We've seen a few reports, recently, about stolen blogs, in Blogger Help Forum: Something Is Broken.Why is my blog not on my dashboard - and why is somebody else publishing, and using my name?
There are so many reports from people who are not using Google "One Account" login properly, that the significance of this problem report was initially overlooked.
More than a few such reports started with the blog owner email address being openly disclosed - generally on the blog, or in comments. Too many blog owners want to be contacted - and they innocently provide their email addresses as a contact point.
We've known, for years, about disclosed email addresses, and brute force password guessing. That is not the only way your email address can be used, to gain access to your Blogger account, however.
Google recently had to deal with a very carefully executed hacking project, where Blogger and Google account owners received some well phrased advice, in their email. Google treats policy violations and invalid activity very seriously in order to protect the users, publishers, and advertisers who make up our advertising ecosystem. While we usually notify publishers and take action for policy and invalid activity at the site level, there may be times when we will need to suspend or disable accounts due to policy violations or invalid activity.
Our hope is that you will be able to resolve your policy issues during the suspension period using This Link
I'm betting that the above message was written, very carefully, by hackers who studied the phrasing and wording of the many abuse / spam / TOS violation notices, sent out by Blogger Support constantly.
Many of the recipients of the email are the same crowd that I encountered, several years ago, when we saw similar numbers of reports about the same type of stolen blogs. The owners typically
- Post their email address, or provide it for contact, visibly.
- Participate in comment based networking, on their blog, and openly state their email address.
- Participate in comment based networking, on similar blogs, and openly state their email address.
Each of these activities can be used, by the bad guys, to build lists of email addresses, of people who can be easily persuaded by an email message, to resolve their policy issues using the link provided. And this led to a number of reports, in the forums, about stolen blogs - and mentioning email, offering to sell the stolen blogs back, to the rightful owners.
If you want contact from your readers, there are more safe ways to allow this.
All of the above contact options give you a possibility of hearing from and / or networking with, your readers - and none of these options require you to disclose your ownership email address.
Just don't disclose your email address, to the world at large. Your email address is one half of the security measure, as designed by Google - that prevents unknown individuals, from taking control of your Blogger account and your blogs.
Finally, if you are not yet using Google 2-Step Verification, this is the time. If you were one of the victims of the recent attack, you know the despair. If not, you truly don't want to be. In either case, you should really want to protect your account, and your blogs.
We see signs of naivete, in Blogger Help Forum: Something Is Broken. too often.I gave my boyfriend (girlfriend, former spouse, Internet acquaintance, whatever) my account password - and now, I can't access my account.
This is a problem which Blogger cannot resolve, in any way.
Please, never ever share your Blogger account. Blogger accounts, like Blogger blogs, are free.
If someone who you know would like to read your private blog - or contribute to your team blog - add that person as a blog member, and let her / him use his / her own Blogger account (new, or existing).
There is absolutely no need for you to ever share your Blogger account.
Use private / team blog membership, when applicable.
Shared Blogger accounts carry all of the risks of team blog ownership - and more. Do not share your personal Blogger account to provide private blog membership, or team blog ownership.
Blogger does not provide an option to protect blog content, using a shared password. If you want to password protect blog content, make the blog private, and add readers. Let your readers use their own password (with their own Blogger account).
Split a blog into a security cluster, if necessary.
If you want to password protect a portion of a Blogger blog, break the blog into two portions - the public portion, and the private portion, and provide the private portion as a private blog.
Private blogs, with large reader communities, will require imaginative setup.
If you must have a private blog with more than 100 members, and you cannot use Google+ as an email based distribution medium, setup a read only account to access the blog - and let the members share that Blogger account.
If you setup a shared Blogger account as a blog member (read only), you'll need to maintain a separate mailing list of all shared members. Use BCC to email everybody (don't share everybody's email address with everybody else), giving them the shared account name and password. Save the mailing list, carefully.
With 100+ shared account members, chances are that one day, somebody will change the password on the account, and lock out everybody else. You'll have to then setup a new Blogger account, make that account a new read only blog member, cancel the old member, and email everybody with the new shared account name and password.
If you must have a community, of over 100 members, and let everybody share (not just read), use Google+ - or setup a wiki based website. Your needs are far beyond the ability of Blogger.
When another person works on the blog, they can use their own account.
If you need someone else to work on the blog, make them a blog member or administrator - with their own Blogger account. If their usefulness is temporary, when they are done, revoke their access to the blog - then verify that they did not leave any back door code behind.
Your account name and password is your personal identity.
In any case, keep your account and password (and the blog ownership) private, to you.
Use common sense. Do not share your Blogger account.
- Do not share your Blogger account with your boyfriend.
- Do not share your Blogger account with your girlfriend.
- Do not share your Blogger account with your husband.
- Do not share your Blogger account with your wife.
- Do not share your Blogger account with your boss.
- Do not share your Blogger account with your employee.
- Do not share your Blogger account with your collaborator.
I've warned everybody that team blogs are security risks - but they are way safer than team Blogger accounts.
- Do not wear other peoples underpants.
- Do not share your Blogger account.
Both are rules to live by.
I've written a few times about protecting your Blogger / Google account, when you use public / shared computers.
Generally, any concern about use of public / shared computers discusses cookies, which are simply invisible traces that you might leave behind when using any computer. If you only use your own computer - and never share your computer - this issue is probably of no concern to you.
If you use a computer that someone else, who you know, also uses, cookies are a small concern. If you use a computer that other people, who you don't know, also use - as in a public computer in a coffee shop or library - this should be a larger concern.
If you look at the Google login screen, you'll see a common option, on many login screens.Stay signed in.
If you hover the mouse over the option, you'll see a small popup.For your convenience, keep this checked. On shared devices, additional precautions are recommended. Learn more.
Clicking on "learn more", you get to read Securely signing in to Google.
The Google Help article mentions cookies as a significant risk to you, when using a public computer ("Devices used by lots of people").Public computers, if well-maintained, automatically clear a user’s web history and cookies. If you’re unsure, we recommend that you use the private browsing feature of the browser. If private browsing isn’t available, clear the browser’s history, cache, and cookies before and after you use the device.
With a shared computer ("Devices shared with a few people"), the risk is less alarming.If you only plan to use the device briefly, such as when visiting a friend or relative, we suggest using private browsing.
If you plan to use the device often (say, for example, it’s your family computer), then we suggest creating a user profile either in the operating system or in the browser so you can keep your information private from other users. We recommend you leave the "Stay signed in" checkbox selected to take advantage of Account Chooser and longer sessions. Learn how to add user profiles on an Android device or in Chrome.
And the final note.If none of these security options are available to you, we strongly suggest you do not sign in to your Google Account. If you do sign in, we recommend deselecting the "Stay signed in" checkbox in case you forget to sign out.
I've discussed clearing cache, cookies, and sessions, in a few articles - and in more than a few forum discussions. In many cases, before the new Google Login (2014) was developed, cookies were moderately significant. Cookies, along with cache and sessions, are normal bits of data, which a knowleagable hacker might find hidden away, on a computer.
With the new Google login display, cookies are a more significant concern. Look at a typical Account Chooser login screen might look like, on a computer shared by a number of people who use Google products.
Would you want any later user of your computer, checking out Account Chooser, and finding your email address in plain view?
If you, personally, only use one Google account, and never use a public or shared computer, you may never see the Account Chooser login screen. If you do see Account Chooser, in its native state (un erased), you will see the account name ("Display Name" in Blogger) and email address of each Google account owner who has used the computer, since cookies were last cleared. Note that the screen print, shown here, has display name and email address, for each of the 5 previous users, erased.
With the Google login display (2014), and Account Chooser, we have gone from account vulnerability to any knowleagable hacker, to account vulnerability to anybody who cares to click on "Use a different account".
Obviously, when using a public computer - and probably a shared computer - you would not want to ever select "Stay signed in". Also, if you ever have to use a public computer, I would always use 2-Step Verification.
>> Top