Only a username and password separates your Evernote collection from prying eyes.

evernote-securityEvernote provides a great cloud-based service for note taking and clipping that lets you store information for access from any Web-connected device. Unfortunately, amidst all the clever suggestions for using Evernote are several very risky tips. The problem: the only thing separating your Evernote collection from prying eyes is a username and password. If you're the victim of a phishing scam or password-stealing malware, that Evernote collection could provide a one-stop-shop for all your sensitive data.

Some premium (paid) users of Evernote mistakenly assume their Evernote data will somehow be safe from external attacks. However, the security in Evernote premium is simply SSL encryption, which merely encrypts the data while it is being transmitted. It does not prevent it from being stolen by anyone who obtains the username and password.

Premium users can highlight a portion of text notes for an an additional layer of password protection, but third-party tests reveal that in the local database, the selected text still remains searchable in plain text. Further, whole notes, images, and notebooks cannot be encrypted. Of course, you could secure the local database using third-party encryption tools, but that would prevent access from other devices (and defeat the purpose of being "in-the-cloud").

 

Bottom line: storing unencrypted data on an Internet-facing server is not a great idea.

With that in mind, following are seven of the worst Evernote (or any cloud-based storage) tips:
1. I'm a teacher. I use @evernote to create individual portfolio files for each student, documenting everything. 
Why it's bad: Compromise of the teacher's Evernote credentials potentially exposes sensitive details on students, who also likely happen to be minors. This tip is not only a security risk to those students, it potentially has legal ramifications for the teacher (and the school at which they teach).

2. Store credit card statements. 
Why it's bad: Credit card statements often include the account number. Exposure could lead to increased risk of credit card fraud.

3.Store login names and passwords for websites (tag with Login to see them all together) 
Why it's bad: Attackers who gain entry to your Evernote account now potentially have access to all your online accounts.

4. Build family medical portfolios including medical history, allergies, pictures of medications, receipts. 
Why it's bad: In the past, cybercriminals who have stolen medical information have sometimes blackmailed the victims. Unless this is information you would feel comfortable sharing with friends, neighbors or even strangers, it is best not stored in-the-cloud.

5. Keep family social security numbers (and other info) in an encrypted note for easy, secure access. 
Why it's bad: Exposure leaves your entire family at risk of identity theft. This type of sensitive information is best kept in a locked file cabinet, not in-the-cloud.

6. Keep router/firewall settings (addresses, passwords, open/closed ports, etc.) handy and nearby. 
Why it's bad: Attackers who gain access can use this information to reconfigure DNS settings on your router or enable their own access to your network.

7. Take a photo of your passport and send it to Evernote. If it's lost or stolen, you can still show the embassy your info.
Why it's bad: A photo of your passport makes it that much easier for counterfeiting. A safer bet would be storing only the passport number (in encrypted form).Cloud-based storage services like Evernote are not really "in-the-cloud". The data is simply off-shored to a remote computer and accessible to anyone who obtains the username and password. The more accessible the data is to you, the more accessible it is to would-be attackers. Off-shored, cloud-based storage is a convenience, but recognize that the convenience does carry risk and is probably not the best storage choice for sensitive information.

Comments  

 
0 # Storage Melbourne 2011-12-02 04:47
And so, Evernote is still untrusted for our confidential files to be stored. Since when it comes to computer storing, being a victim of hack or scam is our major problem. And it is true, we must not entrust here our credit cards info's.
Reply | Reply with quote | Quote
 

Add comment


Security code
Refresh

Evernote Blogcast
  • Week in Review: A Recap of This Week’s Posts
    The All New Evernote 4.0 for Android Completely redesigned and packed with new features and settings, Evernote 4.0 for Android is the most powerful Evernote for Android, ever. Learn more. Let’s Get Cooking: The First Evernote Cook-Along with Home Cooking Ambassador Join Home Cooking Ambassador Lauren Atkins for our first-ever Evernote Cook-Along. Get cooking. With [...]
  • Quick Tip Friday: Capture Multiple Types of Media in a Single Note
    Did you know that you can put lots of different stuff into a single note? Try it. Create a New Note, then: Type text Add a few checkboxes Record some audio Drag in a file or two (documents, PDFs, presentations, spreadsheets) Snap an image Combining different pieces of content into a note lets you keep [...]
  • Trunk Spotlight: FileThis Fetch for Automatically Sending Bills and Statements to Evernote
    App: FileThis Fetch Company: FileThis Platform: Web Price: Free trial. Monthly and Annual Plans available Type: Document management If you’re considering going paperless, or already working your way towards a paperless lifestyle, you may just be trying to figure out how to electronically send paper bills to your Evernote account, where you can find, organize, [...]
  • With a Lot of Help from Our Friends
    Remember that $70 million round of funding we announced way back a week and a half ago? A crazy amount of stuff has happened since then, but I wanted to go back to the topic of the funding announcement and add a cool new detail: there’s a small “CEO Club” that’s helping to build Evernote. [...]
  • The All New Evernote 4.0 for Android
    Major operating system updates are a great opportunity for us to rethink our apps. That’s exactly what happened when Google released the Ice Cream Sandwich operating system. Today, we’re excited to unveil the completely redesigned Evernote 4.0 for Android. It’s more than just a new look, it’s the most powerful Evernote for Android, ever. Get [...]
  • Let’s Get Cooking: The First Evernote Cook-Along with Home Cooking Ambassador
    After welcoming our Home Cooking Ambassador to the Ambassador Program, we naturally wanted to cook something. Since so many of you already use Evernote and Evernote Food to manage recipes and capture your cooking and eating experiences, we thought it would be fun for Lauren to lead a community cook-along event that lets us connect [...]