The definition of a symmetric cipher requires the cipher text to be (practically) indistinguishable from random. Length is not particularly useful (multiple blocks, different block ciphers with equal block length).
Lots of developers who read "Learn PHP in 24 Hours" and similar texts use md5 (32 chars) or sha1 (40 chars). If you're an attacker and see a hex string that's 40 chars long, that gives you a great place to start since you know it's likely to be a naïve SHA1 hash.
If Evernote is not using a key derivation function, I don't know what to say.