Home > What Was Your First Pet's Name? Lessons Learned About E-Mail Security

Security Focus

What Was Your First Pet's Name? Lessons Learned About E-Mail Security

10/10/2008

Last month a hacker gained access to Vice Presidential candidate Sarah Palin's personal e-mail account, gov.palin@yahoo.com. (Earlier Palin had refused to release the e-mail under a public records request.) Initial reports credited the attack to an anti-Scientology group, but, as the story evolved, that was debunked, and things now point to an individual acting alone. A detailed description of the complex claims and counter-claims can be found in Michelle Malkin's blog.

The FBI and Secret Service were quick to take action, seeking copies of the documents from the Associated Press (which refused) rather than Googling for the multiple sites that had them online. (I downloaded my copies from Wikileaks.) A Federal grand jury has indicted a Tennessee student for "intentionally accessing without authorization" Governor Palin's e-mail account.

The person claiming to be the hacker didn't use sophisticated techniques; he just made use of the password reset feature. Something any regular e-mail user could do. He claims he went to Palin's account, said that he had forgotten the password, and invoked the password reset feature. The only information he needed was her birthdate, zip code, and answer to the security question, where she met her spouse--which she had answered in front of several million people at the Republican convention.

That's how easy it was. No rocket science here. I remember being asked in the 1980s, when e-mail was just becoming widespread, "How do you know someone else isn't reading my mail." My answer was, "You don't." My advice then was simple: "Don't put anything in e-mail that you wouldn't want to be made public."

The Rest of the Story
The whole episode has a number of interesting side stories. One is that shortly after the hack, Bill O'Reilly on Fox News characterized the sites that posted some of the contents as "despicable, slimy, scummy Web sites" and asked "why can't they go there tonight to the guy's house who runs it, put him in cuffs and take him down and book him?" In retaliation another group hacked O'Rielly's Web site and obtained a list of subscribers and their passwords and released 20 of them to Wikileaks.org, a site for whistleblowers and hackers to leak documents.

Another side story is what the hacker found, or perhaps more importantly, what he didn't find. After sending excerpts from Palin's e-mail account to sites such as Wikileaks, the individual who claims the hack said that he deleted the contents from his own computer because of legal concerns. He has also posted "I read though the e-mails... ALL OF THEM... before I posted, and what I concluded was anticlimactic, there was nothing there, nothing incriminating, nothing that would derail her campaign as I had hoped, all I saw was personal stuff, some clerical stuff from when she was governor.... And pictures of her family." Since Palin's Yahoo e-mail account has been taken down, there is no way to verify the accuracy of his claim.



Recommended Reading
  • UNLV Hospitality Students Learn on Micros Opera

    The William F. Harrah College of Hotel Administration at the University of Nevada, Las Vegas (UNLV) has received a donation from Micros Systems that will allow the college's students to use its Opera hospitality software in classes.

  • Cambridge Reduces Support Needs in Move to New Wireless System

    The University of Cambridge is deploying Aruba Networks' wireless LAN equipment to replace a legacy network that had become unmanageable and a drain on resources. Since early 2008, about 100 Aruba AP-65 access points have been deployed, along with dual MMC-6000 Multi-Service Mobility Controllers.

  • iKnow Social Learning Platform Expands Language Support

    Cerego has released new content creation tools for its iKnow social learning platform, adding support for creating learning modules in any of 188 languages. The company has also expanded language support for the text-to-speech technology used in the iKnow platform.

  • Smart Debuts Updated Whiteboard Lineup

    Smart Technologies last week unveiled updates to its Smart Board 600i interactive whiteboard system. The new lineup includes both a standard 4:3 and a widescreen 16:10 model, each featuring new boom-mounted, short-throw projectors.

  • SUNY's Binghamton Monitors Network with Lancope's StealthWatch

    Binghamton University, part of the State University of New York (SUNY) system, is using StealthWatch from Lancope to help streamline network management, control, and security with visibility of network behavior. Binghamton has an IT network that spans 20,000 client endpoints and six geographic locations. After contending with worm propagation and other security threats that affected network performance, the university's network management team sought a way to increase visibility of network traffic and analyze network behavior for potential threats.

  • Tufts Grants Rights for Mileage-Increasing Transportation Technology to Electric Truck

    Tufts University has optioned rights to a technology that can recharge the batteries of any hybrid electric and electric-powered vehicle while it is driven. The Tufts-developed technology could increase by 20 percent to 70 percent the miles per gallon or total driving range performance of vehicles like the Honda Civic, Ford Escape, and Toyota Prius hybrids and the Tesla Motors and Phoenix Motorcars electric vehicles.