Live data from Hacker News

Evernote doesn't really care about security

markpercival.us

11–20 of 64 posts

Re: Evernote doesn't really care about security

#11
post #9

Only half the points are valid. SSL is a selling point, because it takes a lot of work to setup completely. Lots of websites (including high-profile ones like Outlook.com) have mixed content errors at one place or another, or appear to but don't fully support SSL. The fact that they "used to" use it as a selling point says enough too. SSL signin should not be enforced. HTTP should give a big warning, but SSL is not f…

Are there clients which support evernote but would not support SSL?

Re: Evernote doesn't really care about security

#13
post #5

The RC2 thing from the disclosure is really, really weird. It makes Evernote the only app built in the last 10 years that I am aware of to build on RC2. I wonder whether it's a mistake, and they're actually using RC4 with truncated keys or something.

Confirmed here too. https://support.evernote.com/link/portal/16051/16058/Article...

"For Evernote's consumer product, the current encryption algorithms are chosen more for exportability under the Commerce Department rather than strength, since our software permits the encryption of arbitrary user data with no escrow."

I guess Evernote's been around for a while, but wasn't it way back in 2010 that the BIS allowed simple self service registration and annual self classification of almost all "mass market" use of crypto?

http://www.bis.doc.gov/encryption/summary.htm

Re: Evernote doesn't really care about security

#14
post #10

> Give it a shot. Send someone a link to the non-SSL sign in and it won’t flip them over to SSL. It will also accept your credentials via non-SSL POST. So fire up SSLStrip and head down to your local coffee shop. If you are in a position to execute a MITM, it doesn't matter whether they flip people to HTTPS or not. If the site forced HTTPS you could still rewrite the redirect and proxy the HTTPS to HTTP (the secure c…

Yeah, this is an entirely valid criticism. It was more of a nitpicky point that they weren't flipping to HTTPS automatically, but from a practical standpoint it's no more secure if they did since they lack HSTS.

Struck it from the post.

Re: Evernote doesn't really care about security

#17
post #15

Most consumers want convenience first, security second. Evernote just targets the mass market.

For the data I store in Evernote I'm fine with this.

One would think there'd be proper competition because one of the major motivators is going paperless... it's kind of odd that in 2013 there still aren't a lot of easy to use solutions that can store sensitive documents (bills, tax documents etc) that require a great level of privacy and security.

Re: Evernote doesn't really care about security

#18
post #17

Earlier quoted context omitted.

For the data I store in Evernote I'm fine with this.

One would think there'd be proper competition because one of the major motivators is going paperless... it's kind of odd that in 2013 there still aren't a lot of easy to use solutions that can store sensitive documents (bills, tax documents etc) that require a great level of privacy and security.

I use 1Password with dropbox sync for secure notes.

Re: Evernote doesn't really care about security

#19
post #9

Only half the points are valid. SSL is a selling point, because it takes a lot of work to setup completely. Lots of websites (including high-profile ones like Outlook.com) have mixed content errors at one place or another, or appear to but don't fully support SSL. The fact that they "used to" use it as a selling point says enough too. SSL signin should not be enforced. HTTP should give a big warning, but SSL is not f…

What wouldn't support SSL? I can't think of a single product.

Re: Evernote doesn't really care about security

#20
post #13

Earlier quoted context omitted.

Confirmed here too. https://support.evernote.com/link/portal/16051/16058/Article...

"For Evernote's consumer product, the current encryption algorithms are chosen more for exportability under the Commerce Department rather than strength, since our software permits the encryption of arbitrary user data with no escrow." I guess Evernote's been around for a while, but wasn't it way back in 2010 that the BIS allowed simple self service registration and annual self classification of almost all "mass mark…

Addressing US regs doesn't necessarily mean you are compliant with assorted international regs.

Crypto, export, and service availability can be tricky things.

Post reply on HN