Evernote resets all passwords after user information is stolen in security breach

154

Popular note-taking service Evernote has reset all user passwords after information including usernames, email addresses, and encrypted passwords was stolen in a security breach. A warning on the service's official blog — which experienced loading problems soon after being posted — emphasises that no content was either "accessed, changed, or lost," but advises users that they will be prompted to choose a new password next time they log in, and provides advice on selecting a secure word or phrase.

The passwords taken in the breach were both hashed and salted, meaning that they should be protected from all but the most dedicated cracking attempts, but the blog post does not explain which encryption algorithm was used. According to an email from Evernote, "unusual and potentially malicious activity" was first detected by the company's security team on February 28th. Evernote plans to release updates to its native apps for various platforms "over the next several hours" in an attempt to smooth out the password reset process for all users.

More from The Verge

Back to top ^
X
Log In Sign Up

forgot?
Log In Sign Up

Please choose a new Verge username and password

As part of the new Verge launch, prior users will need to choose a permanent username, along with a new password.

Your username will be used to login to Verge going forward.

I already have a Vox Media account!

Verify Vox Media account

Please login to your Vox Media account. This account will be linked to your previously existing Eater account.

Please choose a new Verge username and password

As part of the new Verge launch, prior MT authors will need to choose a new username and password.

Your username will be used to login to Verge going forward.

Forgot password?

We'll email you a reset link.

If you signed up using a 3rd party account like Facebook or Twitter, please login with it instead.

Forgot password?

Try another email?

Almost done,

By becoming a registered user, you are also agreeing to our Terms and confirming that you have read our Privacy Policy.
Spinner.vc97ec6e

Authenticating

Great!

Choose an available username to complete sign up.

In order to provide our users with a better overall experience, we ask for more information from Facebook when using it to login so that we can learn more about our audience and provide you with the best possible experience. We do not store specific user data and the sharing of it is not required to login with Facebook.

tracking_pixel_5345_tracker