The following blog post is also being sent to all Evernote users as an email communication. Evernote’s Operations & Security team has discovered and blocked suspicious activity on the Evernote network that appears to have been a coordinated attempt to access secure areas of the Evernote Service. As a precaution to protect your data, we have decided to implement a password reset. Please read below for details and inst…
I haven't received such an email, wonder why. Anyway Evernotes android client wasn't very good and it was far too slow to start. And now the have been hacked. Anybody know a good alternative?
Evernote hacked
71–80 of 220 posts
Re: Evernote hacked
#72Earlier quoted context omitted.
People are going to argue with you semantically, but you'll all generally be in agreement (except 3DES is a block cipher, not a hash function).
3DES is a black cipher but block ciphers can be used for hashing. 3DES in particular was used on UNIX/Linux based systems quite extensively. http://www.freebsd.org/doc/handbook/crypt.html See this: http://en.wikipedia.org/wiki/One-way_compression_function#Co...
Re: Evernote hacked
#73Re: Evernote hacked
#74Earlier quoted context omitted.
Yeah, Evernote really should have been zero-knowledge end-to-end encrypted. Recently https://crypton.io/ was released and my hope is that lots of new SaaS offerings will use it and that this will in the end force even the big names (Dropbox, 37signals, etc) to adopt real security.
> to adopt real security. Won't happen until it's perceived that the lack of security is costing them money.
Re: Evernote hacked
#75I don't understand why they don't offer encryption.
Encryption on /what/? Point to point or content encryption? Also if your password has been compromised and that same password is used to encrypt your data then what exactly would encryption do?
Re: Evernote hacked
#76http://news.ycombinator.com/item?id=5154502
While there are (so far) no such comments about Evernote releasing this stuff on a Saturday morning. I think security breaches are just discovered at inconvenient times.
Re: Evernote hacked
#77The following blog post is also being sent to all Evernote users as an email communication. Evernote’s Operations & Security team has discovered and blocked suspicious activity on the Evernote network that appears to have been a coordinated attempt to access secure areas of the Evernote Service. As a precaution to protect your data, we have decided to implement a password reset. Please read below for details and inst…
> Please create a new password by signing into your account on evernote.com( https://www.evernote.com/Login.action ). and > Never click on ‘reset password’ requests in emails Is sure to confuse a lot of people.
Re: Evernote hacked
#78That's why I don't use any fancy services for my notes, which usually contains sensitive data. I simply use Notational Velocity which encrypts my notes and stores it locally. It does provide a synchronization option with SimpleNote but they can't even be bothered with using SSL.
Re: Evernote hacked
#79(FWIW I didn't get the email so I was simply locked out and used their "forget password" form instead of trying to log in, which may have a different reset process).
Re: Evernote hacked
#80i guess they're counting on compromised passwords not being used individually to create new ones?