Encrypting Evernote with Mailvelope #openpgp #encryption #privacy

Image Source: http://goo.gl/x0hsp

A few weeks ago, I bemoaned the fact that Evernote–free or Premium–lacked built-in support for GPG public/private key encryption. Although many have shared that Evernote offers many encryption/privacy options for the notes, the truth is, some may not be satisfied with that.

This blog entry explores using a Chrome browser add-on–Mailvelope–to encrypt Evernote notes with your OpenPGP/GPG public key. A few quick warnings:

  1. Encrypt data in Evernote with this approach, you won’t be able to search it.
  2. Chances are, you won’t be able to decrypt it on anything short of a full computer with all the right software loaded (e.g. Chrome, Mailvelope, Evernote). I imagine some Android apps could do this.
  3. File attachments won’t be encrypted. You might as well encrypt them by compressing them with 7z AES-256 encryption (e.g. Keka on Mac, 7z on Windows).
  4. None of this happens automatically. Simply, don’t put anything into Evernote unencrypted (it’s so easy to make that mistake these days).
  5. Think of something else? Leave a note in the comments.

Here’s a quick overview–from Mailvelope–on public keys.

OpenPGP and therefore Mailvelope uses public-key cryptography which means a key is split up in two parts:public and private key with different purposes:
  • public key: used to encrypt a message. Can and should be available to everybody.
  • private key: used to decrypt a message. Needs to be stored securely. Access is restricted by password.

This concept is explained on the page “How Gpg4win works” in an illustrative way.

Ok, now that you’re an expert, how do you use Mailvelope to accomplish this? Take these steps:

1) Create–or use your existing one–your public key for Mailvelope; Mailvelope allows you to do this in the Chrome add-on, which is nice. You’ll encrypt content to yourself that will be saved in Evernote.

Be sure to use a secure password…you can generate one with this tool.

2) Install the Mailvelope Chrome add-on (they’re working on a Firefox version)

3) Import your public key into Mailvelope so you can start encrypting your webmail (e.g. Gmail, Yahoo, Hotmail), as well as other web sites (like Evernote Notes) that you add.

4) While viewing an Evernote Note, switch to full-screen view and ADD that Page…

This will allow you to see the gold padlock that indicates Mailvelope is available to encrypt the contents of your Evernote Note, as shown below:

Note the full-screen view of the “Untitled” note where I have some gibberish typed in…on the far right side of the screen, you’ll see the gold padlock indicating that Mailvelope is ready to encrypt content.

When you click on the padlock, you will begin the process of encrypting the data:

Once your Evernote Note has been encrypted, you can click on DONE in the top right hand corner. This will save your encrypted note in Evernote.

The process is quite fast.

Well, thanks for joining me on this quick exploration! I had fun writing it and I hope you’ll have fun giving it a try! Encryption is everyone’s concern.

Everything posted on Miguel Guhlin’s blogs/wikis are his personal opinion and do not necessarily represent the views of his employer(s) or its clients. Read Full Disclosure

var _gaq = _gaq || []; _gaq.push([‘_setAccount’, ‘UA-3445626-5’]); _gaq.push([‘_setDomainName’, ‘mguhlin.org’]); _gaq.push([‘_trackPageview’]); (function() { var ga = document.createElement(‘script’); ga.type = ‘text/javascript’; ga.async = true; ga.src = (‘https:’ == document.location.protocol ? ‘https://ssl’ : ‘http://www’) + ‘.google-analytics.com/ga.js’; var s = document.getElementsByTagName(‘script’)[0]; s.parentNode.insertBefore(ga, s); })();

2 thoughts on “Encrypting Evernote with Mailvelope #openpgp #encryption #privacy

  1. Matthias Heil January 29, 2013 at 3:46 am Reply

    How interesting, and good that this can be done if/when required. The thought of deliberately adding notes that are not searchable, however, ….bewilders me!-)

  2. Ed Salter November 10, 2014 at 8:51 am Reply

    Would it be possible to search the notesd if I would let the Title and the Subject unencrypted (like email)?

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

%d bloggers like this: