图尔西·加巴德多年来在多个账户上重复使用同一个薄弱密码。
Tulsi Gabbard Reused the Same Weak Password on Multiple Accounts for Years

原始链接: https://www.wired.com/story/tulsi-gabbard-dni-weak-password/

最近《连线》杂志的一篇报道称,国家情报总监图尔西·加巴德多年来在多个在线账户(包括电子邮件、Dropbox和LinkedIn)上使用同一个容易破解的密码。这引发了对其安全措施的担忧,尤其是在此前她参与的一个Signal群聊中分享了敏感军事信息之后。这个密码出现在可追溯到2012年的泄露数据库中,其中包含单词“shraddha”,可能与科学认同基金会(一个克里希纳教的分支)有关。加巴德的发言人表示,这些泄露事件发生在近十年前,密码已经更改。她的团队还强烈否认与科学认同基金会有任何关联,并指责媒体存在印度教恐惧症。尽管否认了这些指控,但该报道还是凸显了加巴德过去网络安全习惯中可能存在的疏忽,因为她作为前国会议员和情报委员会成员,接触过敏感信息。

这个Hacker News帖子讨论了一起涉及图尔西·加巴德相关账号的安全漏洞。用户们重点提到了密码“shraddha”,这似乎与加巴德与科学认同基金会(Science of Identity Foundation,Hare Krishna运动的一个分支)的联系有关。 除了这起具体事件之外,讨论还扩展到了对现任政府能力不足的评论。一位用户将其与小布什政府进行了对比,认为尽管存在政治分歧,后者仍然配备了有能力的人员。几位评论者认为这个问题超出了政治的范畴,将糟糕的密码安全归因于普遍的人性弱点。讨论最后以对新闻周期中似乎无穷无尽的“愚蠢”行为的反思以及Y Combinator 2025年夏季申请的公告而告终。
相关文章

原文

Tulsi Gabbard, the director of national intelligence, used the same easily cracked password for different online accounts over a period of years, according to leaked records reviewed by WIRED. Following her participation in a Signal group chat in which sensitive details of a military operation were unwittingly shared with a journalist, the revelation raises further questions about the security practices of the US spy chief.

WIRED reviewed Gabbard's passwords using databases of material leaked online created by the open-source intelligence firms District4Labs and Constella Intelligence. Gabbard served in Congress from 2013 to 2021, during which time she sat on the Armed Services Committee, its Subcommittee on Intelligence and Special Operations, and the Foreign Affairs Committee, giving her access to sensitive information. Material from breaches shows that during a portion of this period, she used the same password across multiple email addresses and online accounts, in contravention of well-established best practices for online security. (There is no indication that she used the password on government accounts.)

Two collections of breached records published in 2017 (but breached at some previous unknown date), known as “combolists,” reveal a password that was used for an email account associated with her personal website; that same password, according to a combolist published in 2019, was used with her Gmail account. That same password was used, according to records dating to 2012, for Dropbox and LinkedIn accounts associated with the email address tied to her personal website. According to records dating to 2018 breaches, she also used it on a MyFitnessPal account associated with a me.com email address and an account at HauteLook, a now-defunct ecommerce site then owned by Nordstrom.

Records of these breaches have been available online for years and are accessible in commercial databases.

The password associated with all of the accounts in question includes the word “shraddha,” which appears to have personal significance to Gabbard: Earlier this year, The Wall Street Journal reported that she had been initiated into the Science of Identity Foundation, an offshoot of the Hare Krishna movement into which she was reportedly born and which former members have accused of being a cult. Several former adherents told The Journal that they believe Gabbard received the name “Shraddha Dasi” when she was allegedly received into the group. Gabbard’s deputy chief of staff, Alexa Henning, responded to questions from The Journal at the time by posting them on X and accusing the news media of publicizing “Hinduphobic smears and other lies.”

“The data breaches you’re referring to occurred almost 10 years ago, and the passwords have changed multiple times since,” wrote Olivia Coleman, a Gabbard spokesperson, in response to questions from WIRED. “As our deputy chief of staff has already made clear on a number of occasions, the DNI has never and doesn’t have affiliation with that organization. Attempting to smear the DNI as being in a cult is bigoted behavior.“

“Your bigoted lies and smears of a cabinet member and your story fomenting hinduphobia is noted,” wrote Henning in response to a follow-up question about the probability of Gabbard’s password containing the same name she was reportedly received into Science of Identity Foundation with, given her denials that she has ever been affiliated with the group. “This was well litigated during her confirmation hearing so congrats on being about 6 months late to this story. Great job.”

联系我们 contact @ memedata.com