The tens of millions of people who use Web-based e-mail clients probably sweated some bullets when Alaska Gov. Sarah Palin’s Yahoo e-mail account was compromised and its contents leaked onto the Web.
If they didn’t, they should have.
That’s because Palin’s account wasn’t so much “hacked” (hacking generally takes some computing skill) as much as it just had the screen door jimmied open. That’s because the security in place on Web-based e-mail is woefully low.
In the Palin case, all the “hacker” did was use Yahoo’s helpful “Password Recovery” feature that is used when people forget their password. That process required the hacker to enter Palin’s login name (which was generally known from earlier stories critical of her use of Yahoo e-mail), date of birth and home ZIP code. The last thing that kept her account locked was the answer to the question, “Where did you meet your spouse?”
The kid who boasted of the hack on a Web forum, and is now presumably seeing the business-end of Secret Service German shepherds, said the whole process took 10 minutes, since Palin had discussed meeting her husband, Todd, in high school. He typed in “Wasilla High,” and he was in.
The final question in most of these sites, including Yahoo, is user-selectable. I always encourage my readers to pick the same question every time on these sites and make the answer something nonsense and something only they would know. So if the question is “What is the name of your first pet” and you always answer “Sophia Loren” (assuming you have never had a pet named after the Italian bombshell) you’re likely safer than if you answer “Spot” or “Rover.” And never, ever, use your mother’s maiden name.
I also use a random ZIP code when I sign up for these sites. One, I don’t want sites…