What’s in your mailbox? That’s a question that may be much easier for a hacker to answer than most people realize, as Alaska governor and Republican vice-presidential nominee Sarah Palin discovered last week.
Six days ago, screen shots of e-mails from Palin’s Yahoo account ([email protected]) were briefly posted to 4chan, a generally anonymous imageboard site. The account of the hack and the accompanying images were quickly pulled from the Web site, but not before the news of the exploit hit the mainstream media.
Identifying a leading suspect in the case did not exactly tax the FBI’s investigative capabilities. The post detailing the exploit was submitted to 4chan by someone using the ID “rubico.” Numerous bloggers (and no doubt, the FBI), noted that the ID resembled a Yahoo e-mail address, “[email protected],” used by University of Tennessee student David Kernell.
In addition, the hacker apparently made relatively little effort to anonymize his or her IP address before attempting to reset Palin’s password. As the hacker wrote in the 4chan post, “yes I was behind a proxy, only one … I panicked.”
The proxy in question was Ctunnel, which reported that the FBI visited to look at its server logs. The owner of Ctunnel declined to identify the IP address the FBI was investigating, but Portfolio.com reported it as owned by Pavlov Media, which provides service to a Knoxville, Tenn., housing complex known as The Commons.
On Sunday, the FBI raided an apartment at The Commons where David Kernell lives and reportedly spent one to two hours taking photographs. While no charges have been filed yet in connection with the illegal access of Palin’s account, a grand jury is scheduled to meet Tuesday.
The ease with which Palin’s account was accessed raises some serious questions about Yahoo’s security mechanisms and the security…