2005 · Security
The 2005 Sidekick hack: a celebrity phone breach and online account security
In February 2005 the address book and notes from Paris Hilton’s T-Mobile Sidekick appeared online. The breach showed how weak account recovery could expose data synced to the cloud.
What happened
The T-Mobile Sidekick, made by Danger, was one of the first popular phones to keep its contacts, notes and photos on the operator’s servers and sync them automatically. Owners could also see and edit that data through a T-Mobile website.
In February 2005 the contents of Paris Hilton’s Sidekick, including the phone numbers of other well-known people, were posted on the web. The story spread around the world within hours, and many of the people whose numbers were exposed had to change them.
How it was done
Investigators and security researchers concluded that the intruders had not broken the phone itself. The most widely reported explanation was that they got into the online account, either by abusing a weakness in T-Mobile’s website or by resetting the password through a security question whose answer could be found from public information, such as a pet’s name. Reports also described phone calls in which the attackers persuaded staff to hand over information, a technique known as social engineering.
A Massachusetts teenager was later sentenced in a juvenile court for a series of computer intrusions that included T-Mobile systems. The case came shortly after a separate, unrelated breach of T-Mobile’s systems by another hacker was revealed in 2004.
Why it mattered
The case was one of the first times the public saw that a phone’s data now lived somewhere else, and that the security of that data depended on the weakest way into the account. Security questions in particular were exposed as a poor safeguard, because the answers are often public. The same weakness was used in 2008 to break into a US politician’s webmail account.
The lessons are still taught today: use unique passwords, treat security-question answers as extra passwords rather than real facts, and turn on two-step verification. Many later celebrity account breaches followed the same pattern of guessed or reset credentials rather than technical attacks on devices.
Sources
- Wikipedia: Danger Hiptop (T-Mobile Sidekick)
- Brian Krebs, reporting on the Sidekick breach investigation, The Washington Post, 2005
- US Attorney’s Office, District of Massachusetts, statement on a juvenile computer intrusion case, September 2005