<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: sarah]]></title>
    <link>http://securityratty.com/tag/sarah</link>
    <description></description>
    <pubDate>Tue, 23 Sep 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Sarah Palin and Security Questions]]></title>
      <link>http://securityratty.com/article/1eba1cf0b2be12e62853ecfc357cf52d</link>
      <guid>http://securityratty.com/article/1eba1cf0b2be12e62853ecfc357cf52d</guid>
      <description><![CDATA[I've always looked at security questions used to automate user password recovery with quite a bit of skepticism . What's the point of requiring strong passwords if you allow anyone to reset the...]]></description>
      <content:encoded><![CDATA[<p>I&#39;ve always looked at <a href="http://goodsecurityquestions.com" target="_blank">security questions</a> used to automate user password recovery with <a href="http://www.pluralsight.com/community/blogs/keith/archive/2006/05/24/24964.aspx" target="_blank">quite a bit of skepticism</a>. What&#39;s the point of requiring strong passwords if you allow anyone to reset the password on an account by answering a (potentially inane) question? And just how many good security questions are there, and how many web sites will ask similar questions, allowing the owner of one web site to reset a user&#39;s password at another site that uses the same question? I&#39;m pretty sure that the typical user will tend to select the same security question if it&#39;s available at multiple sites. In many web sites I&#39;ve seen, the security question is clearly the weak link in the chain.</p> <p>Apparently <a href="http://voices.washingtonpost.com/securityfix/2008/10/son_of_tenn_lawmaker_indicted.html?hpid=news-col-blogs" target="_blank">a fellow recently was indicted</a> on charges of <a href="http://blog.wired.com/27bstroke6/2008/09/palin-e-mail-ha.html" target="_blank">hacking</a> into the Republican vice presidential nominee&#39;s Yahoo <a href="http://wikileaks.org/wiki/VP_contender_Sarah_Palin_hacked" target="_blank">email account</a>, by simply doing some research on the Internet to find her birthday, zip code, and the answer to her security question, &quot;Where did you meet your spouse?&quot; All told the attack reportedly took under an hour to complete.</p> <p>Given the level of interest in Palin and other public figures, and the large amount of information about them available to the public, it makes sense that they will be some of the easiest targets for attacks like this.</p><div style="clear:both;"></div><img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=53812" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 04:09:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security question">security question</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <category domain="http://securityratty.com/tag/security questions">security questions</category>
      <category domain="http://securityratty.com/tag/question">question</category>
      <category domain="http://securityratty.com/tag/typical user">typical user</category>
      <category domain="http://securityratty.com/tag/user password recovery">user password recovery</category>
      <category domain="http://securityratty.com/tag/password">password</category>
      <category domain="http://securityratty.com/tag/yahoo email account">yahoo email account</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <source url="http://www.pluralsight.com/community/blogs/keith/archive/2008/10/09/sarah-palin-and-security-questions.aspx">Sarah Palin and Security Questions</source>
    </item>
    <item>
      <title><![CDATA[Palin Hacker Allegedly Involved in Another Computer Intrusion]]></title>
      <link>http://securityratty.com/article/b0e235cee9a2d5c7f3d32327ba039f4d</link>
      <guid>http://securityratty.com/article/b0e235cee9a2d5c7f3d32327ba039f4d</guid>
      <description><![CDATA[A 20-year-old Tennessee student who was indicted this week for gaining unauthorized access to Alaska Gov. Sarah Palin's Yahoo account, was involved in another computer intrusion years ago while in...]]></description>
      <content:encoded><![CDATA[A 20-year-old Tennessee student who was indicted this week for gaining unauthorized access to Alaska Gov. Sarah Palin's Yahoo account, was involved in another computer intrusion years ago while in high school, a former teacher says. David Kernell and a fellow classmate guessed the password to a system storing lesson plans and got detention for it, the teacher says.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=85be033c030c3ca62c0f90c544831a6f" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=85be033c030c3ca62c0f90c544831a6f" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=g9jaM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=g9jaM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=zlQFm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=zlQFm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=gga2m"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=gga2m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=9gFwM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=9gFwM" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=NLfwM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=NLfwM" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=4MYSm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=4MYSm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=2mTlm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=2mTlm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=7s4MM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=7s4MM" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/416036147" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/416036150" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 00:28:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/computer intrusion">computer intrusion</category>
      <category domain="http://securityratty.com/tag/20-year-old tennessee student">20-year-old tennessee student</category>
      <category domain="http://securityratty.com/tag/lesson plans">lesson plans</category>
      <category domain="http://securityratty.com/tag/yahoo account">yahoo account</category>
      <category domain="http://securityratty.com/tag/alaska gov">alaska gov</category>
      <category domain="http://securityratty.com/tag/teacher">teacher</category>
      <category domain="http://securityratty.com/tag/david kernell">david kernell</category>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/416036150/tennessee-stu-1.html">Palin Hacker Allegedly Involved in Another Computer Intrusion</source>
    </item>
    <item>
      <title><![CDATA[Tenn. student indicted for hacking Palin's e-mail]]></title>
      <link>http://securityratty.com/article/7c2688b677117f0cc6d9c24b26f2cd38</link>
      <guid>http://securityratty.com/article/7c2688b677117f0cc6d9c24b26f2cd38</guid>
      <description><![CDATA[The Tennessee college student who came under suspicion as the hacker who broke into the e-mail account of vice presidential candidate Sarah Palin has been indicted by a federal grand...]]></description>
      <content:encoded><![CDATA[The Tennessee college student who came under suspicion as the hacker who broke into the e-mail account of vice presidential candidate Sarah Palin has been indicted by a federal grand jury.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:24a7da4fcaef57af8e5c3adccf4c01ee:lPQi71Ep5ZL2IM%2F7ngVjpVf1tOpD80wO0dLRvEB7nFTnNxAl94aJWuNe4fVtqfFLF6g5VwESQVVm'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c8c50797519e84ee0cea0140fa7f728b:OGQGpLs76HqHTtZC3cpj6eckPrN%2FGkPjdmJ8hzepjjA7l3sKDmSo9a%2B0j%2B%2Fe7ez2W%2FmPCKpjS%2BmKSQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:5e7684fabee745e619f63fa26309daf1:wDUmO4of6AEBzsdJ9y7GREmH%2F1fvt5oY0hh1b0m5uDePMgPFLBrzXQh6sBu6zXv%2B95HvIEDtiy2JGQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:5a3d52939d24cd40fe82d50282bcada4:yo2dceotwAllcZFQcJZePMjl2jde0kCytfpxA7zSR%2B0l8%2F9Eb5MO356cgi3YJ9xJ5vV1UwM%2FyvIM8w%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/click.phdo?s=9296a669728ea3309de7ceb244294be0"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=9296a669728ea3309de7ceb244294be0"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=9296a669728ea3309de7ceb244294be0" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/federal grand jury">federal grand jury</category>
      <category domain="http://securityratty.com/tag/tennessee college student">tennessee college student</category>
      <category domain="http://securityratty.com/tag/vice presidential">vice presidential</category>
      <category domain="http://securityratty.com/tag/e-mail account">e-mail account</category>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <category domain="http://securityratty.com/tag/hacker">hacker</category>
      <category domain="http://securityratty.com/tag/suspicion">suspicion</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=9296a669728ea3309de7ceb244294be0">Tenn. student indicted for hacking Palin's e-mail</source>
    </item>
    <item>
      <title><![CDATA[US man indicted for hacking Palin's e-mail account]]></title>
      <link>http://securityratty.com/article/cf8d43137452a74790c06b8a54535a8e</link>
      <guid>http://securityratty.com/article/cf8d43137452a74790c06b8a54535a8e</guid>
      <description><![CDATA[A 20-year-old Tennessee man has been indicted for hacking into an e-mail account of U.S. vice presidential candidate Sarah Palin, according to court...]]></description>
      <content:encoded><![CDATA[A 20-year-old Tennessee man has been indicted for hacking into an e-mail account of U.S. vice presidential candidate Sarah Palin, according to court records.]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/e-mail account">e-mail account</category>
      <category domain="http://securityratty.com/tag/vice presidential">vice presidential</category>
      <category domain="http://securityratty.com/tag/court records">court records</category>
      <category domain="http://securityratty.com/tag/20-year-old tennessee">20-year-old tennessee</category>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <source url="http://www.networkworld.com/news/2008/100808-us-man-indicted-for-hacking.html?fsrc=rss-security">US man indicted for hacking Palin's e-mail account</source>
    </item>
    <item>
      <title><![CDATA[Summarizing Zero Day's Posts for September]]></title>
      <link>http://securityratty.com/article/0862d75223b7c454c16ff0e7eaa11124</link>
      <guid>http://securityratty.com/article/0862d75223b7c454c16ff0e7eaa11124</guid>
      <description><![CDATA[As usual, here's September's summary of all of my posts at Zero Day . You may also want to catch up and go through August's and July's summaries , next to adding my personal RSS feed or Zero Day's...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOrZOYxNDcI/AAAAAAAACQ4/Ktm1do-Wybs/s1600-h/zero_day_october.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOrZOYxNDcI/AAAAAAAACQ4/77K4rA4iDJo/s200-R/zero_day_october.png" /></a>As usual, here's September's summary of all of my posts at <a href="http://blogs.zdnet.com/security">Zero Day</a>. You may also want to catch up and go through <a href="http://ddanchev.blogspot.com/2008/09/summarizing-zero-days-posts-for-august.html">August's</a> and <a href="http://ddanchev.blogspot.com/2008/08/summarizing-zero-days-posts-for-july.html">July's summaries</a>, next to adding <a href="http://updates.zdnet.com/tags/dancho+danchev.html?t=0&amp;s=0&amp;o=1&amp;mode=rss">my personal RSS feed</a> or <a href="http://feeds.feedburner.com/zdnet/security">Zero Day's main feed</a> to your RSS reader.<br />
<br />
Notable article for September - <a href="http://blogs.zdnet.com/security/?p=1899">Spamming vendor launches managed spamming service</a>.<br />
<br />
<b>01.</b> <a href="http://blogs.zdnet.com/security/?p=1847">DoS vulnerability hits Google's Chrome, crashes with all tabs</a><br />
<b>02.</b> <a href="http://blogs.zdnet.com/security/?p=1852">Malware and spam attacks exploiting Picasa and ImageShack</a><br />
<b>03.</b> <a href="http://blogs.zdnet.com/security/?p=1899">Spamming vendor launches managed spamming service</a><br />
<b>04.</b> <a href="http://blogs.zdnet.com/security/?p=1908">Facebook introducing new security warning feature</a><br />
<b>05.</b> <a href="http://blogs.zdnet.com/security/?p=1911">Google downplays Chrome's carpet-bombing flaw</a><br />
<b>06.</b> <a href="http://blogs.zdnet.com/security/?p=1922">Targeted malware attack against U.S schools intercepted</a><br />
<b>07.</b> <a href="http://blogs.zdnet.com/security/?p=1926">The most "dangerous" celebrities to search for in 2008</a><br />
<b>08.</b> <a href="http://blogs.zdnet.com/security/?p=1935">Norwegian BitTorrent tracker under DDoS attack</a><br />
<b>09.</b> <a href="http://blogs.zdnet.com/security/?p=1939">Attacker: Hacking Sarah Palin's email was easy</a><br />
<b>10.</b> <a href="http://blogs.zdnet.com/security/?p=1958">Bill O'Reilly's web site hacked, attackers release personal details of users</a><br />
<b>11.</b> <a href="http://blogs.zdnet.com/security/?p=1964">India's government: At last, we've cracked Blackberry's encryption</a><br />
<b>12.</b> <a href="http://blogs.zdnet.com/security/?p=1975">Memory exhaustion DoS vulnerability hits Google's Chrome</a><br />
<b>13.</b> <a href="http://blogs.zdnet.com/security/?p=1983">44% of second hand mobile devices still contain sensitive data</a><br />
<b>14.</b> <a href="http://blogs.zdnet.com/security/?p=1986">Spammers attacking Microsoft's CAPTCHA -- again</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8t7TM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8t7TM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9ttSM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9ttSM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7rNcm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7rNcm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BtQ4m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BtQ4m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7SqTM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7SqTM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZCYzM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZCYzM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Gu2Bm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Gu2Bm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/413926169" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 06:54:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google downplays chrome">google downplays chrome</category>
      <category domain="http://securityratty.com/tag/chrome">chrome</category>
      <category domain="http://securityratty.com/tag/vendor launches">vendor launches</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <category domain="http://securityratty.com/tag/september">september</category>
      <category domain="http://securityratty.com/tag/norwegian bittorrent tracker">norwegian bittorrent tracker</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/hand mobile devices">hand mobile devices</category>
      <category domain="http://securityratty.com/tag/malware attack">malware attack</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/413926169/summarizing-zero-days-posts-for.html">Summarizing Zero Day's Posts for September</source>
    </item>
    <item>
      <title><![CDATA[Palin and politics: lots to talk about ]]></title>
      <link>http://securityratty.com/article/ed234b897e908289f742708600d0ee34</link>
      <guid>http://securityratty.com/article/ed234b897e908289f742708600d0ee34</guid>
      <description><![CDATA[Gibbs discusses reader feedback to last week's column about the break-in of Republican vice-presidential candidate Sarah Palin's e-mail account and the heady intersection of IT and...]]></description>
      <content:encoded><![CDATA[Gibbs discusses reader feedback to last week's column about the break-in of Republican vice-presidential candidate Sarah Palin's e-mail account and the heady intersection of IT and politics. ]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/politics">politics</category>
      <category domain="http://securityratty.com/tag/e-mail account">e-mail account</category>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <category domain="http://securityratty.com/tag/heady intersection">heady intersection</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/break-in">break-in</category>
      <category domain="http://securityratty.com/tag/republican">republican</category>
      <category domain="http://securityratty.com/tag/column">column</category>
      <source url="http://www.networkworld.com/columnists/2008/100308-backspin.html?fsrc=rss-security">Palin and politics: lots to talk about </source>
    </item>
    <item>
      <title><![CDATA[Web mail rivals at risk of password-reset hacks]]></title>
      <link>http://securityratty.com/article/cca3dec0ad718b7243ddc9acb9acaa1e</link>
      <guid>http://securityratty.com/article/cca3dec0ad718b7243ddc9acb9acaa1e</guid>
      <description><![CDATA[Yahoo Mail isn't the only Web-based e-mail service that hackers could dupe into giving up passwords, the tactic that apparently was used to break into Alaska Gov. Sarah Palin's Yahoo account this...]]></description>
      <content:encoded><![CDATA[Yahoo Mail isn't the only Web-based e-mail service that hackers could dupe into giving up passwords, the tactic that apparently was used to break into Alaska Gov. Sarah Palin's Yahoo account this month.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:f57faaa49652f1ca5e40515d5dba8b8b:enhiibMsLpo20BVNdSZuZtpNa%2BkBZ1qoC7utaESvXZkY%2Fm0ffM%2FyAzzeRcmgpjLKxrtBLmmZ4ggH'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:42b9784e6fb5894dcbf1bf85a389ee07:Z%2Badb30kFh6IZ6FZ9xx7RrgGMB8D1VmHoTX30Nb01eqP34xn4DbqehbdzHqFycZQuO1rPBPk9gYngw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:a3b6076835c5889473c68730a9c22f91:qDxfGf2x%2FMdH41p4SssgjkTfqJ0Ix9BiLNPMf0p6UsYm74%2B1Pj%2F452NJBvYfhfei4yAHR9trI%2BzCQg%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:77fa4ac62c174b0213a48be4951e286d:zOolIISCqKemyaHqj%2FIx8%2BmO5AQqsXmtqrJOmXiVMRTCnyruqJnmb92ijBz2GbdD0wI1cXW0GY%2FnWw%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/click.phdo?s=bc1191df76eef43e59b0e9da72c34b2a"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=bc1191df76eef43e59b0e9da72c34b2a"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=bc1191df76eef43e59b0e9da72c34b2a" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/yahoo account">yahoo account</category>
      <category domain="http://securityratty.com/tag/yahoo mail">yahoo mail</category>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <category domain="http://securityratty.com/tag/alaska gov">alaska gov</category>
      <category domain="http://securityratty.com/tag/e-mail service">e-mail service</category>
      <category domain="http://securityratty.com/tag/apparently">apparently</category>
      <category domain="http://securityratty.com/tag/passwords">passwords</category>
      <category domain="http://securityratty.com/tag/month">month</category>
      <category domain="http://securityratty.com/tag/dupe">dupe</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=bc1191df76eef43e59b0e9da72c34b2a">Web mail rivals at risk of password-reset hacks</source>
    </item>
    <item>
      <title><![CDATA[Sarah Palin's E-Mail]]></title>
      <link>http://securityratty.com/article/22bb4b94d574654a5aab8a33a6ec3144</link>
      <guid>http://securityratty.com/article/22bb4b94d574654a5aab8a33a6ec3144</guid>
      <description><![CDATA[People have been asking me to comment about Sarah Palin's Yahoo e-mail account being hacked. I've already written about the security problems with &quot;secret questions&quot; back in 2005: The point of all...]]></description>
      <content:encoded><![CDATA[<p>People have been asking me to comment about Sarah Palin's Yahoo e-mail account being hacked.  I've <a href="http://www.schneier.com/blog/archives/2005/02/the_curse_of_th.html">already written</a> about the security problems with "secret questions" back in 2005:</p>

<blockquote>The point of all these questions is the same: a backup password. If you forget your password, the secret question can verify your identity so you can choose another password or have the site e-mail your current password to you. It's a great idea from a customer service perspective -- a user is less likely to forget his first pet's name than some random password -- but terrible for security. The answer to the secret question is much easier to guess than a good password, and the information is much more public. (I'll bet the name of my family's first pet is in some database somewhere.) And even worse, everybody seems to use the same series of secret questions. 

<p>The result is the normal security protocol (passwords) falls back to a much less secure protocol (secret questions). And the security of the entire system suffers.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=4AnbL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=4AnbL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=5j7HL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=5j7HL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 12:01:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/password">password</category>
      <category domain="http://securityratty.com/tag/current password">current password</category>
      <category domain="http://securityratty.com/tag/questions">questions</category>
      <category domain="http://securityratty.com/tag/secret questions">secret questions</category>
      <category domain="http://securityratty.com/tag/random password">random password</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/normal security protocol">normal security protocol</category>
      <category domain="http://securityratty.com/tag/backup password">backup password</category>
      <category domain="http://securityratty.com/tag/secret question">secret question</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/sarah_palins_e-.html">Sarah Palin's E-Mail</source>
    </item>
    <item>
      <title><![CDATA[In the News: Hacking Sarah's Email, TSA-Approved Laptop Bags]]></title>
      <link>http://securityratty.com/article/9f99d21d694700b803cf34b6f0f0a637</link>
      <guid>http://securityratty.com/article/9f99d21d694700b803cf34b6f0f0a637</guid>
      <description><![CDATA[Hacking Palin's EmailIt's no secret in the IT community that hacking into someone's email account is a fairly trivial task, but now that VP-candidate Sarah Palin's account has been...]]></description>
      <content:encoded><![CDATA[Hacking Palin's EmailIt's no secret in the IT community that hacking into someone's email account is a fairly trivial task, but now that VP-candidate Sarah Palin's account has been cra...]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 11:47:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <category domain="http://securityratty.com/tag/fairly trivial task">fairly trivial task</category>
      <category domain="http://securityratty.com/tag/palin">palin</category>
      <category domain="http://securityratty.com/tag/email account">email account</category>
      <category domain="http://securityratty.com/tag/emailit">emailit</category>
      <category domain="http://securityratty.com/tag/secret">secret</category>
      <category domain="http://securityratty.com/tag/community">community</category>
      <category domain="http://securityratty.com/tag/cra">cra</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/402253237/">In the News: Hacking Sarah's Email, TSA-Approved Laptop Bags</source>
    </item>
    <item>
      <title><![CDATA[Palin hacking probe: What's next?]]></title>
      <link>http://securityratty.com/article/34143e518f604c71c8ec5a16db4c8ecf</link>
      <guid>http://securityratty.com/article/34143e518f604c71c8ec5a16db4c8ecf</guid>
      <description><![CDATA[The intensity of the probe into the hacking of Sarah Palin's e-mail has subsided but big questions...]]></description>
      <content:encoded><![CDATA[The intensity of the probe into the hacking of Sarah Palin's e-mail has subsided but big questions remain.]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/probe">probe</category>
      <category domain="http://securityratty.com/tag/questions remain">questions remain</category>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <category domain="http://securityratty.com/tag/e-mail">e-mail</category>
      <category domain="http://securityratty.com/tag/intensity">intensity</category>
      <source url="http://www.networkworld.com/news/2008/092408-palin-hacking-probe-whats.html?fsrc=rss-security">Palin hacking probe: What's next?</source>
    </item>
  </channel>
</rss>
