Following hack, Evernote speeds move to two-factor authentication
The company is one of many trying to shore up its systems in the face of aggressive hackers
IDG News Service - Evernote is speeding up its plans to offer two-factor authentication to users following a recent data breach that exposed user names, email addresses and encrypted passwords.
The company, which makes note-taking software, disclosed on its blog on Saturday that an attacker accessed its internal network, which forced it to reset 50 million user passwords. Payment information was not accessed, Evernote said.
The company had planned to roll out two-factor authentication to users eventually but is now accelerating those plans, according to an Evernote spokeswoman.
Two-factor authentication usually requires a user to enter a time-sensitive code in addition to their user name and password. The code can be sent by SMS, or a standalone application such as Google Authenticator can generate a code.
Two-factor authentication poses a somewhat higher barrier for hackers, who not only need to capture a person's static login details but also the code.
It is not impossible to get the code, however, and several malicious software programs for mobile devices have been able to snatch it. If that interception is successful, the hacker can then quickly enter the details and log in to a person's account.
Other security features are also in the works. Evernote said it will offer "significant upgrades to the optional client-side encryption features later this year, including updated algorithms to take advantage of the additional flexibility allowed under changes to the US export control laws, as well as other user-selectable features."
Evernote is just one of many companies, including Apple, Facebook and Microsoft, that have disclosed hacking incidents in recent weeks,.
Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk
- 10 Hot Big Data Startups to Watch
- 11 Unique Uses for Google Glass, Demonstrated by Celebs
- How to Export Your Google Reader Account
- How to Better Engage Millennials (and Why They Aren't Really so Different)
- Telltale signs of ATM skimming
- 20 security and privacy apps for Androids and iPhones
- Big screen con artists: 7 great movies about social engineering
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- eBook: Security for a faster world This eBook presents a model that will help you determine how secure you are and outlines a new approach based on intelligence gathering...
- Deliver Customer Value with Big Data Analytics Big Data requires that companies adopt a different method in understanding today's consumer. Read this white paper to learn why Big Data is...
- Cloud Analytics for the Masses Learn the best practices in building applications that can leverage volume, variety and velocity of Big Data for organizations of any size.
- An Interactive eGuide: DDoS Attacks In today's world, Distributed Denial of Service (DDoS) attacks on organizations are becoming more prevalent. The number of attacks are increasingly annually with...
- 3 Reasons Why Sepaton is the World's Fastest Backup Solution Leading analyst, Storage Switzerland learns how Sepaton backs up and deduplicates massive data volumes while maintaining the industry's fastest performance - all in...
- Virtustream (Vayence) video taking a 3000-Seat SAP Environment to the Cloud How can public cloud services help your organization reduce costs and increase security for your mission All Cybercrime and Hacking White Papers | Webcasts