Palin Email Hacker Found
mortonda writes to tell us that the person responsible for breaching Sarah Palin's private email account has been found. We discussed the breach last Wednesday, shortly before the hacker, a University of Tennessee-Knoxville student, posted a message detailing his methods. Wired has a story examining the potential legal consequences for the hacker.
Cracker is an idiot. Ever hear of Tor? Or better yet, post the information on something like Freenet and just advertise it on Freenet somehow and let other people get the information out to the main web.
Of course, the fact that he posted his nick on /b/ when it's usually forced-anon anyway means he basically confessed. Not to mention that he said which proxy service he used -- note to criminals: if you want to get away with something, don't brag about how you did it!
It's better to vote for what you want and not get it than to vote for what you don't want and get it.
- E. Debs
There's no evidence that we know of that this kid was indeed the hacker other than a post on /b/. And accepting a post on /b/ to be reliable information is like... trusting /.'s front page.
It is usually the easiest way for a lot of systems; that, or just ask the user and they will tell you.
If you have followed the story, he didn't guess the password. He used publicly available information to fool Yahoo's password recovery tool to give it up.
As simple as it may sound, it is a bit more involved than 'guessing' a password.
Not even password guessing. He apparently took public information about her and reset the password.
If anyone wondered if demanding date of birth, home town, etc. was a BAD way of determining identity, this should resolve that for them.
The preferred solution is to not have a problem.
If he's a student, I hope Palin opts not to press charges, or pushes for a slap-on-the-wrist. Some kind of punishment that will sting, but won't be career ending.
No, they are *already* useless for private communication. Email is sent in plaintext across networks, and regardless of prosecution, the attack vector used here is a pretty easy one. If your email is unencrypted, or you're using easily looked-up information as passwords or recovery questions, then it's not private. period.
It would almost be better not to prosecute at all, if it has the effect of making people aware of, and take precautions against, the complete lack of privacy already extant.
Can you be Even More Awesome?!
Why is Sarah Palin using a private account when she is Governor?
Because there are laws in place that say what you can and cannot do with government services and equipment. What you do not seem to get is she was abiding by these laws. Thats why she has 2 (or more) email accounts. The hacker ought to be prosecuted, he even said he did it with malicious intent
I really wanted to get something incriminating which I was sure there would be
but guess what? he found squat and diddly.
I read though the emails... ALL OF THEM... before I posted, and what I concluded was anticlimactic, there was nothing there, nothing incriminating, nothing that would derail her campaign as I had hoped, all I saw was personal stuff, some clerical stuff from when she was governor.... And pictures of her family
Bad Panda! No Bamboo for you! In matters of importance ACs will not be responded to. Want to say something critical,OK
1) Buy cheap pc using cash (OLPC or similar)
2) Find open wifi network, choose a place far from where you live
3) Connect to TOR and do your dirty deeds
4) Clean finger prints from PC and trash it, far from where you live
OR
1) Goto internet cafe, ensure cafe has no security cameras
2) Pay with cash
3) Connect to TOR and do your dirty deeds
4) Clean finger prints from computer
Profit?
First, it wasn't password guessing. He exploited Yahoo's password recovery system to get it to reset her password. He basically used public information to pose as Palin and convince Yahoo's password recovery system that he needed the password reset. Exploiting such a weakness in the system is, by any standards, "hacking".
Second, after he got in, he than went through all of her e-mail. Breaking into a system, even if it had been a password guess, and then going through its contents is again, by any standard standard, hacking.
I loath Palin, but this guy is going to get what he has coming. Even shitty and crazy humans who think the world is a few thousand years old and much to my horror might be president one day, get legal protection. It isn't like the police can go, "Yeah, he hacked in, but Palin kinda sucks, so I think we will let this one slide".
You're posting here, using racist codespeak (Bubba?), advocating for the physical and/or sexual abuse of someone who hacked a Yahoo account?
Fucking fascist.
- The Big Lebowski
If you have followed the story, he didn't guess the password. He used publicly available information to fool Yahoo's password recovery tool to give it up.
And somehow that turned into headlines that say:
Palin Email Hacker Impersonated Her, Stole Password
http://www.google.com/search?q=palin+impersonated
Even the Associated Press went down that road.
[Fuck Beta]
o0t!
A number of those emails seem to be very state-businessy looking at who they are all from. And apparently they were using those accounts in order to have the ability to quickly delete any email they wanted rather than be subject to maintaining them for FOIA requests.
It is no longer uncommon to be uncommon.
Yeah, just like the punishment to the Watergate burglars was the same as that meted out to regular burglars.
Fact is bugging your political opponents is Serious Business legally.
echo -e 'global _start\n _start:\n mov eax, 2\n int 80h\n jmp _start' > a.asm; nasm a.asm -f elf; ld a.o -o a;
Why is Sarah Palin using a private account when she is Governor?
Because there are laws in place that say what you can and cannot do with government services and equipment. What you do not seem to get is she was abiding by these laws. Thats why she has 2 (or more) email accounts. The hacker ought to be prosecuted, he even said he did it with malicious intent
That's not why she uses personal e-mail accounts for state business.
Interviews show that Ms. Palin runs an administration that puts a premium on loyalty and secrecy. The governor and her top officials sometimes use personal e-mail accounts for state business; dozens of e-mail messages obtained by The New York Times show that her staff members studied whether that could allow them to circumvent subpoenas seeking public records.
Like the GOP staff that used an exploit to read their oppositions email? Hmm, there were no legal consequences in that case. Maybe there should have been? Report Finds Republican Aides Spied On Democrats http://query.nytimes.com/gst/fullpage.html?res=9F00E0D7103FF936A35750C0A9629C8B63
http://voices.washingtonpost.com/the-trail/2008/09/17/palins_yahoo_account_hacked.html
Among the e-mails released as part of the records request in June were several from Frye asking a state official whether private e-mail accounts and messages sent to BlackBerry devices are immune to subpoena, then reporting the answer to the governor and her husband, Todd, who also uses a Yahoo! mail address.
Asking if Yahoo accounts are subject to subpoena and relaying the answer to the governor suggests to me that the accounts were not simple private email accounts.
As for the hacker, hopefully the Feds will give him a nice long stay in a real PMITA prison with a guy named Bubba.
Your post was great until you said this. People should be punished according to sentences under the law, not subjected to the arbitrary abuse of other prisoners.
Social scientists are inspired by theories; scientists are humbled by facts.
Most of the newsbits explicitly mention that "Governor Palin has come under media criticism in the past week for using private email accounts to avoid Alaskan freedom of information laws." Neither of you seem to have even read the original story?!
Often wrong but never in doubt.
I am Jack9.
Everyone knows me.
Let's say that hypothetically, she was discussing government business on a Yahoo! account. One later crime committed against her does not mean she gets a pass on her own. Plus, she might be Vice President. Hell, maybe even President. So it does matter a bit more than what some punk does.
Actually she was using her yahoo email accounts to conduct state business.
The best education consists in immunizing people against systematic attempts at education. - Paul Feyerabend
What I've seen here is that Palin properly followed the demarcation line between "official business" which is done via official state systems, and "private communications" which may NOT be done via state systems.
Then you've seen only what you've wanted to see. Palin thoughout her time in office has consistently blurred the official with the personal.
For starters, if she wished to keep the line clearly marked, she should have chosen an email handle other than gov.sarah.
Then there's this from the New York Times:
While Ms. Palin took office promising a more open government, her administration has battled to keep information secret. Her inner circle discussed the benefit of using private e-mail addresses. An assistant told her it appeared that such e-mail messages sent to a private address on a "personal device" like a BlackBerry "would be confidential and not subject to subpoena."
Ms. Palin and aides use their private e-mail addresses for state business. A campaign spokesman said the governor copied e-mail messages to her state account "when there was significant state business."
On Feb. 7, Frank Bailey, a high-level aide, wrote to Ms. Palin's state e-mail address to discuss appointments. Another aide fired back: "Frank, this is not the governor's personal account."
Mr. Bailey responded: "Whoops~!"
Whoops, indeed. I wouldn't consider this a distraction from the issues, especially given the Bush Administration's record. I find it among the scariest aspects of her prospective election.
The Times article:
http://www.nytimes.com/2008/09/14/us/politics/14palin.html?pagewanted=all
Innovation makes enemies of all those who prospered under the old regime... -- Machiavelli
Please have the courtesy of reserving judgement (sic) until such a time all the facts are in
Request denied. Slashdot is not a court of law, and judgments and opinions expressed by its membership are not binding on anyone. As such they may be made and expressed with too few, just the right amount, or too many facts.
I am not a crackpot.
Heh.
The best education consists in immunizing people against systematic attempts at education. - Paul Feyerabend
I can't believe this shit is modded insightful. The judge even admonished the Palins for trying to destroy this guys life. Most of the claims are pretty much hearsay, and at least two of them you cite have been explained. Wooten may not be a great guy, but the shit her family has spewed is a gross over exaggeration. All of her claims of "being tough on corruption" are bullshit. She took tons of money from the bridge to nowhere project. McCain HIMSELF even called her projects out specifically when he was attacking pork spending (wonder why the sudden change of heart...God damned sellout used to have at least some ethics and purpose). She has a tremendous history of abuse of power with this, her dear ol "shadow governor" hubby who seems terribly involved in state business, and then there is the numerous other cases of her firing everyone in her path that didn't do her bidding. She is right in line with the Bush/Cheney method of 0 accountability, above the law, I do what I want style government.
Then there is the issue of her being against teaching evolution. Or the issue of her refusing to fund sex ed classes and demanding abstinance only education (I bet her daughter would have prefered to know how to use a condom about now). We also have her silly "ebay" jet crap...which didn't sell on ebay and was prompty sold to another of her Republican cohorts in a no bid sale for less than market value.
That crazy double talking bitch has no place in our government. And for all you who think Obama's minister was a wackjob, you should check out Palin's. I think the crap Obama's pastor said was pretty bad, but chasing witches out of town just takes the fucking cake.
It is on the news because she is a stark raving mad, clueless, and evil bitch of a woman who will do anything to get her way and dodge any kind of accountability. To include the SAME GOD DAMNED STUNT that this administration pulled by illegally outsourcing emails on government business to avoid the archival requirements. All of this from the party that expects me to believe "if you have done nothing wrong you have nothing to hide" applies to everyone but them.
The only change I can believe in is what I find in my couch cushions.