Evernote’s CTO on Your Biggest Security Worries From 3 to 300 Employees
firstround.com
firstround.com
I also find the view that smaller startups should just get a product out the door and neglect security completely abhorrent. Waiting until you're at 10 employees before you start hashing passwords? Are you kidding me? Are we professionals or what?
So based on those observations my confidence in the security of Evernote has decreased substantially. Their philosophy represents much of what's wrong with VC-style startups. Imagine a restaurant saying "just forget about hygiene until you're profitable"!
Being aware of the current best practices in password encryption is part of your job. Checking if your knowledge is still up to date takes 30 minutes, tops. Implementing it in your stack of choice, provided you've made a sane choice to start with, is trivial. Hell, you can probably just cut and paste from one of the articles you've found in the aforementioned 30 minutes.
None of this will slow you down when getting the first alpha release out of the door.
Just look to this [1] example of hot trouble 37signals got themselves in 2 years ago.
[1] http://37signals.com/svn/posts/3078-trust-is-fragile#all_com...
Time to look into alternatives.
- Don't worry about proper password storage until you are at 4-10 employees and have a prototype out the door? No, proper password storage is one of those things you deal with at the very beginning.
- Not worrying about a password safe until 11-30 employees? Using something like keepass, lastpass, etc, is trivial and should be started from day one as well. Your developers should already be in the habit of using one anyway.
- There should be decent password-locking screensavers on all computers. That way a smash-and-grab computer theft only amounts to a $1,500 asset loss, no critical data loss. There is nothing here about hard drive encryption, so a password locking screensaver is going to do nothing to prevent loss of sensitive data in a smash and grab.
I also dislike this attitude, mentioned in the 1-3 employees stage:
And from a security standpoint, you shouldn’t be doing very much.
In our industry, we keep on complaining about horribly poor security practices all over the internet. Attitudes like that just persist the poor state of affairs.
And the irony about Evernote being hacked (http://evernote.com/corp/news/password_reset.php)... I'm surprised they were even able to find the compromise and prepare a coordinated response. Who knows, maybe this event is what caused the CTO to see the light? Learn from other's mistakes, people.
I mean, enforcing HTTPS is easy and elementary, but maybe they didn't have time? Or something.
If you search HN, there has been previous discussion about Evernote's lack of security across many areas.
Other than that, I don't care either way about the company.
> If anyone in Silicon Valley knows the value of secure access and keeping information safe, it’s him.
I can think of, I don't know, 30 people at the top of my head that I would rather be listening to. If you caught me in a drunken stupor I could probably still give you 10-15 of them.
That said, there's nothing really wrong with the article, but it's also pretty basic. Putting stuff behind VPN and installing antivirus can help you, but it's not anywhere near enough if you're actually exposed.
Is it? I just save the password in the browser. Computers are not fooled by logos and pretty pages, the manager won't fill in the password on a fake site.
http://contagiodump.blogspot.com/2011/06/may-31-cve-2010-333...
Think about the human element in that for a minute...
However security should be baked into everything one does. Also using a good modern framework to enforce security and good practices is a quick win.
Password encryption & SQL injection in 2013 should be a thing of the past. It has been brought up so many times in the past you'd think people would make sounds decisions to use solid frameworks and/or best practices to avoid these common security holes.
uhh.... doing IT work for U.S. government seems more like a reason to assume he's not good at his job. #HEALTHCARE.GOV
and are they really inferring that no one in silicon valley knows anything about secure access or keeping information safe? i'm done with the article. dumb.