News Blog

News Blog


Hackers hit Palin, expose the dangers of using personal e-mail to conduct business

While it's hard to imagine President Bush, Vice President Cheney or Republican presidential candidate John McCain spending much time on (or even having) a personal e-mail account, the newer generation of politicians are as plugged in as the rest of us. In fact, just how much they use e-mail for official business is fast becoming an issue in this election as the campaigns head into the homestretch.

To wit: hackers broke into the Yahoo! e-mail account of Republican vice presidential nominee Sarah Palin and plastered personal photos, several messages, and Palin's e-mail contact list on a site called Wikileaks.org, the site reports. This is the same site that a federal judge in San Francisco in February wanted to disable to prevent it from continuing to publish confidential information.

Although the hacker (or hackers) have not revealed his/her/their identities (the data was sent anonymously to Wikileaks.org), it's pretty clear the intent was to punish Palin for, as the New York Times reported this weekend, using her Yahoo! e-mail account to conduct state business in Alaska.

McCain campaign manager Rick Davis in a statement called the hack a "shocking invasion of the Governor's privacy," but there's nothing shocking about it at all. Palin's Yahoo! e-mail account is protected by a Yahoo! ID (which is the same as her e-mail address) and a password. If someone were to figure out that combination, they would have full access to all of her Yahoo! e-mails. As writer Herbert Thompson demonstrated last month in a Sciam.com article, "How I Stole Someone's Identity," someone committed to hijacking a person's e-mail account can do so without breaking much of a sweat.

Alaska's state government has an e-mail system for its employees, and there's a reason those employees should use it while on the job. This e-mail is better protected than standard Yahoo! or Google e-mail accounts (visitors to Gov. Palin's official Web site can send her e-mail through a template on the site—they are not given her actual e-mail address). Unless you work for the government, most people probably couldn't even get to the log-on screen to access state employee e-mail accounts. In contrast, anyone can log onto Yahoo! from that company's main site.

Of course, it would be very difficult to keep a skilled hacker from accessing most information (a group of hackers calling themselves the "Greek Security Team" penetrated computer systems inside CERN's Geneva, Switzerland, facility, where the world's biggest particle accelerator is housed). In fact, while I was doing the basic research for this blog post, Wikileaks itself was hacked. When clicking on the link to the latest on the Palin story, I was taken to a page that read: " I NOW HACK THIS WEBSITE! AREN'T YOUR PROUD OF ME, WIKILEAKS. I CAN PLAY YOUR GAME TOO!!!" Is nothing sacred?

(Image courtesy of iStockphoto; Copyright: Alex Slobodkin)

 

Tags: security, e-mail, election, privacy, Palin, hacker
More News Blog: Next: Are you more likely to be politically left or right if you scare easily? Previous: Bleak forecast: Arctic sea ice just misses record melt

6 Comments

Add Comment
View
  1. 1. K. Quatel 04:51 PM 9/18/08

    PERSONAL vs BUSINESS email privacy....? There's virtually zero difference.

    The very announcement that the FBI and Secret Service are "investigating" the Palin personal email account tells you that nothing will be made public. Those agencies almost assuredly already have determined the hack's identity with dozens of extant Carnivore/Packeteer/ Coolminer/ Echelon/Omnivore/Magistrand/Silkworth/Pathfinder style programs. There's no doubt they located said hack in a great deal less time than it took for the composition of this email.

    To Wit: The FBI a very few years ago located (in seconds) a known, highly skilled data recovery specialist in my area (both in Software anf Hardware recovery matters) who had broken his own rules and done some routine finalization work while connected to the internet via a very small local LAN. Big mistake, (as it turned out) he'd recovered data off a laptop hard drive belonging to a Haliburton employee containing records of deep desert Irag wartime encampment, action, location photos, as well as documentation of ongoing contract assignments for a variety of in country activities instigated by Haliburton Co.. Within seconds of the internet connection the FBI was doing a virtual walk through of the LAN this foreign borne (though then naturalized American citizen) was connected to. A number of CMOS and BIOS chips were altered on the LAN and his station had tunneling code laid down on the hard drive the compactness, brevity, and perfection of its assembly might "bring tears" (I was told) to just about any top level code engineer that had the privilege of reading it. He was contacted by the FBI shortly thereafter and within a few days of their "interview" the data recovery specialist "apparently" left town.

    I believe the above to be true because of my close connection to one of the parties involved.

    SO.... it might be wise to asssume any and all traffic you send and receive via the interenet is quite transparent to our national "protectors" , if they wish it to be so. Just a few words for thought in this cautionary tale.... there really is no privacy left in our current technolgical environment and I wish you the very best of luck, if you think otherwise.

    No message is selected
    Click any message to view it in the reading pane. Attachments, pictures, and links from unknown senders are blocked to help protect your privacy and safety.

    To show messages automatically when you select a folder, change your reading pane settings
    1 message is selected
    Mark as safe | Mark as unsafe

    Reply | Report Abuse | Link to this
  2. 2. Job 05:46 PM 9/18/08

    On Slashdot, a user by the name of Stanislav_J had the following insight:

    “When someone does this sort of hacking/eavesdropping/snooping to a government official, it's called "a shocking invasion of...privacy and a violation of law."

    When the government does it to you, it's called the "Patriot Act."”

    Reply | Report Abuse | Link to this
  3. 3. ted.rybak 07:50 PM 9/18/08

    I guess Hillery's and Obama's money to the hackers didn't pay off.. I got a memo from Obama to Hillery, asking where to send the hackers money to hack into Palin's email..... Too bad they wasted 2million for some worthless data. Hell it ain't their money anyway it all the fools that put money into their worthless campaigns. Maybe they should be prosecuted?

    Reply | Report Abuse | Link to this
  4. 4. trim_one 09:17 AM 9/19/08

    Huh . . . hard for some to imagine, perhaps. I will refrain from mentioning army boots and mothers; maybe Scientific American can stay away from politics and stick to science.

    Reply | Report Abuse | Link to this
  5. 5. lowland 11:02 AM 9/19/08

    Everyone so smart call this hacker so dumb.Do we have a sloppy hacker or a smart and devious hacker framing the kid?don't say no or act like you're so smart if you haven't considered it.If the I.P. Addy matches the kid in question yet it still doesnt add up a then programs like netbus or back orifice with a built in wiping routine should be considered. These are common names for a trojan jacker that a hacker can take over your computer use it without you knowing it,then attack others with your computer address.It turns your computer into a proxy..after the deed is done it can erase itself and fill in where it was with random bytes. Anyone can download these programs off the net in a matter of three minutes..Remember M.O.M. (means,opportunity,& motive)Who really has all three? Palin...Let us not forget the bug Karl Rove found in his Texas office and the WHOLE story behind that!! What, you dont know what Im talking about? Well then just nevermind

    Reply | Report Abuse | Link to this
  6. 6. lowland 11:02 AM 9/19/08

    Barracuda refused to turn over 1100 emails in a F.O.I.A. Stating they are of a personal nature, when they are not. That’s a federal crime. It’s a pre-meditated crime,which to commit the crime of illegally shielding government documents is why she was using the account in the first place. Moreover the Attorney Generals Office of the great state of Alaska just issued an opinion that if government documents are in a private e-mail account,the State has the right to review them, that they must be saved for three years, and that to destroy (delete) them is a crime.In my opinion, Palin or someone in her employment (McCorkell? Having a P.I. Background & couldn’t resist giving herself 2 min. of fame)done this as an excuse to delete and/or discredit the account.I believe the trail will lead back to them if it’s followed in a prudent manner. Everyone so smart call this hacker so dumb.Do we have a sloppy hacker or a smart and devious hacker framing the kid?don't say no or act like you're so smart if you haven't considered it.If the I.P. Addy matches the kid in question yet it still doesn’t add up a then programs like netbus or back orifice with a built in wiping routine should be considered. These are common names for a trojan jacker that a hacker can take over your computer use it without you knowing it,then attack others with your computer address.It turns your computer into a proxy..after the deed is done it can erase itself and fill in where it was with random bytes. Anyone can download these programs off the net in a matter of three minutes..Remember M.O.M. (means,opportunity,& motive)Who really has all three? Palin...Let us not forget the bug Karl Rove found in his Texas office and the WHOLE story behind that!! What, you don’t know what I’m talking about? Well then just nevermind

    Reply | Report Abuse | Link to this
Leave this field empty

Add a Comment

You must sign in or register as a ScientificAmerican.com member to submit a comment.
Click one of the buttons below to register using an existing Social Account.

More from Scientific American

See what we're tweeting about

Scientific American Editors

Tweets could not be retrieved at this time

Free Newsletters


Get the best from Scientific American in your inbox

Solve Innovation Challenges

Powered By: Innocentive

  SA Digital
  SA Digital

Science Jobs of the Week

Email this Article

Hackers hit Palin, expose the dangers of using personal e-mail to conduct business: Scientific American Blog

X
Scientific American MIND iPad

Tap into your MIND

Get Both Print & Tablet Editions for one low price!

Subscribe Now >>

X

Please Log In

Forgot: Password

X

Account Linking

Welcome, . Do you have an existing ScientificAmerican.com account?

Yes, please link my existing account with for quick, secure access.



Forgot Password?

No, I would like to create a new account with my profile information.

Create Account
X

Report Abuse

Are you sure?

X

Institutional Access

It has been identified that the institution you are trying to access this article from has institutional site license access to Scientific American on nature.com. To access this article in its entirety through site license access, click below.

Site license access
X

Error

X

Share this Article

X

About the Bering in Mind Blog

In this column presented by Scientific American Mind magazine, research psychologist Jesse Bering of Queen's University Belfast ponders some of the more obscure aspects of everyday human behavior. Ever wonder why yawning is contagious, why we point with our index fingers instead of our thumbs or whether being breastfed as an infant influences your sexual preferences as an adult? Get a closer look at the latest data as "Bering in Mind" tackles these and other quirky questions about human nature. Sign up for the RSS feed or friend Dr. Bering on Facebook and never miss an installment again.

X

About the Cross-check Blog

Every week, John Horgan takes a puckish, provocative look at breaking science. A former staff writer at Scientific American, he is the author of several books—most notably, The End of Science: Facing the Limits of Knowledge in the Twilight of the Scientific Age. He currently directs the Center for Science Writings at Stevens Institute of Technology. He lives in New York State's Hudson Highlands, where he plays ice hockey each winter to hone his cross-checking skills.

X

Expeditions Blog

Ever wonder what it's really like to be working in Antarctica or collecting core samples from the middle of the Pacific Ocean? Get a first-hand feel for scientific exploration by following the blog posts of researchers out in the field.

X

About the Extinction Countdown Blog

Several times a week, John Platt shines a light on endangered species from all over the globe, exploring not just why they are dying out but also what's being done to rescue them from oblivion. From unusual or little-known organisms like the giant spitting earthworm and the stinking hawk's-beard to popular favorites like cheetahs and koalas, Platt, a journalist specializing in environmental issues and technology, does his part to slow the countdown.

X

About the Guest Blog

The editors of Scientific American regularly encounter perspectives on science and technology that we believe our readers would find thought-provoking, fascinating, debatable and challenging. The guest blog is a forum for such opinions. The views expressed belong to the author and are not necessarily shared by Scientific American.

X

About the Solar at Home Blog

Follow Scientific American editor George Musser as he installs--or tries to install--solar photovoltaic panels on the roof of his suburban New Jersey home. You'll learn the literal nuts and bolts of going green with the sun and get energy-saving tips even if you aren't putting up panels.

Write to us with tips or comments at blog@sciam.com and follow us on Twitter: http://twitter.com/sciam.

X