Palin e-mail hack highlights weak Web security; Democratic lawmaker's son implicated

Join Our Community of Science Lovers!

This article was published in Scientific American’s former blog network and reflects the views of the author, not necessarily those of Scientific American



On supporting science journalism

If you're enjoying this article, consider supporting our award-winning journalism by subscribing. By purchasing a subscription you are helping to ensure the future of impactful stories about the discoveries and ideas shaping our world today.


Details (as well as plenty of rumor and speculation) continue to emerge about how messages and images from Republican vice presidential nominee Sarah Palin's Yahoo! e-mail account were made public earlier this week. The FBI and U.S. Secret Service are investigating the incident, but several news outlets and blogs report the attack was a multi-step process made possible by weaknesses in the password reset feature (found on many Web sites—not just Yahoo!) as well as proxy servers that allow people to cover their tracks as they navigate the Web.

The  hackers may have exploited the password resetting system of Yahoo's e-mail service using details about Palin's life—her birth date and zip code, for example—pulled from sources freely available on the Web, BBC News reported today.

A story by ComputerWorld's Gregg Keizer provided a bit more detail, reporting that on Wednesday, someone identified only as "rubico" claimed on the 4chan.org message board to have gained access to Palin's e-mail by using Yahoo's password reset feature. Keizer also reports that the FBI has contacted the operator of the Ctunnel proxy service (which serves primarily students or workers who want to access sites that are normally blocked by their network administrators), because the person (or persons) who accessed Palin's e-mail account did so through Ctunnel (a move intended to keep law enforcement from tracking illegal activity back to the culprit's IP address).

Perhaps the best blow-by-blow description of what may have happened is provided on the blog of conservative syndicated columnist Michelle Malkin by one of her readers.

In a case of self-scrutiny, bloggers and other Web users searching for the culprit have linked the handle "rubico" to the 20-year-old son of Tennessee Democratic State Rep. Mike Kernell. The Tennessean Thursday reported that Mike Kernell confirmed that his son, David, a University of Tennessee-Knoxville student, is at the center of an Internet discussion into the hacking of the personal e-mail of vice presidential candidate Sarah Palin. The article, however, does not say—despite reports on several Web sites, including here—that David Kernell admitted to hacking Palin's e-mail or that Mike Kernell named his son as the culprit.

(Image courtesy of iStockphoto; Copyright: Alex Slobodkin)

Larry Greenemeier is the associate editor of technology for Scientific American, covering a variety of tech-related topics, including biotech, computers, military tech, nanotech and robots.

More by Larry Greenemeier

It’s Time to Stand Up for Science

If you enjoyed this article, I’d like to ask for your support. Scientific American has served as an advocate for science and industry for 180 years, and right now may be the most critical moment in that two-century history.

I’ve been a Scientific American subscriber since I was 12 years old, and it helped shape the way I look at the world. SciAm always educates and delights me, and inspires a sense of awe for our vast, beautiful universe. I hope it does that for you, too.

If you subscribe to Scientific American, you help ensure that our coverage is centered on meaningful research and discovery; that we have the resources to report on the decisions that threaten labs across the U.S.; and that we support both budding and working scientists at a time when the value of science itself too often goes unrecognized.

In return, you get essential news, captivating podcasts, brilliant infographics, can't-miss newsletters, must-watch videos, challenging games, and the science world's best writing and reporting. You can even gift someone a subscription.

There has never been a more important time for us to stand up and show why science matters. I hope you’ll support us in that mission.

Thank you,

David M. Ewalt, Editor in Chief, Scientific American

Subscribe