Thanks for the headsup. Changing now.
Password Reset Discussion Thread
#1
Posted 02 March 2013 - 04:04 PM
Premium Windows & Android | Wales, UK - EN Mobile 5.1.2 public | Galaxy S3 Android 4.1.2 | FF 21
EN Desktop 4.6.6.8360 (268868) Public | HP DV6000 laptop Vista SP1 | FF 22.0 + Clipper 5.7 & Clearly 9.3369.854.430 | MS Office 2007
User Manuals: Mac | Windows | iOS | Android | Getting Started | Support Page | Knowledge Base | Status Page | Support Requests & Feedback
#2
Posted 02 March 2013 - 04:17 PM
Beware - I had to resync all my off-line content on iPad and iPhone because of this. Support ticket #16051-248323.
#3
Posted 02 March 2013 - 04:18 PM
Glad i found this post.
Tried to login (desktop app) today and was getting error, went on web sign in and asked me for a pass reset.
Cheers
#4
Posted 02 March 2013 - 04:24 PM
I certainly hope they send and email to everyone's email of record. I was lucky and tried to sign in on the web client and discovered I had to do a password reset to log in.
#5
Posted 02 March 2013 - 04:34 PM
I certainly hope they send and email to everyone's email of record. I
was lucky and tried to sign in on the web client and discovered I had
to do a password reset to log in.
From the blog post:
The following blog post is also being sent to all Evernote users as an email communication.
I assume that may take a little time though...
My Evernote Help Shared Notebook: http://www.evernote....t/evernote-help
#6
Posted 02 March 2013 - 04:36 PM
Two-step verification would be nice to avoid this type of problems
#7
Posted 02 March 2013 - 04:45 PM
Beware - I had to resync all my off-line content on iPad and iPhone because of this. Support ticket #16051-248323.
Me too... 5GB worth - not at all happy about that - also not sure I haven't lost space on the iPad with the re-download... I'd appreciate some word on this from Evernote
#8
Posted 02 March 2013 - 05:02 PM
Well, Evernote can't say they weren't repeatedly warned.
There have been tons of previous comments about Evernote security requesting 2-factor authentication, full note encryption and many other security suggestions.
I'm sure most users are glad to hear that even though this type of activity is becoming more common with large services, Evernote is doing something to improve its security (by asking you to create a new password).
Hope it's not too difficult for everyone with multiple mobile devices and fat fingers to complete the process of getting back online by entering a new lengthy complex password several times.
According to the blog post mentioned above, there has been:
- no evidence that your Evernote content was accessed
- no evidence that any payment information was accessed
- but the hackers did gain access to user information, usernames, email addresses and encrypted passwords.
However no worries man - your password was hashed and salted.
Make sure you have multiple Evernote backups as well.
#9
Posted 02 March 2013 - 05:03 PM
I hope our email addresses were also stored on Evernote's servers in encrypted format, as I'm not looking forward to a deluge of spam.
#10
Posted 02 March 2013 - 05:17 PM
why not using 2 step auth providing by google?
#11
Posted 02 March 2013 - 05:25 PM
I guess it's understandable, if rather annoying. But...
No e-mail, yet.
Why no announcement on the Evernote Status RSS feed?
Why no announcement on the Evernote Tech Blog RSS feed?
Martin
#12
Posted 02 March 2013 - 05:26 PM
I hope our email addresses were also stored on Evernote's servers in encrypted format, as I'm not looking forward to a deluge of spam.
Seconded.
Martin
#13
Posted 02 March 2013 - 05:33 PM
I'm glad they are forcing the password change, but as others have said they way it is being handled seems a bit amateurish.
#14
Posted 02 March 2013 - 05:35 PM
So the status is more for technical messages (outages/maintenance/etc.), but I guess a message could have gone there.Why no announcement on the Evernote Status RSS feed?
Why no announcement on the Evernote Tech Blog RSS feed?
The Tech blog would (possibly) be slightly redundant and the normal blog, which is where the announcement is, would be better as there are more likely more followers to that than the tech blog.
At least, that is my take on it.
Scott
My Evernote Help Shared Notebook: http://www.evernote....t/evernote-help
#15
Posted 02 March 2013 - 05:41 PM
"Evernote’s Operations & Security team has discovered and blocked
suspicious activity on the Evernote network that appears to have been a
coordinated attempt to access secure areas of the Evernote Service.
As a precaution to protect your data, we have decided to implement a
password reset. Please click link below for details and instructions."
Every company gets hit with problems - how they handle those problems is what sets them apart.
Easy misses (EN did *not* do) by Evernote once they discovered the problem:
1) Immediate email broadcast to all users with the simple text above.
2) For those users who had not seen the email and were wondering why they were being forced to reset PW, insert the same simple text in the password reset screen rather then leaving them wondering "I did not click 'reset password' - why is Evernote stuck in this reset loop?"
Edit: I had to learn what happened via a Tech Crunch tweet:
http://techcrunch.co...ayment-details/
#16
Posted 02 March 2013 - 05:42 PM
I'm a premium user and I didn't get an email. Not happy about it, but the security breach is even more worrisome.
#17
Posted 02 March 2013 - 05:44 PM
I really wish they explained on the password reset screen WHY Evernote is forcing you to reset a password. I originally thought it was either a bug (since I didn't ask for a reset) or that I was experiencing some sort of man in the middle attack.
#18
Posted 02 March 2013 - 05:51 PM
This is the first time that I can remember that they've had any sort of breach, although I'm not overwhelmed with joy at how I found out about it, I think you have to give them a chance and let them learn a little as they go along. Hopefully there won't ever be another breach (of course there will be), but if there is then our expectation of how they handle notifications will be justifiably higher.
#19
Posted 02 March 2013 - 05:55 PM
#20
Posted 02 March 2013 - 05:56 PM
Not being surprised or annoyed I'll just note this sort of thing is precisely why MY company won't let me keep sensitive data in public cloud services. Before we get anywhere near Evernote Enterprise - and they tell us this isn't something they're terribly interested in - this would have to get fixed to enterprises' satisfaction.
BTW what happens if an Evernote Business customer grows to become an Enterprise one? :-)
Also tagged with one or more of these keywords: security, issue, hacked, windows, mac, ios, android
Windows
Evernote Products →
Evernote →
Text und Bilder in Evernote oder am Originalplatz?Started by bilbo_b, Today, 08:47 AM |
|
|
||
iOS
Evernote Products →
Evernote Hello →
The ConceptStarted by bluesgeek, Today, 04:02 AM |
|
|
||
General Discussions →
Evernote General Discussion →
Evernote Knowledge Base →
EVERNOTE DATA, IN CLOUDStarted by leandro.sche@gmail.com, Today, 02:07 AM |
|
|
||
Mac
Evernote Products →
Evernote →
How do I save to a Notebook?Started by zagyzebra, Today, 01:55 AM |
|
|
||
Windows
Evernote Products →
Evernote →
Evernote: Buried Alive - Any Book Recommendations for an Evernote Hoarder?Started by LookingGlassWriting, Today, 01:25 AM |
|
|
1 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users
-
Google Mobile (1)













