28.05.2023 Views

The-art-of-invisibility-_-the-world’s-most-famous-hacker-teaches-you-how-to-be-safe-in-the-age-of-Bi

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

yyou are or were married and that yyour partner, or yyour ex, has a sibling who

is either a man or married to a man born in the state yyou provided. That’s a

lot of additional information from a simple answer. On the other hand, if

yyou don’t have a brother-in-law, go ahead and answer the question

creativelyy, perhaps byy answering “Puerto Rico.” That should confuse

anyyone tryying to build a profile on yyou. The more red herrings yyou provide,

the more yyou become invisible online.

When answering these relativelyy uncommon questions, alwayys consider

how valuable the site is to yyou. For example, yyou might trust yyour bank to

have this additional personal information but not yyour streaming video

service. Also consider what the site’s privacyy policyy might be: look for

language that sayys or suggests that it might sell the information it collects to

third parties.

The password reset for Sarah Palin’s Yahoo e-mail account required her

birth date, zip code, and the answer to the securityy question “Where did yyou

meet yyour husband?” Palin’s birth date and zip code could easilyy be found

online (at the time, Palin was the governor of Alaska). The securityy

question took a bit more work, but the answer to it, too, was accessible to

Kernell. Palin gave manyy interviews in which she stated repeatedlyy that her

husband was her high school sweetheart. That, it turns out, was the correct

answer to her securityy question: “High school.”

Byy guessing the answer to Palin’s securityy question, Kernell was able to

reset her Yahoo Mail password to one that he controlled. This allowed him

to see all her personal Yahoo e-mails. A screenshot of her inbox was posted

on a hacker website. Palin herself was locked out of her e-mail until she

reset the password. 15

What Kernell did was illegal, a violation of the Computer Fraud and

Abuse Act. Specificallyy, he was found guiltyy on two counts: anticipatoryy

obstruction of justice byy destruction of records, a felonyy, and gaining

unauthorized access to a computer, a misdemeanor. He was sentenced in

2010 to one yyear and one dayy in prison plus three yyears of supervised

release. 16

If yyour e-mail account has been taken over, as Palin’s was, first yyou will

need to change yyour password using (yyes, yyou guessed it) the password

reset option. Make this new password a stronger password, as I suggested

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!