Only half the points are valid. SSL is a selling point, because it takes a lot of work to setup completely. Lots of websites (including high-profile ones like Outlook.com) have mixed content errors at one place or another, or appear to but don't fully support SSL. The fact that they "used to" use it as a selling point says enough too. SSL signin should not be enforced. HTTP should give a big warning, but SSL is not f…
Evernote doesn't really care about security
11–20 of 64 posts
Re: Evernote doesn't really care about security
#12Re: Evernote doesn't really care about security
#13The RC2 thing from the disclosure is really, really weird. It makes Evernote the only app built in the last 10 years that I am aware of to build on RC2. I wonder whether it's a mistake, and they're actually using RC4 with truncated keys or something.
Confirmed here too. https://support.evernote.com/link/portal/16051/16058/Article...
I guess Evernote's been around for a while, but wasn't it way back in 2010 that the BIS allowed simple self service registration and annual self classification of almost all "mass market" use of crypto?
Re: Evernote doesn't really care about security
#14> Give it a shot. Send someone a link to the non-SSL sign in and it won’t flip them over to SSL. It will also accept your credentials via non-SSL POST. So fire up SSLStrip and head down to your local coffee shop. If you are in a position to execute a MITM, it doesn't matter whether they flip people to HTTPS or not. If the site forced HTTPS you could still rewrite the redirect and proxy the HTTPS to HTTP (the secure c…
Struck it from the post.
Re: Evernote doesn't really care about security
#15Re: Evernote doesn't really care about security
#16Most consumers want convenience first, security second. Evernote just targets the mass market.
Re: Evernote doesn't really care about security
#17Most consumers want convenience first, security second. Evernote just targets the mass market.
For the data I store in Evernote I'm fine with this.
Re: Evernote doesn't really care about security
#18Earlier quoted context omitted.
For the data I store in Evernote I'm fine with this.
One would think there'd be proper competition because one of the major motivators is going paperless... it's kind of odd that in 2013 there still aren't a lot of easy to use solutions that can store sensitive documents (bills, tax documents etc) that require a great level of privacy and security.
Re: Evernote doesn't really care about security
#19Only half the points are valid. SSL is a selling point, because it takes a lot of work to setup completely. Lots of websites (including high-profile ones like Outlook.com) have mixed content errors at one place or another, or appear to but don't fully support SSL. The fact that they "used to" use it as a selling point says enough too. SSL signin should not be enforced. HTTP should give a big warning, but SSL is not f…
Re: Evernote doesn't really care about security
#20Earlier quoted context omitted.
Confirmed here too. https://support.evernote.com/link/portal/16051/16058/Article...
"For Evernote's consumer product, the current encryption algorithms are chosen more for exportability under the Commerce Department rather than strength, since our software permits the encryption of arbitrary user data with no escrow." I guess Evernote's been around for a while, but wasn't it way back in 2010 that the BIS allowed simple self service registration and annual self classification of almost all "mass mark…
Crypto, export, and service availability can be tricky things.