Evernote To Introduce Two-Factor Authentication

Following a security breach on the weekend, the developer of popular note-taking and organisation software Evernote has announced plans to speed up the introduction of two-factor authentication (2FA) for its services.

Earlier, the company chose to reset passwords for 50 million accounts, after an attacker was able to gain access to account information stored on the platform, such as user names, emails and encrypted passwords. This situation could have been prevented if 2FA was available.

Learning from mistakes

On Saturday, Evernote initiated a “service-wide password reset”, after the security team discovered a “coordinated attempt to access secure areas of the Evernote Service”.

An investigation launched by the company soon discovered that an unidentified party was able to gain access to account information. Evernote found no evidence of hackers accessing private user content or payment details. All of the passwords were subsequently reset, and users informed of the breach in an email.

According to spokeswoman Ronda Scott, Evernote was always planning to introduce optional security measures to its services. However, following the attack, the company will be “accelerating those plans”.

Two-factor authentication is an authentication method which requires the presentation of at least two out of three factors: a knowledge factor (such as a password or PIN), a possession factor (such as a keycard or a smartphone) or an inherent factor (like a fingerprint or eye iris pattern).

It is unlikely the attackers would be able to use the stolen data, since Evernote, abiding by good security practices, ‘hashed’ and ‘salted’ its passwords. “If this was performed correctly, then users should not be concerned about their passwords being compromised. Evernote took the right steps to reset everyone’s password too,” commented Mark Bower, VP for Product Management at Voltage Security.

“Very likely there was a Java or zero day exploit leading to system penetration. Maybe an insider opened a malicious email from spear phishing. We may never know, but once again it shows that what was once considered the impenetrable barrier, the enterprise perimeter, is now just a semi permeable membrane only as good as the weakest link,” he added.

Earlier this month, Twitter posted a job listing, looking for a software engineer in product security, with experience in areas such as “multifactor authentication and fraudulent login detection”. This prompted rumours that the microblogging platform could be looking to join the ranks of Dropbox, Facebook, Google, PayPal and other companies which have already implemented 2FA.

How well do you know Internet security? Try our quiz and find out!

Max Smolaks

Max 'Beast from the East' Smolaks covers open source, public sector, startups and technology of the future at TechWeekEurope. If you find him looking lost on the streets of London, feed him coffee and sugar.

View Comments

  • Which situations could have been prevented using SFA?

    Obviously we are not talking about illegal access to the Evernote systems.
    2FA makes authentication phase more secure because there is need for a physical token for the access.

    Instead, what was compromised last time, was the information system of Evernote, which means emails, userID's, passwords (probably well coded), as the company said.

    But they didn't mentioned the notes set by users in the system; and these were been accessed or not?

    Anyway, for me (a premium account) Evernote is a really good services/product.

    If I may ask, I would like to know better about their ISMS, expecially regarding the security measures for "customers-notes".

    Last about 2FA; well, it's a nice-to-have gadget; most important to me is the immediacy of a reaction after a system break, the promptly of information sending to the customers (like the last time)

    Personally I put sensitive informations in Evernote, only after a codification, generally using a tool like PGP/GPG

    Yes, I know that Evernote client has embedded a cryptography tools, but I wasn't able to find tech information about them (the algorithms used); however, the fact that "nobody (including Evernote staff) can recover this text if the passphrase is lost or forgotten", gives me hope that there is a good architecture behind curtains.

Recent Posts

Amazon Workers In North Carolina Reject Unionisation

Workers at Amazon warehouse near Raleigh vote against joining union, as company continues to challenge…

12 hours ago

China President Xi Meets With Top Tech Leaders

High-profile meeting with tech leaders seen as signal China is boosting tech sector after years…

12 hours ago

South Korea To Buy 10,000 GPUs For National AI Hub

South Korea hopes to gain leg up in international AI race with infusion of private…

13 hours ago

BYD, Geely, Great Wall Add DeepSeek AI To EVs

Chinese electric vehicle giants rush to incorporate DeepSeek AI tech to cars after it creates…

13 hours ago

South Korea Suspends DeepSeek From App Stores

South Korean data authority suspends Chinese AI start-up DeepSeek from Apple, Google app stores while…

14 hours ago

Google Puts ‘Profits Over Privacy’ With Tracking Change

Privacy advocates criticise Google over decision to allow companies to track users via digital fingerprints,…

14 hours ago