtp services on an ec2 instance directly.
Given that, what is the value proposition here?
(Or if I am totally wrong, by all means call me out accordingly)
You could still record every incoming and outgoing email as it goes through your server, couldn't you?
I really don't see the advantage of Helm.
Do you have a plan to help make email security features easy to consume: SPF, DMARC, MTA-STS etc.?
Is there a way to opt out on the information that is collected?
I looked on your site but it does not show a logical architecture which might be useful for some of us.
SMTP is more problematic because of spam: outbound traffic on port 25 is blocked, so a true home mail server won't work without a reachable gateway mail server somewhere else. That's basically what the linked product is: they manage the protocol side of the service on your behalf, and forward all the content to your local device which connects to them via some internal protocol.
When it comes to consumer internet services, the US is a 3rd world country, which is kinda odd considering most of the western world does their business there.
I just checked the terms on my 300/300 fiber connection, as well as my (backup, company paid) 25/5 ADSL.
They're almost identical:
* no spamming. * no racism/unethical behavior. * no portscanning. * no illegal downloads/uploads.
Besides that i can use it for whatever i like. They block port 25 though, and you can only get it opened by purchasing a commercial connection. It has a dynamic IP address that only changes when i reboot my modem, which happens once every 2 years or so, so practically static IP :)
The ADSL has all ports open and a staic IP.
Generally they don’t care if it’s for personal use. I’ve heard of them shutting people down for something they saw as business related. They didn’t really get shut down, it was more like a friendly “We see what you’re doing and a business plan would allow you to do it for $30 more a month”.
That seems to have potential for abuse.
> provide network content or any other services to anyone outside of your Premises local area network
I'm not sure if Verizon has the same intention, but if they take their own wording exceptionally strict, you would be in the wrong whenever you play a multiplayer game and end up being the host.
Generally in my own experience they don't want you hosting a service opened to the general public running all the time. I think running an open mail relay would get you banned very quick. It seems like this product is intended to be used purely for yourself.
AT&T terms: >• with respect to dial-up accounts, using any software or device designed to defeat system time-out limits or to allow Customer's account to stay logged on while Customer is not actively using the IP Services or using such account for the purpose of operating a server of any type;
I have many servers on att internet, including email.
And yes, the no servers clause is an issue, it was raised initially by people doing peer to peer torrenting, and some folks running servers.
Enforcement is a bit tricky though because folks like Comcast and Verizon get so much value from being able to see all of your Internet traffic that they won't actually cut you off for running a local server but they will be passive aggressive about it. For example, they will start changing your IP every couple of hours (they set the DHCP lease time to be low and force the DHCP server to always give you a different IP).
The common solution is a VPN tunnel which is what Helm is doing, but that tunnel has to end up somewhere so that can be a problem if that 'somewhere' is commonly used by bad actors. (Like say in Ukrainian data centers)
I expect that this restriction will go the way of paid SMS messages eventually but for now it is going to be troublesome.
Also IANAL but "services to anyone outside" does not sound like it includes un-firewalled, password-protected, services for personal use. The word used is "anyone outside" not "any machine outside". The resident themself would presumably be an insider regardless of their physical or network location.
Also I think a reverse proxy with end-to-end encryption could solve the problem with no public-facing open ports. That doesn't count as a server in my book.
1: http://www.centurylink.com/legal/en/highspeedinternetsubscri...
I don't think there is a good enough definition of "server" or "serving" for such restrictions to be enforceable except is an arbitrary way.
I have an MUA that retrieves email from a server and sends email to a server. It might run in a browser and interact with GMail. It might be a mobile app or Thunderbird or Outlook. It might be sendmail or postfix or Exchange. Which of these are "servers"? Which are banned and which are ok?
> with respect to dial-up accounts, using any software or device designed to defeat system time-out limits or to allow Customer's account to stay logged on while Customer is not actively using the IP Services or using such account for the purpose of operating a server of any type;
AFAIK, AT&T does not prohibit running a server on broadband accounts.
What's being done by Helm is not much different than using Back to my Mac or Plex or SlingTV.
In any case, these ToS are over-broad and most customers probably violate them every day, especially the copyright provisions. The ToS are not enforced to the letter but allow the ISP to terminate an account if the violations are egregious. I don't think running a Helm server would get you booted.
If you're going to tin your own mail server, it's paying for a good VPS. Beside the guaranteed static IP, being on an IP block with a good reputation, good VPS provider have redundant power sources and console access over the web, which you are unlikely to have either from home.
- You run the risk of hardware failure, which would take days to recover. When your warranty expires, it'd cost you, too.
- Disk failure may lose all your data.
- Fire, theft, or hurricanes may destroy it.
- You still give access to your data to a company, which controls software updates and the EC2 proxy (in this case).
- Many home ISPs have shitty upload connectivity, so your email won't work that well on the go.
- Internet and power outages mean you won't send or receive any email.
- You lose the knowledge email providers get from scale, including ever-evolving spam filters, and a guaranteed clean outgoing IP.
If you really want to control your data, just spin up something like ownCloud (not sure if that's the best solution, just an example). Companies like DigitalOcean make it as simple as point and click.
Helm actually solves this exactly - they already have continuity of service coming in the pipeline, and the product as-it-ships will support encrypted backup/restore out of box, similar to how your iPhone supports iCloud backup.
I've run my own mail servers for Posterous before and it was probably 2 to 10 hours a month of maintenance, software updates, etc. And that's not something normals can do.
The company itself is run by folks who are committed to running this as a sustainable long term business that takes are of its customers and is super responsive to the community. As a board member I promise you we'll do that.
I looked for the founders bio, a company contact info. There is nothing on their site. All I saw was a letter in the "About" section by the founder.
You might have gotten to know these guys after various meetings and due diligence process. There is nothing on their website that sells me on trusting them or the company.
I had to go the "Careers" section to see the location of the company.
When you're in the business of selling trust, you really need to focus on selling trust first and not technology (maybe they're connected ultimately) but I just don't feel I can trust this company based on the materials provided on their website.
Hope this feedback is meaningful.
What's the base operating system and hardware architecture the box is based on? It says "Linux" on the page but doesn't go into specifics.
Why not just use regular hardware, e.g. Intel NUCs, or even allow people to run your software on their own hardware (like OwnCloud does)?
In Germany there was/is a startup, Protonet (https://protonet.com/), that had almost the exact same idea a while ago. They went bankrupt though and one of the reasons was that it cost a ton of money to design and produce their own hardware, which also looked very cool (orange hexagon!) but didn't provide much added value beyond what a normal, boring-looking compact PC could provide (at 500 € less than their box for the same specs). They also marketed their own OS, which was based on a modified Linux distribution, modified open-source software and a shiny management layer on top as well. They found out that developing and maintaining a Linux fork isn't so easy either, so they eventually canned it. So what's different about Helm in your opinion?
But if I don't actually need to be able to reach the box in order to use my email - if it will work even when the box is offline, powered-down, stolen, or destroyed - then what, exactly, is the point of the $500 box itself?
It's not privacy, it seems. If it were private, how could it work when the box is offline?
I'm not opposed to a "pay for your email instead of it being ad-and-surveillance-supported" model. I just don't see the point of paying $500 for a box that you're telling me the service will function just fine without.
I think it is a great idea to have a device which is as simple to use as a router but focused on typical cloud services. As security is a critical aspect of the whole idea, the subscription service is a smart move too. Maybe you should offer a monthly subscription too (consumer friendly).
Are there any plans to start shipping to Europe in the near future?
Like, backups. Everyone knows how this can be done. Have automated scheduled backups. Encrypt them. Send to offsite storage. This should be handled through a generic backup protocol so you can choose your provider and be sure the app doesn't siphon your personal data.
Users should not need to manually fuck around to set this up for every computer and every app they use. This should be absolutely standard. Preferably built at OS level. I know Ubuntu had something of this sort, but IIRC it wasn't based on an open standard where you could choose your own storage provider. Windows? Hah.
Instead, developers strip users of all control over their data claiming it's for their own good, and push everything to a myriad proprietary cloud solution through random protocols with dubious security implications.
> You still give access to your data to a company, which controls software updates and the EC2 proxy (in this case).
Because you read all code changes every time you `pkg upgrade` or `dpkg dist-update`.
> Many home ISPs have shitty upload connectivity, so your email won't work that well on the go.
Is that really an issue? I probably use <100kB personnal email per day anyway. Even in the US, 100kB/day upload is not unheard of.
Also, the "on-the-go" issue is DL speed: from your device to your server. How long your server takes to send the mail is mostly irrelevant - instantaneous transmission should be done by phone.
> Internet and power outages mean you won't send or receive any email.
More comments around here about sending servers that MUST retry, and fail only after a few days.
> You lose the knowledge email providers get from scale, including ever-evolving spam filters, and a guaranteed clean outgoing IP.
That could be a real issue, but the ever-evolving filters at my ISP clearly can't spot (nor stop) the spam I receive anyway.
The outgoing IP shouldn't be a problem if you've registered it in your DNS, and it matches the SMTP or whatever subdomain.
Not commenting on the rest: you download incoming mail from your server, i.e. your home uplink. If someone sends you a photo or zip file, that’s the bottle neck.
Not to mention syncing email with the brain dead protocol that is IMAP…
It's also dangerous to say because you don't understand or see the value in something, that there possibly can't be any.
Today's home connectivity + LTE fail over is reasonable to rely on. One could put a vps proxy in front of it if you really wanted.
Running a home appliance is not out of the question or unreasonable. I have a Mac mini server that is coming on 8 years of age and zero issues.
Today, the combination of Ubuntu, docker, and ready to go setups make it super easy. Offsite backups are not an issue anymore. Running owncloud is good for files locally, but email is worth it in some cases.
We own a lot of appliances at home that have a lifecycle to maintain already.
The reality is the above issues have a much lower chance of happening than 10-15 years ago.
Hardware is far more reliable and than it was, my 15 year old servers pulled from my data center were still working when I virtualized.
A discovery I made was owning a PDU (like an APC Masterswitch) cleans the electricity so much enough that attached equipment don't seem to fail. I ran my own email server in a datacentre for clients for a long time because it was the norm.
With Home Automation adoption increasing I suspect a home appliance of some kind will become a reality anyways. If personal data became a feature of it, that would be useful.
The challenge with email is that once you give out any mail address to people, you are on the hook to ensure that it's a functional address. Not something you can just try for 6 months and then easily move on from. And if you decide to move on from this service, will the average person be able to easily migrate that custom domain to a different email provider? (Yes, technically this is possible, but can normal users do it easily? Is it part of the service that Helm provides?)
Part of the point (and the impressive software that has been built here) is that backups happen transparently, and if anything ever happens to the Helm you can get another one and get back up and running by restoring from online backups. It's the same principle: things can happen to your iPhone but you can get up and running with a new one easily.
Data loss is more or less a solved problem. You don't need Google for that. ;-)
On the other hand, even without putting my tin hat on: I get customized ads best on my email contents, WTF?! Everybody can see based on the browser ads what kind of sites I'm surfing to.
> Internet and power outages mean you won't send or receive any email.
Except if you have a charged battery and LTE. ;-) In fact just a charged battery is needed when network is down to read old mails.
> Fire, theft, or hurricanes may destroy it.
Solved problem. Encryption...
I'm a Fastmail user and pretty happy with the service. But, what's the real world benefits of Helm over an encrypted email service, like ProtonMail?
Most cloud-based email services hold email in the clear - we believe this means you don't really own your data. Encrypted email services have challenges around search, access via proprietary protocols and the risks of running highly sensitive operations in client-side javascript.
1 - how many domains can I use? I currently use ~6 with my Fastmail account 2 - can I have multiple users? I recognize that fastmail doesn't let me but at this price point I would want it. It looks like you support that but I'm unsure. 3 - How do you convince my ISP to let me receive traffic on the ports required to run a mail server? (most firewall them on residential accounts) 4 - If I were this committed to my email, why wouldn't I just set it up for free myself? This is actually my biggest question in regards to the product/target market. Are there that many people out there that both care about how email works to this degree and aren't willing to host their own?
The website is heavy on theatrics and bold statements but I feel actually kind of lacking in terms of the meat. There's more than a few parts made it difficult for me to get any information at all (the automatic slide show on the Product page, the 'see the inside' slideshow on the tech page). If I had to guess I'd say this site wasn't tested against Firefox (doesn't seem that any are anymore due to its low market sharE).
On the meat - we have a post coming tomorrow that is the first in a series where we will dive into the technology.
Regarding Firefox issues, please email me at giri@thehelm.com and we'll look into it. We have avid Firefox users on our team and did test it but may have missed some things.
Thanks for your questions and let me know if I can answer any more.
There is no break-even point on this because by default the subscription is more than Fastmail, including their business offering, and even amortizing the device over a decade is still a stretch (what device lasts a decade anymore?). I think what I'm realizing is that even with a gross annual household income over half a mil USD is that I can put a price on email and it's lower than this.
All of that said I do think you've got a neat product. The EC2 solution for tunneling is novel and explains the higher subscription cost. I hope you are successful because I'm curious to see what version 2 would be like service/pricing wise.
I hope you end up seeing this.
I feel like am your target user for this product. I want to be able to isolate the majority of my data away from these large corporations (namely Google), email is probably the hardest one for me to do myself. I really want to use your product.
BUT, and this is a HUGE but, I am a web developer and I have like 15 domain names. Some from old businesses, some for just random stuff. I accept email from all of them and have online accounts tied to many of them. In order for me to use this product, I absolutely need to bring ALL my domain names with me.
In fact, the number of supported domain names is the primary feature I look at when comparing email providers. If it doesn't support the amount that I have, I immediately disregard it, doesn't matter what else they be offering.
So please reconsider the number of domain names. I imagine there are lots of users like me.
Best of luck to you and your team!
It would be best to give ability to create random subdomains, so a user can have a separate addresses for everyone. Then it would be easy to filter out spam on the proxy level. Which is crucial for a server on a mobile phone.
1. e-mail address loss (domain loss, service termination if you don't own the domain, ...)
2. email service loss (server goes down, ...)
3. delivery mechanism compromise (someone gets to read future messages, can be used to hijack online accounts)
4. sending mechanism compromise (partial impersonation, etc.)
5. e-mail archive compromise (someone gets to read old messages)
6. archive loss
You have to think hard about each point:
- how it can happen,
- how would you detect it,
- what it could lead to,
and then prepare for those circumstances via preventive measures, and by having a plan for when it happens.
For example if you register your domains under an account where email that was used for registration comes from one of those domains 3. can easily lead to 1. and you're hosed. You have to have way to restore 2. without access to e-mail addresses that will not work while 2. is happening. You will most probably have no way of detecting 3./4. before bad things start happening. etc. etc.
E-mail is not really something to fuck with, because of how important it is for authentication on the web.
Helm website doesn't work for me, but if you're thinking about an easy way to have a personal email server, and don't have experience, be careful.
Reading the (mouse hijacking) technology page I see:
>Helm is a high-performance server with capabilities normally found in larger, business-class hardware. To accomplish this performance in a smaller (and quieter) form factor, Helm has been engineered to dissipate heat through its aluminum base.
Is that the reason behind the design? Does it mean it's fully passive cooling? Also is it really necessary to have that much cooling in the first place? An email server doesn't need that much juice normally, especially for a small handful of users.
Then get a dirt cheap VPS (less than $15/yr) from lowendbox/lowendtalk and run a OpenVPN tunnel.
So what's the advantage of having this at home instead of an ISP? For one, backup and restore is fast and easy. You can use your NAS that's at home. You may want to have an additional offline backup in case your home network gets completely compromised. A box at home is also more difficult to tamper with. If you're paranoid, put it into a tamper resistant box.
Helm promises to handle this in a way that doesn't let them read transmitted mails. You still have to trust them ultimately, but the stakes are higher.
Also, remember the $99 per year is AFTER shelling out $500 for the device.
I don’t seem to be the target market for this but I wish them well—we need more effort towards re-decentralizing E-mail.
??! No, half is half. Strange response. It's $50/year, and the $50/year charged by Fastmail is already quite steep for email.
For $499 and $99/yr (!!), I don't think you'll convince techies this a worthwhile product either. Maybe the ultra paranoid users. But, in my experience those are also the people who can build their own solution.
Do you know what Segment does? It makes it easy to send data anywhere -> https://segment.com/catalog
I doubt I'm the only one who made this choice. For some of us, content is still the reason we use a web browser; that includes those of us who value privacy and minimising the amount of arbitrary code we run on our devices.
Apps market? Piwik (tracking)? Why would I allow these?
> Helm just works with your home network—no configuration needed. Helm connects securely to a unique gateway, which is assigned a static IP address so Helm is reachable by other mail servers and secure TLS sessions can be established.
A nice approach, but it does sort of chip away at the decentralisation claim that's at the core of their messaging.
> Do you know where your email is?
You show, Google, NSA, etc... but doesn't this service route email through your own servers to get to the box in my home? what makes your servers more secure than Google's at handling the emails? If I have to trust you to route the emails, I might as well just use something like Fastmail that hosts them too.
More crucially, what can I do with the box if I ever stop paying you? or you go under, etc.
I really hope to be proven wrong.
That’s why today ANTISPAM on the net has all but shut down the option of having email outside the big boys or edu.
Somewhat off topic, but another nice project named Helm is the Helm Synth by Matt Tytel, which is open source and sounds pretty freakin good!
1) Is email access provided through the Helm App, SMTP/IMAP, or is there a webmail interface as well? Can you use this device without a smartphone?
2) Which Linux distro is this based on?
3) What file system is used? Is it something like ZFS or BTRFS, which could protect against corruption? Since there seems to be only one drive, I assume there is no RAID-like redundancy included to protect against drive failure?
4) Where are the encrypted backups stored? What is the procedure for recovering them? I expect that the backup recovery keys are also stored offline on the flash drive?
5) How are software updates performed? Are they pushed from a managed system that you control, or does the device itself pull updates automatically on a schedule? How long will you guarantee software updates for? If you stop providing them, or are slow to patch a vulnerability, is there any way for the user to patch the device themselves? Local SSH access perhaps?
Lastly, a comment, please consider not overriding the scroll behaviour on your website. It may look slick when it works, but when it doesn't (as it doesn't on my Firefox), it totally breaks the website. In the case of your technology page, it is super-annoying, since the details I want are at the bottom, and I'm forced to watch the slideshow before I can see them.
Disclaimer, I'm engaged in The Kinguard Project.
Having owned and run my own mail servers myself for some 10 years, I'll tell you something for nothing. Owning your own mail server is not something that comes for free. At least, it wasn't for me.
Unless your product has brought something that's drastically different in terms of software, security and spam maintenance, it's too much of a pain in the ass for a non-technical person to manage. Heck, I'm about as technical as they come. I ran plenty of different kinds of mail servers in those ten years. The effort and inconvenience it caused in that time just wasn't worth it to me any more.
Having to stress out every time I moved, needing to make sure my internet wasn't shut off until I left the premises and making sure it was already on at the new premises before I could move anything, always being the guy on call if my mail server went down.
Then came Cloud and I no longer had to worry about physical hardware ownership and maintenance. I no longer had to worry about if my internet at home was working. The opportunity to move my mail server to a VM, and then hosted Exchange and now Office 365. This has offered me so much mental freedom, I don't think I could go back.
The added stress wasn't worth the extra flexibility and security in my mind. All my email is now handled by Microsoft. Sure it costs me a little money each month, but I've got the peace of mind that their security team is on it and while I'm pretty security savvy, I've got nothing on their security team. In addition, I'm not the guy on call when everything falls to pieces.
I realize that most technical people won't have my perspective on this, but it's definitely something you should think about.
I've been up and running with Helm for the past month on my garrytan.com email domain and it's been zero maintenance.
It's rad, does all of the DNS/SSL/DKIM foo necessary to make your email fully deliverable, includes contacts and calendar sync, is multi-user, multi-domain, etc.
Ansible, yaml config, I think only a single domain.
If you are unreachable, the mail server that is trying to contact you should try again later.
How many times, at what interval and for how long retries happen vary.
Most servers will notify the sender saying that “message delivery failed permanently” if the receiver is unreachable for such a long period of time that the sender server gives up.
So between the resilience to temporary unreachability and the fact that the sender should be notified if delivery times out, I would say that the chance that anything important is lost is very slim.
The bigger problem is the fact that home ISPs often block outbound SMTP, as well as the fact that their IP blocks are often regarded as low trust by others, meaning that you will certainly run into problems sending mail every now and then. I did not yet read the OP link, but am going to, so I don’t know if they offer proxying/forwarding of outbound SMTP.
> In a typical system, the program that composes a message has some method for requesting immediate attention for a new piece of outgoing mail, while mail that cannot be transmitted immediately MUST be queued and periodically retried by the sender.
[ ... ]
> Retries continue until the message is transmitted or the sender gives up; the give-up time generally needs to be at least 4-5 days.
In a lot of cases, users may be paying for a static IP from their ISPs (or even have one for free, by default), or they may be running their own DDNS via a cloud instance already. This does nothing but add a $100/year fee for something that is exceptionally non-reusable and narrowly-scoped.
My first thought in seeing gsreenivas' discussion about the VPN/iptables/EC2 is that the physical box at home makes it feel more secure than an EC2 solution, but I'm not sure that is actually the case.
https://www.bloomberg.com/news/articles/2018-10-17/dusty-pro...
Tag a few high level corp accounts and play the market as deals are closed over gmail accounts.
+17% on Twilio buying Sendmail just this month :)
Are you using a custom distro or one of the off the shelf ones? What webserver (presumably there is one) is running on this? MTA? What're you using for backups? Is this just a ownCloud running under the hood with a tunnel to AWS and small proprietary layer on top?
Along different lines, how to do the backups work? Are they just stored on the device (what happens when its drive dies)? If not where are they stored and how much manual intervention is required. If your company goes under can I use any opensource software to decrypt the backups and access my emails?
Edit: With the list of sources in hand I can answer a lot of the questions I posited. So for others interested:
Distro: Still unknown, but see additional interesting tidbits.
Webserver: Neither nginx or apache are present. If I had to guess its using golang's net code to run any webserver / API that is present
MTA: postfix, dovecot, opendkim, opendmarc, spamassassin (might be more components I missed)
ownCloud: Doesn't appear so
backup software: Duplicity
backup location / process: Unknown
Interesting other tidbits:
OpenVPN is present, and so is ipsec-tools/strongswan. So they might be using either IPSec, OpenVPN or a combination of both for the tunnels. They could just be distribution defaults.
It's running docker, I'm guessing they're using some form of container image sync update system rather than a proper package manager.
It contains a fully developer toolchain, so presumably this is a full distribution rather than a minimized / custom one.
Based on the versions it appears the ARM processor is a QorIQ variant which is an ARM evolution of the PowerPC architecture.
Contains the libatomic libraries, so perhaps this is running on Fedora Atomic as an underlying OS? Would explain the presence of docker and give an idea how they're providing updates.
Appears to have a wifi chip (I couldn't find any information about connectivity on their site). Specifically it seems to be using a Qualcomm ath10k chip.
We will be publishing more details to answer your questions in depth in a series of coming posts. I'll give you some quick answers right now.
We use Yocto to spin our own Linux build. Key projects we utilize: OpenLDAP Postfix Dovecot Darwin Calendar and Contacts Certbot OpenDMARC OpenDKIM OpenSSL Python SPF Policy Sieve SpamAssassin Duplicity StrongSwan Docker
We're using duplicity for backups. So you can use it to decrypt backups as you will have the keys as well. Backups are stored on a service we run using S3 and will always be accessible for the user even if something happens to the company.
The price point is also a bit high for a Canadian Customer, so I like the idea but a bit too pricey for North of the boarder after currency exchange.
But I would love a small server box that can be simply stacked to increase capacity for home labs and desktop k8s clusters without having to buy and configure a switch and complicated power delivery.
I wanna get away from "free" email, but I think it requires a more full blown solution, something which offers a client with the polish of gmail.com along with it's excellent spam detection/protection, that can be self hosted on any random computer/server (using docker, or similar) that is very nearly plug and play.
Unfortunately, such a project would need to be OSS, with a consulting-type income structure, but the big companies that would be willing to pay for such a thing all use O365, and would never be willing to try something not nearly as proven.
Sorry, I respectfully disagree. We shouldn't fix email, we should throw it away and replace it.
It is almost impossible to have secure email that can't be eavesdropped, even with PGP. Normal people just don't get the need for security and can't bother the hassle of encrypting their email.
Also, from an usability perspective, email was a solution for an age without mobile computing.
What we need is something like Signal: instant messaging with privacy built in by default.
And neither of us have to change apps or behavior.
This is pretty good.
Most providers will blacklist anyone who isn't one of them. So I front my home email server with a big account to relay in and out of. It kinda sucks, but all my stuff just works.
So I can happily fire up my Macintosh II, load up Outlook 98 and read email.
I use Office 365 to front my domain, I think it's like $12 a month for the corporate version so I can have it front domain emails. And that means I get office for all my devices so I'm not the one having to deal with having old versions of stuff.
1) I’d need to feel secure my email would actually deliver correctly. Zack Whittaker on Twitter [1] mentioned that the CEO’s email wound up in his Gmail spam folder. This would be utterly unacceptable for me, even though I don’t frequently email new people.
2) The single domain per server totally makes this DOA for me. I have multiple domains with separate, non-aliased mailboxes, controlled via legacy GApps accounts. It winds up being a security advantage because I use different accounts/domains for different services and that means that the likelihood of me being severely hacked is lower as a result. But beyond that, a single domain designation seems off for this type of product. The people willing to spend $500 on this kind of hardware are the people who have multiple domains.
3) I worry about the long term future of a startup like this. If they go out of business, not only is my hardware now worthless, I now have to migrate my inboxes to Fastmail or GSuite or something else, or face configuring my own local mail server, which is what I was trying to avoid to begin with. And in my case, that would also potentially mean giving up grandfathered GApps accounts with 50 users and custom domain support.
I wish Helm luck and we need disruptive email startups and better turnkey hosting solutions, but I’m not sure this is the right solution at the moment.
[1]: https://twitter.com/zackwhittaker/status/1052619938349899776...
The founder of daplie is moving on to found ppl, which is also similar to helm, but without email being the primary focus. I started helping with the email feature before getting a new job and not having any spare time for the project. This is a better solution to email than we had come up with.
I still wonder, does one successful kickstarter mean there's enough market demand for these products to succeed? I just can't see personal servers at home becoming anywhere near user friendly enough for the general population. Go try a digital ocean 1-click install 3 times in a row. The results are different every time. I see that same problem happening with these personal servers.
Nope.
And i also do not want to have my email gateway at home. I do move, i do like to shutdown hardware, i like to travel and might not be able to access my hardware.
There are good small and secure email providers out there which costs money. I would even prever a managed vps server somewhere.
However, I recognize the value of having my email served and saved on premises. If I could have a fairly secure and automated backup from my local files, that’s great.
If I can also use a self hosted webmail interface then I want that too.
I agree that $500 is a lot, but it’s not an absurdly large amount.
* "Keys only you have access to" -> "Only you have the keys"
* "Room for growth" -> "Room to grow"
* "Gets better over time" -> "Always improving [etc.]"
I mention all the above because I really like what I see here and I'm looking for room in my budget after I post this comment :)
Good luck!
Your technology page mentions that you provide an mx gateway (presumably for inbound email for home networks that don't usually have a static IP address). You also mention that emails forwarded to the helm server via your gateway are encrypted end-to-end and your gateway cannot read the contents of that email.
I am unable to understand how this happens. TLS is not end-to-end -- since the sending mail server will establish a TLS connection with your gateway it means that you necessarily have to decrypt the incoming email before forwarding it to the helm server.
Can you explain to me how I am wrong here?
If I'm somewhere and my internet goes down, I will lose access to everything. And as we all know, stuff will go down at some point (probably at the most inconvenient time).
And secondly, if residential internet cuts off - would I lose emails sent to me?
> Internet service providers normally don’t provide their customers with networking capabilities that are required to run an email server. In most cases, upgrading to an expensive business class internet service is needed. The subscription service that is part of the Helm service handles this for you without you having to upgrade your ISP.
> We handle all fees associated with domain registration and renewal when you create a new domain for your Helm. In addition, we also provide storage for offsite encrypted backups and include access to new features, service and security patches.
I also can't imagine that having a hardware device in-home actually reduces the unit costs of that storage, so if this were an on-line service priced even cheaper, I'd love to pay for it.
My concerns echo those of commenter 'andr'.
Why is this not simply a download?
Do you have stats on e-mail deliverability given that you're suggesting I send all my e-mail through a random EC2 EIP? (Is it actually an EIP, or is it just default EC2 egress?)
Most people who care enough about security understand what this device does, along with actually buying one of these, will most likely already have the technical skills to setup something similar themselves.
That being said, once it supports multiple domains/domain aliases and webmail, I'll probably be picking one up, if not for anything else then for fun.
Is it open to users to be able to run their own docker images on it ?
It could be interesting to see whether MTAs evolve away from that design feature/constraint. Email seems ever-more centralized. Then again, it's a great robustness feature with a very small downside if any, so hopefully it's just my paranoia.
This sounds like Helm becomes the email gateway. Sure, an email server might be running on the device, but emails will be routed through Helm the company. Am I missing something?
Not sure about the Helm but i havn't found any source code nor any description on which open source components they use. But i for one would not trust my personal information to a closed box.
Disclaimer, i'm engaged in the Kinguard project.
Best solution is to have your own AS number and IP ranges and your own hosting.
1) Wasn't the whole point of email moving to the cloud to enable access on any device anywhere? If I move my email to Helm can I still access it on the go?
2) Assuming I can access it on the go. I'd need pretty fast upload speeds right? I live in Australia, and our internet is god awful.
The privacy oriented techie doesn't trust Helm any more than they trust Google... so they're going to do everything themselves from scratch anyway, so what does Helm do for them?
PS: For some reason, people are willing to pay more and see more value on "physical things" than virtual solutions. Anyone knows the psychology behind this behaviour?
the NUC form factor would be great.
The only thing I'd really want is to have option to not pay for annual $99 fee, and instead have everything configurable so that I can point tunnel it to my own VPS/VPN or I can use it at the office, where the business ISP account allows me to host my own email server.
What honestly makes this more appealing than $50 per year for Fastmail?
Unix, vim, emacs, lisp, the shell, and even the web itself is all old tech at this point. Old doesn't have to mean bad. It's tech that's stood the test of time.
And yes, you could definitely do this on a raspberry pi. That's what we used to prototype. It's not great for a long last, durable and secure platform though.
All that is managed by the SMTP servers and the numbers change, but normally just losing internet connection or power for some hours doesnt make emails dissapear. By design.
See under the question: What happens to my email if my power or Internet service goes out?
Also the yearly fee seems high compared to a lot of other stuff but still reasonable, especially as you start adding more services.
Cool idea though.
As an aside, any suggestions on easy to install/configure/update mail in a box + letsencrypt options? Thinking of throwing something on an rPI for similar chores.
It runs on a cheap SBC and you can use a 15$/year VPS as a relay.
RISC-V is still new and expensive for companies like this