Yahoo, Hotmail, Gmail all vulnerable to Palin-style password-reset hack
Tactic used to access VP candidate's e-mail works on the top three services
Computerworld - Yahoo Mail isn't the only Web-based mail service that could be duped into giving up someone else's account password, the tactic that some have argued was used to break into Gov. Sarah Palin's e-mail earlier this week.
Google Inc.'s Gmail, Microsoft Corp.'s Windows Live Hotmail and Yahoo Inc.'s Mail all rely on automated password-reset mechanisms that can be abused by anyone who knows the username associated with an account and an answer to a single security question, according to quick tests run by Computerworld.
Computerworld reporters and editors were able to "break" into their own and colleagues' accounts on all three services, then reset passwords armed only with the account's username and the correct response to one of a limited number of common security questions, such as mother's maiden name, the name of a favorite pet or the make of a first car.
Some of the personal information that would provide answers to the security questions may be easily found by searching social networking sites or the Internet, the approach a hacker labeled as "rubico" claimed to have used to dig up the responses necessary to access Palin's account.
Hackers who know the username of an account -- which is often identical to the part of the e-mail address that precedes the "@" symbol -- and correctly type the distorted "CAPTCHA" characters are faced with only a security question before being allowed to change the account password. (CAPTCHA, or "Completely Automated Public Turing Test to Tell Computers and Humans Apart," is the name for the security tool that uses distorted, scrambled characters to stymie automated bots.)
None of the services required that the new password be sent to an alternate e-mail address -- although that was an option for all three -- and instead offered an all-online process.
Adam O'Donnell, director of emerging technologies at message security vendor Cloudmark Inc., said that automated password-reset is the rule in Web-based mail, whether the service is free, like Yahoo, Hotmail and Gmail, or offered as part of the monthly fee by one's Internet service provider.
"ISPs have razor-thin margins, and one call to the help desk to reset a password would wipe out the month's profit on that user," said O'Donnell in an interview yesterday.
At the time, although other security experts were skeptical of the hacker's claim to have accessed Palin's account through a password-reset, O'Donnell had said it sounded "very plausible."
According to rubico, who some have speculated is the 20-year-old son of a Tennessee state legislator, the online research needed to reset Palin's password took just 45 minutes.
Palin e-mail hack
- Yahoo, Hotmail, Gmail all vulnerable to Palin-style password-reset hack
- Report: Tenn. legislator confirms son is at center of Palin hack chatter
- Web proxy firm working with FBI to trace Palin e-mail hacker
- IT Blogwatch: Sarah Palin e-mail hacker drops anchor, arrr!
- Security researchers ponder possible Palin hacks
- Update: Hackers claim to break into Palin's Yahoo Mail account
- Sharon Machlis: Yahoo users: Like Sarah Palin, you may be vulnerable to an e-mail hack
- Douglas Schweitzer: How safe is your e-mail correspondence?
- Global News Update: Thursday, September 18, 2008
Read more about Networking in Computerworld's Networking Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Digital Transformation: Creating New Business Models Where Digital Meets Physical
- Individuals and businesses alike are embracing the digital revolution. Social networks and digital devices are being used to engage government, businesses and civil...
- Make the Connection: Better Network Connectivity Drives Transformation
- Network connectivity is more than just plumbing. Leading organizations today see high-performance network connectivity as a critical enabler of competitive advantage, and not...
- Virtualizing Government Infrastructure
- All server virtualization solutions are not created equal. The more-with-less agenda for government agencies is tailor-made for server virtualization, which is evolving into...
- Moving Service Management to SaaS
- Today, organizations can enjoy similarly substantial benefi ts by migrating their IT service management functions to a software-as-a-service model. This paper shows how...
- Achieving 360 Degree Network Visibility with Nimsoft
- 360° network visibility is critical for ensuring continuous availability of networks, servers, and applications-anything less could
have costly bottom-line implications.
All Networking White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Unified Communications 101
- What's the best way to implement a unified communications solution for your organization?
- Try the OptiView® XG on your network - FREE
- The OptiView® XG is the first dedicated tablet with automated network and application analysis -- fastest way to root cause. XG raises the...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and... All Networking Webcasts