Yahoo, Hotmail, Gmail all vulnerable to password reset hack

By Gregg Keizer, Computerworld |  Security, Yahoo, email 18 comments

Yahoo Mail isn't the only Web-based mail service that could be duped into giving up someone else's account password, the tactic that some have argued was used to break into Gov. Sarah Palin's e-mail earlier this week.

Google Inc.'s Gmail, Microsoft Corp.'s Windows Live Hotmail and Yahoo Inc.'s Mail all rely on automated password reset mechanisms that can be abused by knowing a username associated with an account and an answer to a single security question, according to quick tests run by Computerworld .
Computerworld reporters and editors were able to "break" into their own and colleagues' accounts on all three services, then reset passwords armed only with the account's username and the correct response to one of a limited number of common security questions, such as mother's maiden name, the name of a favorite pet or the make of a first car.

Some of the personal information that would provide answers to the security questions may be easily found by searching social networking sites or the Internet, the approach a hacker labeled as "rubico" claimed to have used to dig up the responses necessary to access Palin's account.

Hackers who know the username of an account -- which is often identical to the part of the e-mail address that precedes the "@" symbol -- and correctly type the CAPTCHA (Completely Automated Public Turing Test to Tell Computers and Humans Apart), the name for the distorted, scrambled characters meant to stymie automated bots, are faced with only a security question before allowed to change the account password.

None of the services required that the new password be sent to an alternate e-mail address -- although that was an option for all three -- and instead offered an all-online process.

Adam O'Donnell, director of emerging technologies at message security vendor Cloudmark Inc., said that automated password reset is the rule in Web-based mail, whether the service is free, like Yahoo, Hotmail and Gmail, or offered as part of the monthly fee by one's ISP.

"ISPs have razor-thin margins, and one call to the help desk to reset a password would wipe out the month's profit on that user," said O'Donnell in an interview yesterday.

At the time, although other security experts were skeptical of the hacker's claim to have accessed Palin's account through a password reset, O'Donnell had said it sounded "very plausible."

According to rubico, who some have speculated is the 20-year-old son of a Tennessee state legislator, the online research needed to reset Palin's password took just 45 minutes.

18 comments

    farzan
    farzan 45 weeks ago
    I have been noticed that password hacking problem seems a very common issued now, so for secure the account user should be very much conscious about the alternate id, security options and lack using of common password while creating a user account, it leads to be less password hacks.Nappybags
    Anonymous 45 weeks ago
    Your work is very good and I appreciate you and hopping for some more informative posts. Thank you for sharing great information to us.anemia homeopathic
    parker7726
    parker7726 46 weeks ago
    This seems a common problem for all users who are suffered from the same password problem, this will be not the fault of search engine but the user must be aware of these problems while to keep a safe password, but it's better to use some security question and avoid to being hacked.combat the fat review
    joehill7833
    joehill7833 46 weeks ago
    I genuinely liked reading through your post!. Quality material. I might advise you to come up with blogposts even more often. By doing this, having this kind of a worthy website I think you will probably rank higher in the search engines.
    Anonymous 46 weeks ago
    You definitely need to careful out there. It isnt enough to use common dates, names, friends etc as password or security question answers...hackers and identity thiefs are much smarter than that. If you only have access to a few uncustomiazable security questions than by all means use "mothers maiden name" but DONT use the real one...make up a name only you will know (and remember)...dont make the hackers job easy. Jess Anxiety Treatment
    abinet
    abinet 46 weeks ago
    I can appreciate the whole matter of the blog that web mail services are not responsible for the password hack it is the responsible of the user to protect their user ids many times it found that user keeps some common password but it's better to give a unique password which is not to be hacked by others or use some security option to protect the user account.internet marketing products
    Anonymous 46 weeks ago
    I agree with the comment above putting the responsibility on the user. When people use passwords like "password" or their wifes name or their birthdate they are just asking for trouble. It was different a few years back but now with all the added security available and the education of how to make a secure password there isn't much excuse. Not trying to be difficult but just want to encourage people to be wise and safe. Eddie Free Credit Score.com
    Anonymous 47 weeks ago
    Just use security questions that aren't so obvious so that your account is safe. Don't use the given ones. Create your own security question. metal detectors
    joshep77
    joshep77 47 weeks ago
    Gregg Keizer I am really thankful near you for sharing such a great bit of information regarding password vulnerability in Yahoo,Gmail,Hotmail from hackers.product development
    Anonymous 47 weeks ago
    Gosh, even emails can easily be hacked nowadays! I think that the proper authorities should do something about this alarming issue, Although it is indeed hard to track hackers, maybe they can all start by banning and apprehending people who sell/provide password hacking services online! how to install hardwood flooring
    Anonymous 47 weeks ago
    How will that happen??So u mean there's another tactic could be... e-liquid
    gene treho
    gene treho 1 year ago
    There's no real way to stop this sort of violations to privacy from happening. Particularly when people are careless regarding their passwords and many times use the same ones along with user ids in different sites. That's why Openid and the such are so necessary. Gene treho repossessed cars for sale news - repossessed car auctions
    Anonymous 1 year ago
    Of course they are! No password is safe when the recovery question is too obvious. I don't blame google, or yahoo, or any other webmail services for this matter. It's the user's responsibility to keep all his/her passwords safe and secured. If you get hacked, that means your not too careful with your own account's security. Just saying.Andy SyI'm a fan of Bill Bartmann Billionaire
    Anonymous 1 year ago
    change cso game password
    Anonymous 1 year ago
    how can i hack into gmai??
    sahilsinharocks
    sahilsinharocks 2 years ago
    how to hack any gmail id by its username...pls say
    Anonymous 3 years ago
    i forget my password so i want my password plz help me
    Anonymous 2 years ago in reply to Anonymous
    just contact me for your problem concerning harking. couragefandation@hotmail.com

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      SecurityWhite Papers & Webcasts

      White Paper

      Overcome Top 7 Admin Challenges of Active Directory

      As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

      White Paper

      Insiders Can Ruin Your Company. Take Action.

      Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

      White Paper

      Top Solutions and Tools to Prevent Devastating Malware

      Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

      White Paper

      Streamline Compliance and Increase ROI

      Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

      White Paper

      X-Ray of the PCI Process-4 Proactive Steps

      This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

      See more White Papers | Webcasts

      Ask a question

      Ask a Question