Lessons Learned from The Sarah Palin Email Hack

CYBERSPACE — The hack of GOP vice-presidential nominee Sarah Palin's email provides a lesson to computer users everywhere: common password protection isn't that great.

The hacker claiming to be behind the email invasion posted on the Internet message board 4Chan.org explained how he retrieved Palin's password information. It sounded all too easy.

First, the hacker used the password retrieval function associated with Palin's Yahoo account and answered two security questions: The governor's birthday and her home ZIP code, both of which he said he was able to find through simple Google searches.

After that, the hacker encountered a more challenging security question: Where did the governor meet her husband?

But once again, a trip to YouTube or some other video-sharing site was all the hacker needed. Gov. Palin herself recounted during her acceptance speech at the Republican national convention that she met her husband at Wasilla, Alaska, High School.

What does this mean for the rest of us? Roger A. Grimes, a security expert who writes for InfoWorld.com, said that no amount of good programming can make up for lousy security questions.

"If your password reset feature is weak (and most are), then the security of your account has nothing to do with anything else besides those few questions," he said.

"It doesn't matter how good the vendor's other security features are, it doesn't matter how long and complex your password is, it doesn't matter how secure their coding is and whether they use SDL programming,” Grimes added. “All that matters is how common the questions and answers are.

What's the solution? One possible answer is to treat every security question like another password field.

"When they ask you for your dog's name, say something like 'Im5n$?aTuy' and put that for all your password reset answers," Grimes said.

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Woodhull Freedom Foundation to Host Virtual 'Pride' Edition of 'Fact Checked' Series

Woodhull Freedom Foundation is hosting a Pride Month virtual edition of its series “Fact Checked by Woodhull.”

'InMelanin' Relaunches Through PAYSITE

InMelanin.com has officially relaunched through PAYSITE.

Pearl Industry Network Partners With Takedown Piracy

Industry trade group Pearl Industry Network (PiN) has officially partnered with Takedown Piracy.

Hollywood Reporter Spotlights XBIZ Miami in Feature on Fan Platforms

Last month's XBIZ conference serves as the setting for a new Hollywood Reporter feature examining the competitive fan platform market.

F2F, Image Angel Launch 'Forensic Watermarking' for Traceability

Friends2Follow (F2F) and Image Angel have partnered to launch a new traceability solution to combat unauthorized content sharing with the use of forensic watermarks.

EU Court: France Can Require Foreign Sites to Implement AV

The European Union’s Court of Justice ruled on Tuesday that France may require pornographic websites based in other EU states to implement age verification in accordance with French law, as long as France follows EU electronic commerce rules.

LoyalFans Announces 'Group Walkthrough' Online Event Series

LoyalFans has announced its new “Group Walkthrough” online event series for creators, taking place every Tuesday and Thursday.

Bree Sky Officially Launches 'ThirstChat' Fan Platform

Creator and entrepreneur Bree Sky has debuted her new fan platform, ThirstChat.

Lawsuit Alleging Meta Pirated VMG Content Will Move Forward

A U.S. district court on Thursday rejected Facebook parent company Meta’s motion to dismiss a suit by Vixen Media Group owner Strike 3 Holdings, which accuses Meta of pirating VMG content to train its artificial intelligence models.

Playboy Partners With Creator Platform Tango

Playboy has partnered with creator platform Tango, introducing Playmates to the livestreaming service.

Show More