Tag Archive for: critics

Critics: Substandard crypto needlessly puts Evernote accounts at risk

Security experts are criticizing online note-syncing service Evernote, saying the service needlessly put sensitive user data at risk because it employed substandard cryptographic protections when storing passwords on servers and Android handsets.

The scrutiny of Evernote’s security comes two days after Evernote officials disclosed a breach that exposed names, e-mail addresses, and password data for the service’s 50 million end users. Evernote blog posts published over the past few years show that the company protects passwords and sensitive user data with encryption algorithms and schemes that contain known weaknesses. That is prompting criticism that the company’s security team isn’t doing enough to protect its customers in the event that hackers are able to successfully compromise the servers or end-user phones.

The chief complaint involves Evernote’s use of the MD5 cryptographic algorithm to convert user passwords into one-way hashes before storing them in a database. Use of MD5 to store passwords has long been frowned on by security experts because the algorithm is an extremely fast and computationally inexpensive way to convert plaintext such as “password” into a unique string of characters such as “5f4dcc3b5aa765d61d8327deb882cf99.” MD5 makes an attacker’s job of cracking the hashes much easier by allowing billions of guesses per second, even on computers of relatively modest means.

Read 13 remaining paragraphs | Comments


Ars Technica » Technology Lab

Mobile phones now becoming a target for cyber attacks – Monsters and Critics

The biggest threat for PC users in the eyes of the BSI president are botnets, private computers that have been infested with viruses to be remote controlled and misused to attack other computers. That makes it very important to protect your computer …
Read more

Dive on the Titanic – from your computer – Monsters and Critics

Atlanta – Ever since it sank on April 15, 1912, the Titanic has been a source of fascination. The ship’s remains have been explored in countless missions. Now, anyone curious can go to www.expeditiontitanic.com for their own exploration at 3,280 metres …
Read more

Computer expert: Virus set Iran’s nuclear programme back 2 years – Monsters and Critics

Jerusalem – The Stuxnet computer virus has set Tehran’s nuclear programme back by 24 months, an Israeli newspaper reported Wednesday, quoting a top German computer consultant. The malicious software, or malware, reportedly targeted Iran’s nuclear …
Read more