The following blog post is also being sent to all Evernote users as an email communication. Evernote’s Operations & Security team has discovered and blocked suspicious activity on the Evernote network that appears to have been a coordinated attempt to access secure areas of the Evernote Service. As a precaution to protect your data, we have decided to implement a password reset. Please read below for details and inst…
> "Never use the same password on multiple sites or services" As long as we're stuck with passwords, this is the single best practice for protecting your accounts. Services WILL be compromised, again and again, and attackers have made a pattern of compromising a poorly-secured service as a side channel to get credentials for a more critical service. Props to Evernote - it seems like they've done the right thing with…
This would be easier if non-critical password cookies didn't expire. Why does my Slashdot or HN password cookie need to expire? Answer: it doesn't, but the fact that it does means that I have to write down dozens of different passwords... and carry them with me if I expect to use those services on a mobile basis.
Life would be a lot easier if password cookies didn't expire (or even if - gasp! - the user was given a choice in the matter). Whenever I'd find myself locked out due to the use of a different browser or platform, I'd request an email reset and keep track of the resulting new password only long enough to update all of my browsers.
If I try to use this strategy now -- and I have -- I'll spend an hour every other day doing nothing but resetting password cookies that didn't need to expire in the first place.
Christ, passwords are stupid. Somebody fix this shit.
/rant