Only half the points are valid. SSL is a selling point, because it takes a lot of work to setup completely. Lots of websites (including high-profile ones like Outlook.com) have mixed content errors at one place or another, or appear to but don't fully support SSL. The fact that they "used to" use it as a selling point says enough too. SSL signin should not be enforced. HTTP should give a big warning, but SSL is not f…
Evernote doesn't really care about security
31–40 of 64 posts
Re: Evernote doesn't really care about security
#32What're the alternatives to Evernote? e.g. decent document tagging, excellent search and preferably OCR.
Re: Evernote doesn't really care about security
#33Is there a way to download your Evernote data? Not to say that I find this an opportunity to bash Evernote, but I am terribly disappointed that a service that advertised you to keep really personal stuff, even your tax info on their servers just got hacked. I think I'm going back to creating .txt files on my desktop which no one else has access to (physcially and programatically), which despite having no encryption o…
Re: Evernote doesn't really care about security
#34"If you encrypt text within a note, we derive a 64-bit RC2 key from your passphrase and use this to encrypt the text. This is the longest symmetric key length permitted by US Export restrictions without going through a complex process to gain export approval." Is this still true? Weren't US cryptography export restrictions relaxed in 2000? (See e.g. http://www.rsa.com/rsalabs/node.asp?id=2327 )
If all you are doing is encrypting data with a standard algorithm, it takes less than 30 minutes to fill out the paperwork to get an encryption registration number (ERN). Total turnaround time when I've done it has been about two weeks.
There are some exceptions. If you are trying to export cryptanalytic software or doing something non-standard, you may have delays.
Re: Evernote doesn't really care about security
#35Is there a way to download your Evernote data? Not to say that I find this an opportunity to bash Evernote, but I am terribly disappointed that a service that advertised you to keep really personal stuff, even your tax info on their servers just got hacked. I think I'm going back to creating .txt files on my desktop which no one else has access to (physcially and programatically), which despite having no encryption o…
The desktop client has a "Export Notes" function that will export to HTML or their custom format. I use this to make a local backup occasionally.
Re: Evernote doesn't really care about security
#36Mark, it would be helpful if you would disclose if you are a paying customer or not, and if not if having additional security options would convert you into a paying customer. The reasoning is pretty simple, people want security but they don't want to pay for it. And while we can debate the argument as to whether or not security is part of a MVP or not, I would not be offended if there were additional security capabi…
Re: Evernote doesn't really care about security
#37Only half the points are valid. SSL is a selling point, because it takes a lot of work to setup completely. Lots of websites (including high-profile ones like Outlook.com) have mixed content errors at one place or another, or appear to but don't fully support SSL. The fact that they "used to" use it as a selling point says enough too. SSL signin should not be enforced. HTTP should give a big warning, but SSL is not f…
1. force it on your servers
2. only include content from your servers
It becomes almost impossible to mix insecure content at this point.
Re: Evernote doesn't really care about security
#38Mark, it would be helpful if you would disclose if you are a paying customer or not, and if not if having additional security options would convert you into a paying customer. The reasoning is pretty simple, people want security but they don't want to pay for it. And while we can debate the argument as to whether or not security is part of a MVP or not, I would not be offended if there were additional security capabi…
Re: Evernote doesn't really care about security
#39Mark, it would be helpful if you would disclose if you are a paying customer or not, and if not if having additional security options would convert you into a paying customer. The reasoning is pretty simple, people want security but they don't want to pay for it. And while we can debate the argument as to whether or not security is part of a MVP or not, I would not be offended if there were additional security capabi…
Re: Evernote doesn't really care about security
#40Mark, it would be helpful if you would disclose if you are a paying customer or not, and if not if having additional security options would convert you into a paying customer. The reasoning is pretty simple, people want security but they don't want to pay for it. And while we can debate the argument as to whether or not security is part of a MVP or not, I would not be offended if there were additional security capabi…
I think you're, rather cynical, reasoning falls flat. This would not be a good policy for a company to adopt. If I was evaluating software and saw such a policy, it would bring a lot of uneasy feelings, even regarding the supposed security of the paid version. This side steps the bad publicity and general ill-feelings the community at large would have about your service. I don't think it is strategically a good choic…
"If I was evaluating software and saw such a policy, it would bring a lot of uneasy feelings, even regarding the supposed security of the paid version."
What if it was explicit? What if Evernote said, "Since it would cause us to lose money if we spent time on both more sophisticated security in the free product. Its basically secure against random threats but dedicated people will be able to break into it. If you want a truly secure product you should sign up for the paid product, part of that fee goes to paying the salaries of the security team we have on staff who are keeping it that way."
We also need to be clear what we mean by "security" here, there is "security" as in we make sure if someone breaks in they cannot easily get your password (they seem to have done that with salted passwords), and their is security as in "Even our operations staff can't get you access to your files if you lose your access token." level of security which takes a lot more work.
I'll admit I was pretty put off by Mark's assertion that Evernote doesn't care about security, his basis for that are three claims, that 2 factor authentication is late, that SSL isn't forced on, and that 64 bit RC2 is used in the free product. What is the purpose of the free product anyway? Is it to prove their security? I don't think it is, I think it is to give you a way to test drive what their product does without risking any money.
Anyway, someone broke in and got access to hashed and salted passwords and Evernote reset those. LinkedIn had the same issue, some Facebook apps grabbed similar data, Google has hosted malware in their App Store which tried to install banking trojans on your phone.
I am not persuaded by the assertion that "Evernote doesn't care about security" any more than "Google doesn't care about security" (and I happen to know they care very deeply and still get compromised now and then).
I defended Evernote because I felt Mark was unfairly maligning them and their CEO. I would be more sympathetic if he was a paying customer, and less sympathetic if he only has a free account.