Following hack, Evernote speeds move to two-factor authentication

The company is one of many trying to shore up its systems in the face of aggressive hackers

Evernote is speeding up its plans to offer two-factor authentication to users following a recent data breach that exposed user names, email addresses and encrypted passwords.

The company, which makes note-taking software, disclosed on its blog on Saturday that an attacker accessed its internal network, which forced it to reset 50 million user passwords. Payment information was not accessed, Evernote said.

The company had planned to roll out two-factor authentication to users eventually but is now accelerating those plans, according to an Evernote spokeswoman.

Two-factor authentication usually requires a user to enter a time-sensitive code in addition to their user name and password. The code can be sent by SMS, or a standalone application such as Google Authenticator can generate a code.

Two-factor authentication poses a somewhat higher barrier for hackers, who not only need to capture a person's static login details but also the code.

It is not impossible to get the code, however, and several malicious software programs for mobile devices have been able to snatch it. If that interception is successful, the hacker can then quickly enter the details and log in to a person's account.

Other security features are also in the works. Evernote said it will offer "significant upgrades to the optional client-side encryption features later this year, including updated algorithms to take advantage of the additional flexibility allowed under changes to the US export control laws, as well as other user-selectable features."

Evernote is just one of many companies, including Apple, Facebook and Microsoft, that have disclosed hacking incidents in recent weeks,.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags intrusionEvernotesecuritydata breachDesktop securitydata protection

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?