Tulsi Gabbard Reused the Same Weak Password on Multiple Accounts for Years

3 hours ago 3

Tulsi Gabbard, the manager of nationalist intelligence, utilized the aforesaid easy cracked password for antithetic online accounts implicit a play of years, according to leaked records reviewed by WIRED. Following her information successful a Signal radical chat successful which delicate details of a subject cognition were unwittingly shared with a journalist, the revelation raises further questions astir the information practices of the US spy chief.

WIRED reviewed Gabbard's passwords utilizing databases of worldly leaked online created by open-source quality firms District4Labs and Constella Intelligence. Gabbard served successful Congress from 2013 to 2021, during which clip she sat connected the Armed Services Committee, its Subcommittee connected Intelligence and Special Operations, and the Foreign Affairs Committee, giving her entree to delicate information. Material from breaches shows that during a information of this period, she utilized the aforesaid password crossed aggregate email addresses and online accounts, successful contravention of well-established best practices for online security. (There is nary denotation that she utilized the password connected authorities accounts.)

Two collections of breached records published successful 2017 (but breached astatine immoderate erstwhile chartless date), known arsenic “combolists,” uncover a password that was utilized for an email relationship associated with her personal website; that aforesaid password, according to a combolist published successful 2019, was utilized with her Gmail account. That aforesaid password was used, according to records dating to 2012, for Dropbox and LinkedIn accounts associated with the email code tied to her idiosyncratic website. According to records dating to 2018 breaches, she besides utilized it connected a MyFitnessPal relationship associated with a me.com email code and an relationship astatine HauteLook, a now-defunct e-commerce tract past owned by Nordstrom.

Records of these breaches person been disposable online for years and are accessible successful commercialized databases.

The password associated with each of the accounts successful question includes the connection “shraddha,” which appears to person idiosyncratic value to Gabbard: Earlier this year, The Wall Street Journal reported that she had been initiated into the Science of Identity Foundation, an offshoot of the Hare Krishna question into which she was reportedly calved and which erstwhile members person accused of being a cult. Several erstwhile adherents told WSJ that they judge Gabbard received the sanction “Shraddha Dasi” erstwhile she was allegedly received into the group. Gabbard’s lawman main of staff, Alexa Henning, responded to questions from the Journal astatine the clip by posting them connected X and accusing the quality media of publicizing “Hinduphobic smears and different lies.”

“The information breaches you’re referring to occurred astir 10 years ago, and the passwords person changed aggregate times since,” wrote Olivia Coleman, a Gabbard spokesperson, successful effect to questions from WIRED. “As our Deputy Chief of Staff has already made wide connected a fig of occasions, the DNI has ne'er and doesn’t person affiliation with that organization. Attempting to smear the DNI arsenic being successful a cult is bigoted behavior.“

“Your bigoted lies and smears of a furniture subordinate and your communicative fomenting hinduphobia is noted,” wrote Henning successful effect to a follow-up question astir the probability of Gabbard’s password containing the aforesaid sanction she was reportedly received into Science of Identity Foundation with, fixed her denials that she has ever been affiliated with the group. “This was good litigated during her confirmation proceeding truthful congrats connected being astir 6 months precocious to this story. Great job.”

Read Entire Article