On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

September 20th, 2008

The lessons in Sarah Palin's email adventure

Posted by Paul Murphy @ 12:15 am

Categories: Applications, Enterprise Policy, General

Tags: Password, Yahoo! Inc., Sarah Palin, E-mail, Online Communications, Paul Murphy

Earlier this week a number of electronic media sites published extracts from Sarah Palin’s private Yahoo email files. Because this happened in the United States the sites doing the publishing committed no crime, but the person who stole them from her Yahoo account did.

According to a posting reproduced on pastebin the theft was carried out simply by pretending to have lost the password and then answering the identity questions Yahoo requires before issuing a password reset:

after the password recovery was reenabled, it took seriously 45 mins on wikipedia and google to find the info, Birthday? 15 seconds on wikipedia, zip code? well she had always been from wasilla, and it only has 2 zip codes (thanks online postal service!)

the second was somewhat harder, the question was “where did you meet your spouse?” did some research, and apparently she had eloped with mister palin after college, if you’ll look on some of the screenshits that I took and other fellow anon have so graciously put on photobucket you will see the google search for “palin eloped” or some such in one of the tabs.

I found out later though more research that they met at high school, so I did variations of that, high, high school, eventually hit on “Wasilla high” I promptly changed the password to popcorn and took a cold shower!

And, of course, he did it in the spirit of hyper-partisanship characteristic of the anti-Palin ranters:

I read though the emails, ALL OF THEM, before I posted, and what I concluded was anticlimactic, there was nothing there, nothing incriminating, nothing that would derail her campaign as I had hoped, all I saw was personal stuff, some clerical stuff from when she was governor. And pictures of her family

Earlier it was just some prank to me, I really wanted to get something incriminating which I was sure there would be, just like all of you anon out there that you think there was some missed opportunity of glory, well there WAS NOTHING, I read everything, every little blackberry confirmation, all the pictures, and there was nothing, and it finally set in…

Although there are numerous unproven claims that “rubico” is the 20 year old son of Tennessee state senator Mike Kernel, a democrat and Obama supporter the lesson here goes well beyond politics.

Sarah Palin seems to have followed all the standard security advice: yahoo uses BSD, not Windows, servers; she never accessed her personal email from hotel or other untrustable devices; she used a reasonably good password; and she gave truthful answers to the memory jogging questions companies like Yahoo use to deal with lost passwords. All great - except look what happened: an electronic Watergate reprise in which some guy hoping to score points with her political opponents used Yahoo’s system against it and published her private emails.

So what’s the bottom line? I think there are two different ones. On an industry basis, everybody’s going to have to rethink their password recovery procedures -thus both opening markets for better solutions and raising the cost and hassle factor for dealing with everyone from the Visa Consortium to Twitter.

The second one is both more general and more personal: there’s always someone who hates you or your company, and there’s always a way for that hatred to gain expression - but you can make it harder for the bad guy by recognizing the obvious: the larger and less personal the organization you trust with personal information, the more accessible it becomes and thus the more likely it is that someone will find a way to use that information against you.

Paul MurphyPaul Murphy (a pseudonym) is an IT consultant specializing in Unix and related technologies. See his full profile and disclosure of his industry affiliations.


Email Paul Murphy

Subscribe to Managing L'unix via Email alerts or RSS.

  • Talkback
  • Most Recent of 44 Talkback(s)
Customize the question
Some sites allow you to customize the question so you can use "What was the licence plate on my first car". Since you are supplying both question and answer you are less vulnerable to the attack as described. Why public e-mail sites like Yahoo, G-Mail,& Hotmail don't use this I don't know.... (Read the rest)
Posted by: Oreamnos_americanus Posted on: 09/25/08 You are currently: a Guest | | Terms of Use
This is just the price paid ...  bjbrock | 09/20/08
Exactly  murph_zZDNet Moderator | 09/20/08
what's scary...  Erik Engbrecht | 09/20/08
Definitely will happen at the worst time always!  joemartn | 09/21/08
Excellent point with many ramifications.  Cayble | 09/22/08
RE: The lessons in Sarah Palin's email adventure  kf6emm | 09/20/08
RE: The lessons in Sarah Palin's email adventure  Pantalaimon | 09/20/08
Yes and No  murph_zZDNet Moderator | 09/20/08
Thank you! It was Palin who hacked her own account...  MGP2 | 09/20/08
She did not hack her own site  GuidingLight | 09/22/08
There's a group called Anonymous  Erik Engbrecht | 09/20/08
Agreed (NT)  murph_zZDNet Moderator | 09/20/08
Security questions was always the weakest link  CobraA1 | 09/20/08
Agreed  murph_zZDNet Moderator | 09/20/08
Question...  MGP2 | 09/20/08
Standard advice to people in the public eye  murph_zZDNet Moderator | 09/20/08
You just made my point....  MGP2 | 09/20/08
Tech savvy politicians...  Erik Engbrecht | 09/20/08
John McCain invented the Blackberry  monkeyman1140@... | 09/22/08
Its further proof...  Cayble | 09/22/08
Customize the question  Oreamnos_americanus | 09/25/08
Web services are set up for "average people"  Mark Miller | 09/20/08
Average People  Erik Engbrecht | 09/20/08
Good point  Mark Miller | 09/22/08
People use free web mails to hide identify!  joemartn | 09/21/08
RE: The lessons in Sarah Palin's email adventure  darclew7 | 09/21/08
RE: The lessons in Sarah Palin's email adventure  BandwidthBandit | 09/21/08
Well, no - at least, I think not  murph_zZDNet Moderator | 09/21/08
Well...yes Murph but seriously...  Cayble | 09/22/08
You missed the main lesson  tonymcs@... | 09/21/08
Hah??  Mark Miller | 09/22/08
You have no idea what official business was carried out in her yahoo email  monkeyman1140@... | 09/22/08
guilty as charged!  Mark Miller | 09/22/08
For the Democrat that hacked her email  GuidingLight | 09/22/08
Convenience vs. Security  btidwell | 09/22/08
Palin should not have used Yahoo for official business  monkeyman1140@... | 09/22/08
Umm, you must be a democrat  murph_zZDNet Moderator | 09/22/08
Democrats should speak for themselves  Mark Miller | 09/23/08
Security Questions are perfectly fine  monkeyman1140@... | 09/22/08
Biased?  Roque Mocan | 09/22/08
Of Course!  brble | 09/22/08
Experience is not bias  murph_zZDNet Moderator | 09/22/08
Funny...  Qbt | 09/22/08
Naw---  BALTHOR | 09/22/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc