Monday, September 22, 2008

The Prime Minister's email list was hacked!





Yesterday (Sunday) a supporter forwarded the following email to me:


Date: Sun, 21 Sep 2008 19:34:54 +0000
From: pm@PM.GC.CA
Subject: Why you shouldn't fear me
To: ALLNEWS_E@LSERV.PMO-CPM.GC.CA

Hi The Average Canadian,

Stephen Harper wanted to tell you...

My name is Stephen Harper. I am an ALBERTAN, here me roar! My goal is to make Canada America's 51st state and destroy health care that all Canadians cherish by infusing my propaganda with hard core ad hominem attacks. Please vote for me, because if you do, I promise you'll be able to vote for McCain 2012!

We are a tar sands level party, not a grass roots party. We consider anything with the word \"Green\" offensive, except for the almighty American dollar, which we hope to be able to implement in the coming months! We shall first have to make sure that American and Canadian jelly beans have the same standards, and then we shall proceed.

I hope everyone has a great weekend,

Take care,

Stephen \"I can lead you to Hell but not back\" Harper

If you agree click here [link deleted].


The person who sent this to me was very upset. She thought she'd signed up in good faith to hear news from the PM's office and here some hacker had obtained her email address.

The Canadian Press, and others, now have a story on this.

The Canadian Press story says,
The jokesters would not necessarily have needed to hack into government computers to perform their stunt; all they would have required was the listserv's email address.
This is totally false. I also run a listserv type email list and, if anyone posts to the list who's not authorized, the message is not sent out, but, instead comes to me for approval.

Another lie coming from Harper's office?

1 comment:

  1. Having a long-time background in web development, when I heard this story on CTV, I immediately guessed that this wasn't a case of "hacking" but incompetance.

    In order for proper message approval before sending is to happen, the list has to be configured that way. This means that either:

    * the web guys the PMO has on staff do not take security very seriously
    * the web guys the PMO has on staff do not know what they are doing
    * the particular version of the listserv software being used by the PMO has a very serious bug

    The media reporting that all you had to know was the email address suggests that the last possibility is out.

    ReplyDelete