Live data from Hacker News

Evernote hacked

blog.evernote.com

71–80 of 220 posts

Re: Evernote hacked

#71
post #37

The following blog post is also being sent to all Evernote users as an email communication. Evernote’s Operations & Security team has discovered and blocked suspicious activity on the Evernote network that appears to have been a coordinated attempt to access secure areas of the Evernote Service. As a precaution to protect your data, we have decided to implement a password reset. Please read below for details and inst…

I haven't received such an email, wonder why. Anyway Evernotes android client wasn't very good and it was far too slow to start. And now the have been hacked. Anybody know a good alternative?

FWIW, but this is what I use MS SkyDrive and DropBox for. Setup your notebook txt or rtf (or odt or whatever) files and get all the same sync. Save a webpage using your browser and get much of the web clipping functionality. Not exactly the same, but clients on all the platforms and also some functionality that Evernote doesn't have.

Re: Evernote hacked

#72

Earlier quoted context omitted.

People are going to argue with you semantically, but you'll all generally be in agreement (except 3DES is a block cipher, not a hash function).

3DES is a black cipher but block ciphers can be used for hashing. 3DES in particular was used on UNIX/Linux based systems quite extensively. http://www.freebsd.org/doc/handbook/crypt.html See this: http://en.wikipedia.org/wiki/One-way_compression_function#Co...

All cryptography is fundamentally transposition and substitution of "symbols" (across a combinatoric space, an "alphabet"). Hash functions can be made from block ciphers, but really, symmetric and asymmetric crypto is just moving around some letters, but in interesting, deterministic ways.

Re: Evernote hacked

#73
I find evernote tremendously helpful and I pay the $5 per month for a premium service, REGARDLESS, a google of https://www.google.com/search?q=evernote+two+step+authentica... says little good about how Evernote respects me or their many many other customers whom have repeatedly asked for two factor authentication.

Re: Evernote hacked

#74

Earlier quoted context omitted.

Yeah, Evernote really should have been zero-knowledge end-to-end encrypted. Recently https://crypton.io/ was released and my hope is that lots of new SaaS offerings will use it and that this will in the end force even the big names (Dropbox, 37signals, etc) to adopt real security.

> to adopt real security. Won't happen until it's perceived that the lack of security is costing them money.

Personally, I've complained to them that as a premium user I should be given the option to fully encrypt a notebook (zero-knowledge style, so only I have the keys). This prohibits all the social network-type sharing stuff though, so they are uninterested in doing this (same with Dropbox). It's a fundamental issue, but I hate that these companies think they should put "sharing" ahead of "security".

Re: Evernote hacked

#75
post #4

I don't understand why they don't offer encryption.

Encryption on /what/? Point to point or content encryption? Also if your password has been compromised and that same password is used to encrypt your data then what exactly would encryption do?

Data encryption with a private key that the user holds. Evernote, like Dropbox, etc. have your crypto keys, and thus will always be subject to hacking and such. If I, and only I, had the keys it would be up to me to keep them safe, and my data would not succumb to a hack of their database, etc.

Re: Evernote hacked

#76
I note that when Twitter released their breach notice on a Friday afternoon there were comments accusing them of trying to "bury" the news:

http://news.ycombinator.com/item?id=5154502

While there are (so far) no such comments about Evernote releasing this stuff on a Saturday morning. I think security breaches are just discovered at inconvenient times.

Re: Evernote hacked

#77

The following blog post is also being sent to all Evernote users as an email communication. Evernote’s Operations & Security team has discovered and blocked suspicious activity on the Evernote network that appears to have been a coordinated attempt to access secure areas of the Evernote Service. As a precaution to protect your data, we have decided to implement a password reset. Please read below for details and inst…

> Please create a new password by signing into your account on evernote.com( https://www.evernote.com/Login.action ). and > Never click on ‘reset password’ requests in emails Is sure to confuse a lot of people.

Huh. I just went to their site to reset my password, and instead of logging in I just used the standard way which sent me and email. Now I'm not so sure I should have trusted that email. Seems like they should have just emailed everyone with new passwords immediately.

Re: Evernote hacked

#78

That's why I don't use any fancy services for my notes, which usually contains sensitive data. I simply use Notational Velocity which encrypts my notes and stores it locally. It does provide a synchronization option with SimpleNote but they can't even be bothered with using SSL.

amen to that. I stopped using evernote awhile ago because of this and once I started using NV I never looked back. Clearly they don't take security seriously enough, which is a shame for those who don't know any better.

Re: Evernote hacked

#79
I managed to reset my password to the same that it was before. I changed it again right away of course, but there should definitely be some protection against that.

(FWIW I didn't get the email so I was simply locked out and used their "forget password" form instead of trying to log in, which may have a different reset process).

Re: Evernote hacked

#80
i didn't get the email, and my original password still works, it just took me directly to change password screen.

i guess they're counting on compromised passwords not being used individually to create new ones?

Post reply on HN