Lessons Learned from The Sarah Palin Email Hack

CYBERSPACE — The hack of GOP vice-presidential nominee Sarah Palin's email provides a lesson to computer users everywhere: common password protection isn't that great.

The hacker claiming to be behind the email invasion posted on the Internet message board 4Chan.org explained how he retrieved Palin's password information. It sounded all too easy.

First, the hacker used the password retrieval function associated with Palin's Yahoo account and answered two security questions: The governor's birthday and her home ZIP code, both of which he said he was able to find through simple Google searches.

After that, the hacker encountered a more challenging security question: Where did the governor meet her husband?

But once again, a trip to YouTube or some other video-sharing site was all the hacker needed. Gov. Palin herself recounted during her acceptance speech at the Republican national convention that she met her husband at Wasilla, Alaska, High School.

What does this mean for the rest of us? Roger A. Grimes, a security expert who writes for InfoWorld.com, said that no amount of good programming can make up for lousy security questions.

"If your password reset feature is weak (and most are), then the security of your account has nothing to do with anything else besides those few questions," he said.

"It doesn't matter how good the vendor's other security features are, it doesn't matter how long and complex your password is, it doesn't matter how secure their coding is and whether they use SDL programming,” Grimes added. “All that matters is how common the questions and answers are.

What's the solution? One possible answer is to treat every security question like another password field.

"When they ask you for your dog's name, say something like 'Im5n$?aTuy' and put that for all your password reset answers," Grimes said.

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

BranditScan Launches 'White Glove' Subscription Tier

BranditScan has launched its new White Glove subscription tier for creators.

German Court: Regulator Can't Block Creator's IG Account, Only Posts

A German court has ruled that while a regional media regulatory agency may block specific Instagram posts that include material deemed harmful to minors, it cannot ban an entire Instagram account due to such a post.

Brazil Lays Out Preliminary Guidelines for New AV Requirements

President Luiz Inácio Lula da Silva on Wednesday signed a decree establishing guidelines for new regulations requiring adult websites to age-verify users located in Brazil.

Senate Committee Debates Section 230 Reform

The U.S. Senate Committee on Commerce, Science, and Transportation held a hearing Wednesday on potential changes to Section 230 of the Communications Decency Act, which protects interactive computer services — including adult platforms — from liability for user-generated content.

Pearl Industry Network Offers Free Creator Memberships

Industry trade group Pearl Industry Network (PiN) has launched its free creator membership initiative.

Sam Bird Acquires Fanblast

Sam Bird, former co-director of global talent agency Surge, has acquired creator monetization tool Fanblast and named himself CEO.

'SheHerGirls' Launches Through Paysite.com

The braintrust behind PoleVixens has officially launched a new membership site, SheHerGirls, also through Paysite.com.

FTC Invites Public Comment on 'Click to Cancel' Rulemaking

The Federal Trade Commission (FTC) announced this week that it is seeking public comment on whether it should amend its Negative Option Rule to better address deceptive or unfair practices.

Aylo Rebuts Indiana AV Suit Claims Over VPN Access

Aylo this week asked a Marion Superior Court judge to dismiss Indiana’s lawsuit alleging that the company violated the state’s age verification law by failing to prevent access by users who employ VPNs and similar means to avoid geolocation.

'PSMTickling' Launches Through Paysite.com

PSMTickling.com has officially launched through Paysite.com.

Show More