So Evernote made me change my password last weekend, and I'm still annoyed about it in a way that's probably out of proportion to the actual problem.
Quick recap for anyone who missed it: on Saturday, Evernote announced that somebody had gotten into their systems and grabbed a database with usernames, email addresses, and password data for basically everyone who uses the service. They were quick to say the passwords were salted and hashed, not sitting there in plain text, which is the bare minimum you'd hope for from a company holding 50 million people's notebooks. Still, they force-reset every account. I opened my laptop Sunday morning, coffee not even finished brewing yet, and got greeted with a login wall instead of my to-do list.
I don't actually think Evernote handled this badly. Salted and hashed is the right call, they told people fast instead of sitting on it for a month like some companies do, and forcing a reset is the correct paranoid move even if the hashes never get cracked. My complaint isn't with Evernote specifically. Its that I now have roughly nine services that have made me do this exact dance in the last year and change, and every single time my brain goes through the same five stages: annoyance, then "what was my password again," then the realization I've been reusing some variant of it somewhere else, then the guilt, then finally the new password which I will absolutely forget by Thursday.
I use Evernote for everything, which is part of why this stung a little more than it should have. Recipe notes, half-formed blog post drafts (some of which never make it here, which you should be grateful for), a running list of RV parks along I-40 my dad keeps sending me links to. None of that is exactly state secrets. But it's the principle of a stranger having had access to the database it all lived in, even briefly, even if all they got was a hashed string that's useless without absurd amounts of compute.
Here's my actual opinion, and I know I say some version of this every time one of these breaches happens: get a password manager already. I've been using LastPass for about a year now and it is genuinely the most boring, unglamorous piece of software I own, and also maybe the most useful. When Evernote made me reset, I didn't have to think of anything. I clicked generate, got back forty characters of nonsense, pasted it in, and moved on with my Sunday. The whole ordeal took ninety seconds instead of the fifteen minutes of "okay what's a password I haven't used before that I'll still remember" that this used to take me.
I get why people don't do it. Handing every password you own to one piece of software feels like exactly the wrong move the week a company just got broken into. But the math still works out in your favor, because the alternative is what most people are actually doing, which is reusing three or four passwords everywhere with minor variations, and that's so much worse. If your Evernote password and your bank password share a root, one breach becomes two problems instead of one.
Also, minor tangent, but am I the only one who finds these "we take security very seriously" statements companies put out kind of funny? Every breach notice reads like it was run through the same template. I don't blame the PR and support people writing them, that's just what you say. But somewhere there should be a version that just says "yeah, this happened, it's bad, here's what we're doing about it" without the corporate throat-clearing first.
Anyway. New password's in the vault, notebooks are safe as far as I can tell, and I've got SXSW Interactive kicking off down in Austin as of yesterday, which means my Twitter feed is about to be unusable for the next several days with people live-tweeting panels I'll never watch. Different post, probably, once I see what actually comes out of it this year beyond another app nobody uses past April.