Live data from Hacker News

Evernote doesn't really care about security

markpercival.us

31–40 of 64 posts

Re: Evernote doesn't really care about security

#31
post #9

Only half the points are valid. SSL is a selling point, because it takes a lot of work to setup completely. Lots of websites (including high-profile ones like Outlook.com) have mixed content errors at one place or another, or appear to but don't fully support SSL. The fact that they "used to" use it as a selling point says enough too. SSL signin should not be enforced. HTTP should give a big warning, but SSL is not f…

No. I consider properly setting up SSL to be a duty of care for the website owner. Your argument could apply to storing passwords in plaintext because "hashing is hard," or doctors refusing to wash their hands between patients because "it takes too much time" -- it's just not a corner that professionals should cut anymore.

Re: Evernote doesn't really care about security

#32

What're the alternatives to Evernote? e.g. decent document tagging, excellent search and preferably OCR.

I'm pretty happy with org-mode, albeit minus the "OCR" bit. (Most of my org-mode docs tend to be written in org and stay there, there's less of this "pulling documents from outside into it" business than evernote)

Re: Evernote doesn't really care about security

#33
post #27

Is there a way to download your Evernote data? Not to say that I find this an opportunity to bash Evernote, but I am terribly disappointed that a service that advertised you to keep really personal stuff, even your tax info on their servers just got hacked. I think I'm going back to creating .txt files on my desktop which no one else has access to (physcially and programatically), which despite having no encryption o…

The desktop client has a "Export Notes" function that will export to HTML or their custom format. I use this to make a local backup occasionally.

Re: Evernote doesn't really care about security

#34

"If you encrypt text within a note, we derive a 64-bit RC2 key from your passphrase and use this to encrypt the text. This is the longest symmetric key length permitted by US Export restrictions without going through a complex process to gain export approval." Is this still true? Weren't US cryptography export restrictions relaxed in 2000? (See e.g. http://www.rsa.com/rsalabs/node.asp?id=2327 )

No, this is not true. I think Evernote has been misinformed.

If all you are doing is encrypting data with a standard algorithm, it takes less than 30 minutes to fill out the paperwork to get an encryption registration number (ERN). Total turnaround time when I've done it has been about two weeks.

There are some exceptions. If you are trying to export cryptanalytic software or doing something non-standard, you may have delays.

http://www.bis.doc.gov/encryption/enc_faqs.htm

Re: Evernote doesn't really care about security

#35
post #33
post #27

Is there a way to download your Evernote data? Not to say that I find this an opportunity to bash Evernote, but I am terribly disappointed that a service that advertised you to keep really personal stuff, even your tax info on their servers just got hacked. I think I'm going back to creating .txt files on my desktop which no one else has access to (physcially and programatically), which despite having no encryption o…

The desktop client has a "Export Notes" function that will export to HTML or their custom format. I use this to make a local backup occasionally.

Thank you! Just took a backup with the desktop tool..

Re: Evernote doesn't really care about security

#36

Mark, it would be helpful if you would disclose if you are a paying customer or not, and if not if having additional security options would convert you into a paying customer. The reasoning is pretty simple, people want security but they don't want to pay for it. And while we can debate the argument as to whether or not security is part of a MVP or not, I would not be offended if there were additional security capabi…

Basic security is dirt cheap, and it is not at all appropriate to risk user data because you want them to pay.

Re: Evernote doesn't really care about security

#37
post #9

Only half the points are valid. SSL is a selling point, because it takes a lot of work to setup completely. Lots of websites (including high-profile ones like Outlook.com) have mixed content errors at one place or another, or appear to but don't fully support SSL. The fact that they "used to" use it as a selling point says enough too. SSL signin should not be enforced. HTTP should give a big warning, but SSL is not f…

SSL is easy to do if you

1. force it on your servers

2. only include content from your servers

It becomes almost impossible to mix insecure content at this point.

Re: Evernote doesn't really care about security

#38

Mark, it would be helpful if you would disclose if you are a paying customer or not, and if not if having additional security options would convert you into a paying customer. The reasoning is pretty simple, people want security but they don't want to pay for it. And while we can debate the argument as to whether or not security is part of a MVP or not, I would not be offended if there were additional security capabi…

Security should not be a feature.

Re: Evernote doesn't really care about security

#39

Mark, it would be helpful if you would disclose if you are a paying customer or not, and if not if having additional security options would convert you into a paying customer. The reasoning is pretty simple, people want security but they don't want to pay for it. And while we can debate the argument as to whether or not security is part of a MVP or not, I would not be offended if there were additional security capabi…

I think you're, rather cynical, reasoning falls flat. This would not be a good policy for a company to adopt. If I was evaluating software and saw such a policy, it would bring a lot of uneasy feelings, even regarding the supposed security of the paid version. This side steps the bad publicity and general ill-feelings the community at large would have about your service. I don't think it is strategically a good choice to make such a compromise on security. At best, I could see giving separate authentication mechanisms such as two-factor for paid users, but that's as far as I'd go.

Re: Evernote doesn't really care about security

#40

Mark, it would be helpful if you would disclose if you are a paying customer or not, and if not if having additional security options would convert you into a paying customer. The reasoning is pretty simple, people want security but they don't want to pay for it. And while we can debate the argument as to whether or not security is part of a MVP or not, I would not be offended if there were additional security capabi…

I think you're, rather cynical, reasoning falls flat. This would not be a good policy for a company to adopt. If I was evaluating software and saw such a policy, it would bring a lot of uneasy feelings, even regarding the supposed security of the paid version. This side steps the bad publicity and general ill-feelings the community at large would have about your service. I don't think it is strategically a good choic…

So can you say more about that? Specifically

"If I was evaluating software and saw such a policy, it would bring a lot of uneasy feelings, even regarding the supposed security of the paid version."

What if it was explicit? What if Evernote said, "Since it would cause us to lose money if we spent time on both more sophisticated security in the free product. Its basically secure against random threats but dedicated people will be able to break into it. If you want a truly secure product you should sign up for the paid product, part of that fee goes to paying the salaries of the security team we have on staff who are keeping it that way."

We also need to be clear what we mean by "security" here, there is "security" as in we make sure if someone breaks in they cannot easily get your password (they seem to have done that with salted passwords), and their is security as in "Even our operations staff can't get you access to your files if you lose your access token." level of security which takes a lot more work.

I'll admit I was pretty put off by Mark's assertion that Evernote doesn't care about security, his basis for that are three claims, that 2 factor authentication is late, that SSL isn't forced on, and that 64 bit RC2 is used in the free product. What is the purpose of the free product anyway? Is it to prove their security? I don't think it is, I think it is to give you a way to test drive what their product does without risking any money.

Anyway, someone broke in and got access to hashed and salted passwords and Evernote reset those. LinkedIn had the same issue, some Facebook apps grabbed similar data, Google has hosted malware in their App Store which tried to install banking trojans on your phone.

I am not persuaded by the assertion that "Evernote doesn't care about security" any more than "Google doesn't care about security" (and I happen to know they care very deeply and still get compromised now and then).

I defended Evernote because I felt Mark was unfairly maligning them and their CEO. I would be more sympathetic if he was a paying customer, and less sympathetic if he only has a free account.

Post reply on HN