Lessons Learned from The Sarah Palin Email Hack

CYBERSPACE — The hack of GOP vice-presidential nominee Sarah Palin's email provides a lesson to computer users everywhere: common password protection isn't that great.

The hacker claiming to be behind the email invasion posted on the Internet message board 4Chan.org explained how he retrieved Palin's password information. It sounded all too easy.

First, the hacker used the password retrieval function associated with Palin's Yahoo account and answered two security questions: The governor's birthday and her home ZIP code, both of which he said he was able to find through simple Google searches.

After that, the hacker encountered a more challenging security question: Where did the governor meet her husband?

But once again, a trip to YouTube or some other video-sharing site was all the hacker needed. Gov. Palin herself recounted during her acceptance speech at the Republican national convention that she met her husband at Wasilla, Alaska, High School.

What does this mean for the rest of us? Roger A. Grimes, a security expert who writes for InfoWorld.com, said that no amount of good programming can make up for lousy security questions.

"If your password reset feature is weak (and most are), then the security of your account has nothing to do with anything else besides those few questions," he said.

"It doesn't matter how good the vendor's other security features are, it doesn't matter how long and complex your password is, it doesn't matter how secure their coding is and whether they use SDL programming,” Grimes added. “All that matters is how common the questions and answers are.

What's the solution? One possible answer is to treat every security question like another password field.

"When they ask you for your dog's name, say something like 'Im5n$?aTuy' and put that for all your password reset answers," Grimes said.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Sen. Mike Lee Renews Push for Federal AV Legislation

Republican Sen. Mike Lee of Utah on Wednesday reintroduced a federal age verification bill that has twice previously failed to make it through Congress.

South Dakota Governor Signs AV Law With Criminal Charges

South Dakota Governor Larry Rhoden has signed into law a bill imposing criminal charges on sites that fail to perform age verification of users when providing access to adult content.

UK Pornography Review Recommends Banning 'Extreme' Content

The “pornography review” initiated under the conservative government of former U.K. Prime Minister Rishi Sunak is soon expected to present its recommendations, which according to a BBC report will include banning any adult content deemed “degrading, violent and misogynistic.”

Malaysian Government Urges Tech Companies to Continue Porn Crackdown

Communications Minister Fahmi Fadzil has asked all social media and online messaging platforms with at least 8 million users to register as application service providers beginning this year, in an effort to monitor and prevent pornography on such sites.

SceneLocker Extends Closed Beta Test for Creators

Content creator cloud storage company SceneLocker has extended its closed beta test.

Ms. Magazine Exposes Anti-LGBTQ+ Effects of AV Laws

Ms. magazine on Tuesday published an article examining how state age verification laws, promoted as a way to protect children online, are being used to censor LGBTQ+ and abortion-related content.

Zuzana Designs Marks 20-Year Anniversary

Web design and marketing firm Zuzana Designs is celebrating its 20th anniversary.

Nikki Sequoia Launches New Fetish Site Through Grooby's Blue.xxx

Content creator Nikki Sequoia has launched her new membership site, NikkisFetishes.com, through Grooby's website management company Blue.xxx.

LukeCooperX Launches Through YourPaysitePartner

Creator Luke Cooper’s new paysite LukeCooperX has launched through YourPaysitePartner (YPP).

Martin Spell Launches New Paysite

Performer Martin Spell has launched a new membership site through MyMember.site.

Show More