<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Speculation on Palin E-mail Hack</title>
	<atom:link href="http://www.veracode.com/blog/2008/09/speculation-on-palin-e-mail-hack/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.veracode.com/blog/2008/09/speculation-on-palin-e-mail-hack/</link>
	<description>Application security testing, analysis, and metrics</description>
	<lastBuildDate>Tue, 15 May 2012 22:16:53 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Palin Yahoo Email Hacked &#171; SecuraBit</title>
		<link>http://www.veracode.com/blog/2008/09/speculation-on-palin-e-mail-hack/comment-page-1/#comment-15991</link>
		<dc:creator>Palin Yahoo Email Hacked &#171; SecuraBit</dc:creator>
		<pubDate>Tue, 13 Mar 2012 16:43:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=282#comment-15991</guid>
		<description>[...] EngÂ (guest on Securabit Episode 7) has posted some commentary on what he thinks might have happened to the account. Â What are your thoughts on this matter? [...]</description>
		<content:encoded><![CDATA[<p>[...] EngÂ (guest on Securabit Episode 7) has posted some commentary on what he thinks might have happened to the account. Â What are your thoughts on this matter? [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Take Business Email Seriously &#124; Seo Vancouver Island</title>
		<link>http://www.veracode.com/blog/2008/09/speculation-on-palin-e-mail-hack/comment-page-1/#comment-2535</link>
		<dc:creator>Take Business Email Seriously &#124; Seo Vancouver Island</dc:creator>
		<pubDate>Sat, 07 Feb 2009 22:15:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=282#comment-2535</guid>
		<description>[...] The biggest news item was VP candidate Sarah Palin&#8217;s use of Yahoo Mail for government business. Apparently, the email account was not breached by any high level hacker attack, but by a weakness in the Yahoo Password Reset. [...]</description>
		<content:encoded><![CDATA[<p>[...] The biggest news item was VP candidate Sarah Palin&#8217;s use of Yahoo Mail for government business. Apparently, the email account was not breached by any high level hacker attack, but by a weakness in the Yahoo Password Reset. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zero Day mobile edition</title>
		<link>http://www.veracode.com/blog/2008/09/speculation-on-palin-e-mail-hack/comment-page-1/#comment-2090</link>
		<dc:creator>Zero Day mobile edition</dc:creator>
		<pubDate>Fri, 19 Sep 2008 13:42:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=282#comment-2090</guid>
		<description>[...] Chris Eng pointed out, you should carefully scrutinize the password reset policy used by the webmail [...]</description>
		<content:encoded><![CDATA[<p>[...] Chris Eng pointed out, you should carefully scrutinize the password reset policy used by the webmail [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.veracode.com/blog/2008/09/speculation-on-palin-e-mail-hack/comment-page-1/#comment-2085</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Thu, 18 Sep 2008 09:59:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=282#comment-2085</guid>
		<description>Anonymous is not a group of hackers - it&#039;s a leaderless collective of like-minded individuals, from all walks of life.

http://www.enturbulation.org/press-media/faq</description>
		<content:encoded><![CDATA[<p>Anonymous is not a group of hackers &#8211; it&#8217;s a leaderless collective of like-minded individuals, from all walks of life.</p>
<p><a href="http://www.enturbulation.org/press-media/faq" rel="nofollow">http://www.enturbulation.org/press-media/faq</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MikeA</title>
		<link>http://www.veracode.com/blog/2008/09/speculation-on-palin-e-mail-hack/comment-page-1/#comment-2084</link>
		<dc:creator>MikeA</dc:creator>
		<pubDate>Thu, 18 Sep 2008 09:29:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=282#comment-2084</guid>
		<description>Crap, sorry, met to post this as well.

http://www.theregister.co.uk/2008/09/18/palin_email_investigation/

Apparently the guy was behind a proxy (says so in his write up), and could easily be traced now.  Also seems that nothing substantive was found in the account because it was the gov.palin@yahoo.com account instead of  gov.sara@yahoo.com - don&#039;t know about you, but I separate out email accounts to work/personal, and the wrong one (well, at least the one everyone was speculating about the contents) was hacked.  However, I can&#039;t imagine that having access to one wouldn&#039;t get you access to the other - I could easily see password/information sharing going on.</description>
		<content:encoded><![CDATA[<p>Crap, sorry, met to post this as well.</p>
<p><a href="http://www.theregister.co.uk/2008/09/18/palin_email_investigation/" rel="nofollow">http://www.theregister.co.uk/2008/09/18/palin_email_investigation/</a></p>
<p>Apparently the guy was behind a proxy (says so in his write up), and could easily be traced now.  Also seems that nothing substantive was found in the account because it was the <a href="mailto:gov.palin@yahoo.com">gov.palin@yahoo.com</a> account instead of  <a href="mailto:gov.sara@yahoo.com">gov.sara@yahoo.com</a> &#8211; don&#8217;t know about you, but I separate out email accounts to work/personal, and the wrong one (well, at least the one everyone was speculating about the contents) was hacked.  However, I can&#8217;t imagine that having access to one wouldn&#8217;t get you access to the other &#8211; I could easily see password/information sharing going on.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MikeA</title>
		<link>http://www.veracode.com/blog/2008/09/speculation-on-palin-e-mail-hack/comment-page-1/#comment-2083</link>
		<dc:creator>MikeA</dc:creator>
		<pubDate>Thu, 18 Sep 2008 09:19:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=282#comment-2083</guid>
		<description>Yep, after seeing the new details come out, I agree it doesn&#039;t look like an inside job at all - as you said Chris, it was far too easy (which is sad in-and-of-itself).  If these people get in they will be in charge of our nuclear codes.  Who&#039;s betting that it won&#039;t be something like &#039;1234&#039; ;)</description>
		<content:encoded><![CDATA[<p>Yep, after seeing the new details come out, I agree it doesn&#8217;t look like an inside job at all &#8211; as you said Chris, it was far too easy (which is sad in-and-of-itself).  If these people get in they will be in charge of our nuclear codes.  Who&#8217;s betting that it won&#8217;t be something like &#8217;1234&#8242; ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Eng</title>
		<link>http://www.veracode.com/blog/2008/09/speculation-on-palin-e-mail-hack/comment-page-1/#comment-2082</link>
		<dc:creator>Chris Eng</dc:creator>
		<pubDate>Thu, 18 Sep 2008 05:08:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=282#comment-2082</guid>
		<description>@Chris Wysopal: Weird, when I tried that &quot;can&#039;t access alternate e-mail account&quot; option, it told me my password couldn&#039;t be reset online.  Maybe I don&#039;t have a secret question defined.

@MikeA: Sounds like this was so easy that no insider info was required.</description>
		<content:encoded><![CDATA[<p>@Chris Wysopal: Weird, when I tried that &#8220;can&#8217;t access alternate e-mail account&#8221; option, it told me my password couldn&#8217;t be reset online.  Maybe I don&#8217;t have a secret question defined.</p>
<p>@MikeA: Sounds like this was so easy that no insider info was required.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MikeA</title>
		<link>http://www.veracode.com/blog/2008/09/speculation-on-palin-e-mail-hack/comment-page-1/#comment-2081</link>
		<dc:creator>MikeA</dc:creator>
		<pubDate>Thu, 18 Sep 2008 04:56:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=282#comment-2081</guid>
		<description>Perhaps a question, one that I&#039;ve not heard many people ask during all this is...

Could it be an insider attack?

All these other attack methods are certainly a good possibility, but there&#039;s plenty of people inside Yahoo, lots &quot;democratic&quot; in nature, and I&#039;m not sure about Yahoo, but most companies are pretty open from the inside.  There&#039;s certainly a (perhaps small) likelihood that someone inside Y! could have &quot;thrown a switch&quot; or &quot;leaked info&quot; about the account.  It&#039;s not as if Y!&#039;s don&#039;t have enough to be pissed off about already, and job security isn&#039;t exactly top of the agenda either.

Just a thought.</description>
		<content:encoded><![CDATA[<p>Perhaps a question, one that I&#8217;ve not heard many people ask during all this is&#8230;</p>
<p>Could it be an insider attack?</p>
<p>All these other attack methods are certainly a good possibility, but there&#8217;s plenty of people inside Yahoo, lots &#8220;democratic&#8221; in nature, and I&#8217;m not sure about Yahoo, but most companies are pretty open from the inside.  There&#8217;s certainly a (perhaps small) likelihood that someone inside Y! could have &#8220;thrown a switch&#8221; or &#8220;leaked info&#8221; about the account.  It&#8217;s not as if Y!&#8217;s don&#8217;t have enough to be pissed off about already, and job security isn&#8217;t exactly top of the agenda either.</p>
<p>Just a thought.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: thehariman.com - Email Sarah Palin Was Hacked! &#124; Computer and Others By Hariman</title>
		<link>http://www.veracode.com/blog/2008/09/speculation-on-palin-e-mail-hack/comment-page-1/#comment-2080</link>
		<dc:creator>thehariman.com - Email Sarah Palin Was Hacked! &#124; Computer and Others By Hariman</dc:creator>
		<pubDate>Thu, 18 Sep 2008 02:31:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=282#comment-2080</guid>
		<description>[...] Sarah palin personal email hacked  Speculation how email hacked : Related PostsNo related postsSocial BookmarkingTags: Gawker, Hacked, Palin Hacked, Sarah Palin, [...]</description>
		<content:encoded><![CDATA[<p>[...] Sarah palin personal email hacked  Speculation how email hacked : Related PostsNo related postsSocial BookmarkingTags: Gawker, Hacked, Palin Hacked, Sarah Palin, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: links for 2008-09-17 (Jarrett House North)</title>
		<link>http://www.veracode.com/blog/2008/09/speculation-on-palin-e-mail-hack/comment-page-1/#comment-2079</link>
		<dc:creator>links for 2008-09-17 (Jarrett House North)</dc:creator>
		<pubDate>Thu, 18 Sep 2008 02:00:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=282#comment-2079</guid>
		<description>[...] Speculation on Palin E-mail Hack &#8230;and here&#039;s how they could have done it. Not every hack requires the knowledge of exploiting buffer overflows and SQL injections&#8230; sometimes there&#039;s just plain bad design at work. (tags: 2008 election palin security) [...]</description>
		<content:encoded><![CDATA[<p>[...] Speculation on Palin E-mail Hack &#8230;and here&#39;s how they could have done it. Not every hack requires the knowledge of exploiting buffer overflows and SQL injections&#8230; sometimes there&#39;s just plain bad design at work. (tags: 2008 election palin security) [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

