Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Third -- How was the system breached?

Dunno, I just went and quickly braved 4chan (I know... I feel so dirty) to see if anyone was linking anything. They had some rapidshare links up (a 1.4 mb and 1.1mb one).

Am grabbing now just to see what they are... I'm curious if there is anymore info on this.



It was a straighforward dictionary hack--her password was "popcorn".


No, it wasn't. "popcorn" is the password after the reset that was posted on /b/. If you look at the screenshots, you'll see that her password was reset using the "Forgot Your ID or Password?" feature.

To reset a Yahoo! Mail password, you need the person's birthdate, zip code, and answer to their "secret question". That information is easily accessible for public figures like Palin. Try it sometime with your friend's email/screenname and Facebook; it's quite easy.


If that's true, I think it's very interesting. I wonder if the security community will step up and take advantage of this opportunity to discuss the inherent security issues with the "secret question" method of account recovery.


Bruce Schneier's one of the more prominent security writers around, and he covered that one over three years ago: http://www.schneier.com/blog/archives/2005/02/the_curse_of_t...

Where I work, all webmail is blocked, so the IA department is grateful to Palin for the object lesson supporting the policy.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: