Ok, just a quick follow up to the Paris Hilton Sidekick hacking thing... (I'm not obsessed... really! I just want to keep putting Paris Pictures up on my blog.. yeah! that's it).
Previously, I speculated that a T-Mobile employee could have gained access. It's been speculated that the T-Mobile website was hacked by way of some poorly written software and unpactched servers.
However, it seems that it may have been much much easier then that.
From Brian McWilliams's post at O'Reilly:
Like many online service providers, T-Mobile.com requires users to answer a "secret question" if they forget their passwords. For Hilton's account, the secret question was "What is your favorite pet's name?" By correctly providing the answer, any internet user could change Hilton's password and freely access her account.
Talk about weak passwords! And, apparently she knew for some time that someone had access and didn't bother to try to get her account name changed or anything. Again, I can't tell if she just really IS that stupid, or if she just wants to do anything to get the media attention.
http://blog.rkware.com/htsrv/trackback.php/34
The life and times of an atypical average guy.
| Mon | Tue | Wed | Thu | Fri | Sat | Sun |
|---|---|---|---|---|---|---|
| << < | > >> | |||||
| 1 | 2 | 3 | 4 | 5 | 6 | |
| 7 | 8 | 9 | 10 | 11 | 12 | 13 |
| 14 | 15 | 16 | 17 | 18 | 19 | 20 |
| 21 | 22 | 23 | 24 | 25 | 26 | 27 |
| 28 | 29 | 30 | 31 | |||