Evernote doesn't really care about security
markpercival.us
Evernote doesn't really care about security
1–10 of 64 posts
Re: Evernote doesn't really care about security
#2Re: Evernote doesn't really care about security
#3Re: Evernote doesn't really care about security
#4I thought SSL was enabled on Evernote for all customers now? Maybe its time to consider not using Evernote.
Re: Evernote doesn't really care about security
#5Re: Evernote doesn't really care about security
#6Re: Evernote doesn't really care about security
#7Re: Evernote doesn't really care about security
#8The RC2 thing from the disclosure is really, really weird. It makes Evernote the only app built in the last 10 years that I am aware of to build on RC2. I wonder whether it's a mistake, and they're actually using RC4 with truncated keys or something.
https://support.evernote.com/link/portal/16051/16058/Article...
Re: Evernote doesn't really care about security
#9SSL signin should not be enforced. HTTP should give a big warning, but SSL is not fully supported in all clients.
Re: Evernote doesn't really care about security
#10If you are in a position to execute a MITM, it doesn't matter whether they flip people to HTTPS or not. If the site forced HTTPS you could still rewrite the redirect and proxy the HTTPS to HTTP (the secure connection being between your proxy server and Evernote's). Only strict transport security would solve this, if the browser supports it and the user has accessed evernote before.