Stunningly weak Yahoo password security

I was wondering just how the hacker got into Palin's account so easily.

"Rubico claimed the actual intrusion into Palin's account was a relatively easy matter. It began after Rubico read news accounts claiming Palin used gov.palin@yahoo.com in her official capacity of governor of Alaska - which, if true, would skirt the state's open government laws. Rubico then hacked Yahoo's password recovery feature. In 45 minutes, he had her birth date, and two possible zip codes, and soon after that online research revealed Palin met her spouse, Todd, while they were students at Wasilla High School, in Alaska."

http://www.theregister.co.uk/2008/09/18/palin_email_investigation_continues/

What is the name of my favourite pet, mothers maiden name, etc, etc.  Gotta love all those password recovery questions.  I frequently put in words that some, including my mother, would consider offensive.

I was extremely upset when some genealogy buff put my full name and birth date on a web page a number of years ago. Along with my parents and siblings information.  That page is gone now.  And thankfully genealogy software doesn't do that by default any more.

Back in the days of bulletin board systems in the early '90s a friend found that many of the local BBS sysop's used the same password on their own BBS's as well as when logged into other BBS's.   Duh!   He was happy to see that that didn't work for me.

How many other website's use similar systems?   Hopefully they're all having a massive "Oh sh*t" moment.  Including the banks. 

Published Thu, Sep 18 2008 20:24 by Tony

Comments

# re: Stunningly weak Yahoo password security

One way to side track these crackers is to publish the wrong birth date and Mothers maiden on your web site/blog.

Tuesday, September 23, 2008 6:04 PM by Garry Robinson

# re: Stunningly weak Yahoo password security

I always put in the wrong birth date.   And I never put in the right answer to any of those questions.  And sometimes I even record the false entries I put in.  <smile>

Most times I can't be bothered with this B.S.  If I need to come back to that site then I just setup another account.  

I don't have any email addresses not running on my own domains.  So it's not a problem for me.

Tuesday, September 23, 2008 6:09 PM by Tony

# re: Stunningly weak Yahoo password security

There's another problem with Yahoo. Certain information - such as your country of residence and zip code - is held on your account page (ie not on file).This information is needed to reset your password. If your account is then illegally accessed, this information can be changed and you have no hope of ever being able to reset your password online. You can do it over the phone if you want to dial a number in the States on PST and if you can remember the answer to your security question. But it's not as if Yahoo! hands out their helpline number willingly.

Sunday, February 15, 2009 3:53 PM by unhappy24

Leave a Comment

(required) 
(required) 
(optional)
(required) 
If you can't read this number refresh your screen
Enter the numbers above: