Posted on 09/18/2008 3:19:45 PM PDT by Night Conservative
The hacker who broke into Republican vice presidential candidate Sarah Palin's Yahoo (NSDQ: YHOO) Mail account appears to have done so by requesting a password reset and answering the challenge questions with the help of Google and Wikipedia.
According to a purported first-person account of the hack posted on 4chan.org, an online forum, "Rubico," the person claiming responsibility, initiated a password change on Palin's account and then supplied the Alaska governor's birthday and her home ZIP code, with the help of "Wikipedia andGoogle (NSDQ: GOOG) to find the info."
That left the so-called security question: "Where did you meet your spouse?"
After further Internet searching, "Rubico" entered "Wasilla High" and was allowed to change the account's password.
Though the posted account is no longer available, it has been republished on Michelle Malkin's blog, on Wired News, and elsewhere.
The text supposedly authored by "Rubico" was supplied to Malkin by an unidentified individual who claims to have monitored the 4chan board where the discussion took place.
A determination about the authenticity of this information will fall to law enforcement officials and the legal system, if the case gets that far.
The reproduced account of the hack indicates that "Rubico" posted the changed password and screenshots from Palin's in-box to the 4chan forum. After that, others supposedly copied the information and posted it to Wikileaks and elsewhere before moderators could delete it.
According to Wired News, the handle "Rubico" has been linked by bloggers to a college student in Tennessee, whose father is a Democratic state representative.
The Register reports that Gabriel Ramuglia, the operator of the Ctunnel proxy service presumably used by "Rubico," has been contacted by the FBI and plans to provide the agency with his log files. Because one of the screenshots of Palin's Yahoo account shows part of a Ctunnelled URL, the FBI stands a good chance of figuring out the IP address of the person who took that screen shot from Ramuglia's log files.
More over here:
Net proxy may pinpoint Palin email hackers
http://www.theregister.co.uk/2008/09/18/palin_email_investigation/
The lesson is...change your password to something random. It is way safer to have a password so complex you have to tape it under your desk drawer than to have a password anyone could easily figure out.
I hope he shares a cell with Axelrod!
I doubt this slug will get more than a wet noodle across his chops
AND HIS DEMORAT DAD AS WELL! Hopefully right up to the Jackass himself, Obama HUSSEIN!!
He’s more than that - he is the State Chair for the Obama Campaign.
Obama campaign activist illegally hacked Palin’s email system for political reasons.
If Rubico is David Kernell, David, his dad and the Dems in TN are in deep doodoo.
That may be a good lesson, but it doesn’t apply here. He didn’t guess her password. He used the Yahoo “reset password” program, which Yahoo has because people FORGET their passwords. Yahoo asks standard questions, and in this case whoever set up the account gave standard answers.
Most programs at least are smart enough to ask questions like “your favorite pet’s name”. But if you are public figure, even that information might be available.
The lesson here is that if you are going to use a service that will allow a password reset to a non-secure account, make sure the answers you give to the questions are NOT the right answers.
Most things I use that have these resets require that the reset information be sent to an already supplied e-mail. That way someone might reset you, but they can’t get the new password unless they know what your other e-mail account is and hacked it.
My guess is Palin didn’t use this e-mail for anything she was worried about, and never thought it would be a problem getting it stolen.
True, but you miss the point. That hacked did nothave to guess the password. He used the passsword reset features, which ask some pretty standard questions. This information was all public knowledge.
I understand how he got her birthday, zip code, and even figured out her security questions. What I don’t understand is how he figured out her user id to get there in the first place.
(I am ignorant of computer stuff, be kind)
Yep but he is the eksepshin...
most of us’uns in Tennessee dont even war no shoos...
let lone hev compootas...
Gosh we cint tern im on...
No lektrisitee..
Jest oyl lamps..
But y’all c’mon see us’uns now y’heear ???
:)
Don’t you have to log in before you can change a password?
I’ve never heard of a password request change without even logging in first. If that’s the case them Yahoo were idiots to set it up that way.
He probably guessed. Probably tried a bunch of different one's. If he's not employed or in school, he'd have a lot of time on his hands.
He most probably will end up with a sore butt if he becomes the cellmate of AxelROD! Something really stinks in that whole campaign (understatement of the Century!)!!
Read last night that in Indonesia, Osama Bin Ladin has brrn replaced on T-shirts of Muslim Radicals as their Hero with, YEP YOU GUESSED IT!, THE GREAT MESSIAH himself, YEP!, Barry Soetoro alias BARACK HUSSEIN OBAMA whose father was a drunken,polygamist philanderer Nerdowell! Great Choice for a POS! but NOT for a POTUS!!
NOBAMA IN 08!!! NOBAMA IN 08!!!!
Any credibility to the rumor that it is Kernell’s son?
All I’ve seen is the vague reference in the Wired article and this one.
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.