Sarah Palin’s E-Mail Hacked With Simple Social Engineering
By Eric Blair
15:17, September 19th 2008
29 votes
Vote this story
Sarah Palin’s E-Mail Hacked With Simple Social Engineering

A 20-year old college student from Tennessee, so far known only by his alias “Rubico” and who claims to be the hacker who broke into presidential running mate Sarah Palin’s e-mail account and published screenshots of her Inbox online, posted a first-person account of how he did it on the 4chan.org forums. If true, the answer is embarrassingly simple:

Rubico says he cracked Palin's account in just under 45 minutes using only the Yahoo password recovery form, and simple web searching. Yahoo, like many other free web mail services today, has the feature of helping a user who has forgotten their password to recover it by giving the answers to a series of questions, answers who only the user is supposedly privy to.

Nevertheless it was a matter of 15 seconds for Rubico to look up Palin’s birthday on Wikipedia and a few minutes to use the U.S. postal service website to find out the only two zip codes in Wasilla, Alaska. The only part that gave the young “hacker” any amount of trouble was the answer to the question of where Palin had met her husband. Looking up publicly available biographical information about Palin, Rubico was able to find out that she and her future husband had eloped after college, and further research yielded that they had met in high school. A few combinations of words later the correct answer, “Wasilla High” was entered. Rubico then reset the Alaska governor’s password to “popcorn” and entered the account.

The simple manner by which Gov. Palin’s account was broken into highlights the inherent weakness of such security systems, considering how most web-mail services and other websites have the option of letting the users retrieve forgotten account data by way of such ‘security questions’.

Rubico says he found "nothing incriminating, nothing that would derail her campaign as I had hoped. All I saw was personal stuff, some clerical stuff from when she was governor… and pictures of her family." Even so, one can notice the irony inherent here:

Before her account was hacked, Governor Palin had come under criticism for the use of private e-mail addresses to conduct state business, an act forbidden by law. Even though the account was broken into to find illicit activities Palin may have hidden from the public, the hack has managed to highlight another reason for which that law was put into effect: such personal e-mail addresses are unsafe and relatively easy to break in to, as amply demonstrated.

If you’re a state official and you carelessly expose sensitive information, you jeopardize the state. Let’s not forget what happened in 2000 with then-CIA director John M. Deutch, when he was discovered to have been accessing his CIA e-mail account from home; if any state secrets have been leaked by his recklessness, it was impossible to trace.



© 2007 - 2008 - eFluxMedia
dotclear

Other News in

Bush Encourages Cooperation At APEC Summit

Bush Encourages Cooperation At APEC Summit

U.S. President George W. Bush, Chinese President Hu Jintao, Japanese Prime Minister Taro Aso and other members of the 21-nation Asia-Pacific Economic Cooperation group, or APEC pledged on Saturday to...

Tibetan exiles end meeting with call for more vigorous action

New Delhi - Tibetan exiles ended a crucial meeting on their future in the northern Indian town of Dharamsala on Saturday agreeing that a firmer stand in dealings with China was needed, delegates...

Attacks, bombing leave nine Afghan civilians, 14 insurgents dead

Kabul - US-led coalition forces killed one civilian and 14 insurgents in southern and western Afghanistan while two children were killed by a roadside bomb and six civilians died in an attack on a...

French Socialists vote - and it's Sarkozy who wins

Paris - The French Socialists just spent two days voting for a new leader, and the big winner was - President Nicolas Sarkozy. The conservative Sarkozy is certain to be strenghened by the bad...

US drone strike reportedly kills British terror suspect

Islamabad - A suspected US pilotless aircraft on Saturday targeted a militant hideout in Pakistan's restive tribal region along the border with Afghanistan, killing four people and injuring six,...

dotclear
Latest videos in World
Mass protest against arrest
Nepal protests after murders
Thai protest site blast kills...
Sailors prefer pirates to no...
EU revamps farm subsidies

dotclear
World You are here: World
» World   » Business   » U.S.   
E-mail To A Friend Print RSS Text size: Decrease font size Increase font size
dotclear
dotclear
dotclear
Most Popular in World
Fla. 19-Year Old Student Kills Self In Front Of Live Webcam

» read full story
dotclear

Interested In This Topic?

News Alert will keep you informed. Find out more.
dotclear
Photos Gallery
dotclear
Today's Latest News
Bush Encourages Cooperation At APEC SummitBush Encourages Cooperation At APEC Summit

» read full story
dotclear