Live data from Hacker News

Evernote doesn't really care about security

markpercival.us

41–50 of 64 posts

Re: Evernote doesn't really care about security

#41

Earlier quoted context omitted.

I think you're, rather cynical, reasoning falls flat. This would not be a good policy for a company to adopt. If I was evaluating software and saw such a policy, it would bring a lot of uneasy feelings, even regarding the supposed security of the paid version. This side steps the bad publicity and general ill-feelings the community at large would have about your service. I don't think it is strategically a good choic…

So can you say more about that? Specifically "If I was evaluating software and saw such a policy, it would bring a lot of uneasy feelings, even regarding the supposed security of the paid version." What if it was explicit? What if Evernote said, "Since it would cause us to lose money if we spent time on both more sophisticated security in the free product. Its basically secure against random threats but dedicated peo…

Where does it say that RC2 is only used for the free product?

AFAIK it's all the time which is ABadThing (tm)

FWIW, if one has to rely on security being a differentiator in 2013, that's IMO a bad sign. Compete on other features but not security.

Re: Evernote doesn't really care about security

#42
post #5

The RC2 thing from the disclosure is really, really weird. It makes Evernote the only app built in the last 10 years that I am aware of to build on RC2. I wonder whether it's a mistake, and they're actually using RC4 with truncated keys or something.

Confirmed here too. https://support.evernote.com/link/portal/16051/16058/Article...

I don't buy this. They could easily have high security versions in countries that allow it. Lowest common denominator in this case is not a good idea.

Re: Evernote doesn't really care about security

#43
post #27

Is there a way to download your Evernote data? Not to say that I find this an opportunity to bash Evernote, but I am terribly disappointed that a service that advertised you to keep really personal stuff, even your tax info on their servers just got hacked. I think I'm going back to creating .txt files on my desktop which no one else has access to (physcially and programatically), which despite having no encryption o…

Well, don't do that. At least stick it in truecrypt

Re: Evernote doesn't really care about security

#44
Co-founder of Catch here, we are sometimes compared to Evernote but Catch is a note-sharing and collaboration app.

1. Two-factor

We don't offer two factor but is something we are investigating. This is mitigated somewhat by the fact that a lot of our users use Google login.

2. SSL / TLS

SSL shouldn't be a paid feature. It's been included in our product for free since we launched.

We try and use SSL everywhere. All page from catch.com are only available via SSL. e.g. login, landing page, marketing, blog, etc.

There are a few exceptions like our Knowledge Base which is powered by Assitly / Desk:

http://support.catch.com/

3. Encryption

We don't offer note level encryption. We'd love to get some feedback on a straightforward way to do key management.

4. HSTS

We've been using HSTS for at least a year now. It was an easy decision for us since all content from catch.com is only available via SSL.

Security is hard and hopefully these breaches will raise the bar for everybody.

Re: Evernote doesn't really care about security

#45
The point that the folks over at Evernote are really missing is that Joe Average is using the very same credentials everywhere else, from their Gmail to the Amazon accounts. If Evernote where sensible about security of their users, they would have explained why it is indeed a bad and common practice to use the same password everywhere, as it is a certain way to get your online identity hijacked sooner rathre than later by means of a breakin like this one. It is good to know that passwords have been stored salted, but nevertheless, eventually these credentials are now compromised and if Evernote where sensible about this they would have told their users to reset their password whereever they use the same one, which is probably lousy marketing compared to "hey, we got your password stolen, but don't worry, it was encrypted".

Re: Evernote doesn't really care about security

#46
post #32

What're the alternatives to Evernote? e.g. decent document tagging, excellent search and preferably OCR.

I'm pretty happy with org-mode, albeit minus the "OCR" bit. (Most of my org-mode docs tend to be written in org and stay there, there's less of this "pulling documents from outside into it" business than evernote)

That doesn't work for the large amounts of paperwork I scan in and need to catalog.

Re: Evernote doesn't really care about security

#48
post #28

Earlier quoted context omitted.

Addressing US regs doesn't necessarily mean you are compliant with assorted international regs. Crypto, export, and service availability can be tricky things.

International regulations are pretty insane. For example, France requires you to submit your software to them for review that's supposed to take up to 2 weeks. This isn't just for product releases, it includes everything, including patches. Apple, MS and Google can get away with it because they have large legal teams that help them with all the various rules and regulations. For smaller companies, it's simply too mas…

So, how come all sorts of small companies, from 1Password to Dropbox use stronger encryption?

Re: Evernote doesn't really care about security

#49
post #19
post #9

Only half the points are valid. SSL is a selling point, because it takes a lot of work to setup completely. Lots of websites (including high-profile ones like Outlook.com) have mixed content errors at one place or another, or appear to but don't fully support SSL. The fact that they "used to" use it as a selling point says enough too. SSL signin should not be enforced. HTTP should give a big warning, but SSL is not f…

What wouldn't support SSL? I can't think of a single product.

Windows XP with any Internet Explorer (even 8) and Safari don't support SNI. You need to use more expensive certificates or get an unique IPv4 address in order to support https there.

Re: Evernote doesn't really care about security

#50
post #31
post #9

Only half the points are valid. SSL is a selling point, because it takes a lot of work to setup completely. Lots of websites (including high-profile ones like Outlook.com) have mixed content errors at one place or another, or appear to but don't fully support SSL. The fact that they "used to" use it as a selling point says enough too. SSL signin should not be enforced. HTTP should give a big warning, but SSL is not f…

No. I consider properly setting up SSL to be a duty of care for the website owner. Your argument could apply to storing passwords in plaintext because "hashing is hard," or doctors refusing to wash their hands between patients because "it takes too much time" -- it's just not a corner that professionals should cut anymore.

Uh, if a selling point of theirs was "we hash your password", I would find that a good thing. I'm not saying it's not a duty for the website owner.
Post reply on HN