PSA: Be sure to change your Evernote password today!

Evernote
By Adam Zeis on 2 Mar 2013 02:08 pm EST
7
loading...
9
loading...
52
loading...

Just a quick PSA today to be sure that you change up your Evernote password. There was some suspicious activity at Evernote HQ earlier today and as a precaution they are requiring users to reset their password before logging in. Kevin and I both thought we were hacked when we got the password update notice this morning, but it looks like all is well and your Evernote goodies are still safe. Just head over to evernote.com to choose a new password and then you'll be all squared away. If you're a BlackBerry Z10 owner you'll need to verify your account again from your device with the new password as well. Check out the full statement from Evernote below.Dear Evernote user,

Evernote Security Notice: Service-wide Password Reset 

Evernote's Operations & Security team has discovered and blocked suspicious activity on the Evernote network that appears to have been a coordinated attempt to access secure areas of the Evernote Service.

As a precaution to protect your data, we have decided to implement a password reset. Please read below for details and instructions.

In our security investigation, we have found no evidence that any of the content you store in Evernote was accessed, changed or lost. We also have no evidence that any payment information for Evernote Premium or Evernote Business customers was accessed.

The investigation has shown, however, that the individual(s) responsible were able to gain access to Evernote user information, which includes usernames, email addresses associated with Evernote accounts, and encrypted passwords. Even though this information was accessed, the passwords stored by Evernote are protected by one-way encryption. (In technical terms, they are hashed and salted.)

While our password encryption measures are robust, we are taking steps to ensure your personal data remains secure. This means that in an abundance of caution, we are requiring all users to reset their Evernote account passwords. Please create a new password by signing into your account on evernote.com.

After signing in, you will be prompted to enter your new password. Once you have reset your password on evernote.com, you will need to enter this new password in other Evernote apps that you use. We are also releasing updates to several of our apps to make the password change process easier, so please check for updates over the next several hours.

As recent events with other large services have demonstrated, this type of activity is becoming more common. We take our responsibility to keep your data safe very seriously, and we're constantly enhancing the security of our service infrastructure to protect Evernote and your content.

There are also several important steps that you can take to ensure that your data on any site, including Evernote, is secure:

Avoid using simple passwords based on dictionary words
Never use the same password on multiple sites or services
Never click on 'reset password' requests in emails - instead go directly to the service
Thank you for taking the time to read this. We apologize for the annoyance of having to change your password, but, ultimately, we believe this simple step will result in a more secure Evernote experience. If you have any questions, please do not hesitate to contact Evernote Support.

The Evernote Team

Reader comments

PSA: Be sure to change your Evernote password today!

16 Comments

Yeah, seriously scared the hell out of me when I got the pop up on my desktop app saying to enter my password. Then I put in my password and it didn't work. Scary. But changed it. All good now. I love evernote!

Who doesn't love Evernote?

My whole life is stored on it.

...Not entirely, but you get the point.

If my account was to be hacked (highly unlikely), they'd have so much confidential information and ruin me. D:

And BlackBerry wonders why people complained about the loss of Outlook desktop sync and didn't simply want to keep all their confidential information "in the cloud".

anyone know how to sync my existing notes into Evernote? just made up an account after seeing this warning lol

Evernote should have sent out notices to all of it's users letting us know what's up. Of course, Crackberry came through, THANKS!

heck Evernote should just go thru BBRY BES and BBRY could offer users a secure Blackberry Evernote experience for an annual fee. I would pay for this !
My buddy a security analyst came back from China said Evernote is gathering traction in China and the site is not hack proof !

Maybe the Posted Note site needs a BES help !!

Any reason why my folders/notes aren't fully sync'd? I don't see a 'sync' or 'refresh' anywhere, but I am missing folders and notes that are there when I look at the web version.

I have deleted the Evernote account from my Z10 for time being since it's not syncing. Using Android sideload for now, since it its fully sync.

I like the integration of Evernote on Z10, but no point if it won't sync. Have ticket opened at Evernote.