Live data from Hacker News

Evernote hacked

blog.evernote.com

81–90 of 220 posts

Re: Evernote hacked

#81

That's why I don't use any fancy services for my notes, which usually contains sensitive data. I simply use Notational Velocity which encrypts my notes and stores it locally. It does provide a synchronization option with SimpleNote but they can't even be bothered with using SSL.

amen to that. I stopped using evernote awhile ago because of this and once I started using NV I never looked back. Clearly they don't take security seriously enough, which is a shame for those who don't know any better.

NV?

Re: Evernote hacked

#82
post #77

Earlier quoted context omitted.

> Please create a new password by signing into your account on evernote.com( https://www.evernote.com/Login.action ). and > Never click on ‘reset password’ requests in emails Is sure to confuse a lot of people.

Huh. I just went to their site to reset my password, and instead of logging in I just used the standard way which sent me and email. Now I'm not so sure I should have trusted that email. Seems like they should have just emailed everyone with new passwords immediately.

I've yet to receive an email so I just went to their site.

Upon logging in with my (presumably) exposed password, I was given the option to enter a new password immediately. Their password reset should fire off an email instantly, not using a batch delivery process, with a confirmation link that then logs me into their system with a one-time key, forcing me to change my password only then.

Yes, that is marginally more complicated, but it's miles more secure. They just gave a free password reset form to whoever is sitting on their database dump for any trivial dictionary passwords they're able to bruteforce. Not doing a mass password reset would have had the same effect.

FWIW, I've also yet to receive any confirmation email that my password has been reset, another potential security problem.

Re: Evernote hacked

#83
post #43

Earlier quoted context omitted.

Your average user has no idea what a hash nor a salt is. There's really no reason for them to include their hashing algorithm in an email like that.

Technology-savvy users want to be informed and assured as well. Why would they not include it? Situations like these specifically call for not leaving things up to the users' imagination. The recent Facebook incident (well, one of them) created a big scare. Better to control the narrative, before others decide to tell their version of the story.

Also the email doesn't talk about the time-frame: when exactly did Evernote discover this activity and how long might they have been compromised for.

Re: Evernote hacked

#85

The following blog post is also being sent to all Evernote users as an email communication. Evernote’s Operations & Security team has discovered and blocked suspicious activity on the Evernote network that appears to have been a coordinated attempt to access secure areas of the Evernote Service. As a precaution to protect your data, we have decided to implement a password reset. Please read below for details and inst…

I never received this email.

I only found out about the hack because my evernote client kept on bugging me saying my password had changed.

Curious as to why I found out the cause via Twitter.

Email is way too slow for these sorts of things

Re: Evernote hacked

#86
I didn't get an email (yet) so I visited the Evernote Forum. I was a bit surprised to see that I had to sign in with the same username and password of my Evernote account. It's convenient, but I prefer seperate accounts, especially since they're using third-party forum software.

Re: Evernote hacked

#87
> we have found no evidence that any of the content you store in Evernote was accessed

This depends on how hard they looked - do people believe content wasn't accessed?

Is it fair to ask them for a technical post about why they don't think content was hacked? I'd love to know how they separate auth from content, and how they ensure that a hacked auth node can't view notes

Re: Evernote hacked

#88
post #60

Earlier quoted context omitted.

Curious, if the attacker knows what the encryption algorithm is, does it help them at all in breaking it? I.e., does it potentially delay breaking it by not revealing it?

No, it's usually known by the format, or even stored together with the password Example: crypt stored the password in the format: $id$salt$encrypted

But this is why we do one or both things: strip obvious things from hashed password and store them separately or add a trivial character reshuffling algorithm. The point is that hacker would not only have to steal your hashed passwords, but also steal and understand your code. Makes it more complicated.

Re: Evernote hacked

#89
post #8

Service currently unavailable. Here is their latest tweet: Important: Evernote just implemented a service-wide password reset. Please read our post for details and instructions Said post is unavailable by the look of it. Can someone post a paste of the blog post in here?

They aren't down (anymore), but in case you are still unable to read it:

-----

Evernote's Operations & Security team has discovered and blocked suspicious activity on the Evernote network that appears to have been a coordinated attempt to access secure areas of the Evernote Service.

As a precaution to protect your data, we have decided to implement a password reset. Please read below for details and instructions.

In our security investigation, we have found no evidence that any of the content you store in Evernote was accessed, changed or lost. We also have no evidence that any payment information for Evernote Premium or Evernote Business customers was accessed.

The investigation has shown, however, that the individual(s) responsible were able to gain access to Evernote user information, which includes usernames, email addresses associated with Evernote accounts and encrypted passwords. Even though this information was accessed, the passwords stored by Evernote are protected by one-way encryption. (In technical terms, they are hashed and salted.)

While our password encryption measures are robust, we are taking additional steps to ensure that your personal data remains secure. This means that, in an abundance of caution, we are requiring all users to reset their Evernote account passwords. Please create a new password by signing into your account on evernote.com.

After signing in, you will be prompted to enter your new password. Once you have reset your password on evernote.com, you will need to enter this new password in other Evernote apps that you use. We are also releasing updates to several of our apps to make the password change process easier, so please check for updates over the next several hours.

As recent events with other large services have demonstrated, this type of activity is becoming more common. We take our responsibility to keep your data safe very seriously, and we're constantly enhancing the security of our service infrastructure to protect Evernote and your content.

There are also several important steps that you can take to ensure that your data on any site, including Evernote, is secure:

Avoid using simple passwords based on dictionary words Never use the same password on multiple sites or services Never click on 'reset password' requests in emails — instead go directly to the service Thank you for taking the time to read this. We apologize for the annoyance of having to change your password, but, ultimately, we believe this simple step will result in a more secure Evernote experience. If you have any questions, please do not hesitate to contact Evernote Support.

The Evernote team

Re: Evernote hacked

#90

The following blog post is also being sent to all Evernote users as an email communication. Evernote’s Operations & Security team has discovered and blocked suspicious activity on the Evernote network that appears to have been a coordinated attempt to access secure areas of the Evernote Service. As a precaution to protect your data, we have decided to implement a password reset. Please read below for details and inst…

> Please create a new password by signing into your account on evernote.com( https://www.evernote.com/Login.action ). and > Never click on ‘reset password’ requests in emails Is sure to confuse a lot of people.

I didn't even get an e-mail, not even as of now March 2 14:03 AST, I saw this on HN first.
Post reply on HN