Almost daily, we see a confused query in Blogger Help Forum: Something Is BrokenI lost ownership access to my blog. Can Blogger restore my access?
Not every blog owner realises that the Permissions wizard has a safeguard, ensuring that every blog will always have at least one administrator. Anybody who is the former owner is now a member of a team blog - and at least one other team member is an administrator.
The ownership transfer process involves 4 steps, out of necessity.
- Invite a new member (if necessary).
- Wait while the new member accepts the invitation (again, if necessary).
- Make the new member an administrator.
- Remove the old administrator (if necessary).
Each step can be executed immediately, or with any amount of elapsed time after the previous step, at your convenience.
Look at the Permissions wizard for your blog, some time. If you are the only administrator, you will see your name, with no ability to delete or demote yourself.
A team blog will have author status selectors.
If you own a team blog, you'll have a selector for each of the team members who are authors, allowing that member to be promoted to administrator status.
A team blog with multiple administrators will have administrator status selectors.
If the team blog has at least 2 administrators, each administrator will have a selector, allowing any administrator to delete or demote any administrator. As an administrator demotes any administrator to an author, the entry for that new author will have the ability for that author to be again promoted to administrator.
A blog with only one administrator will have no administrator status selector.
Whenever you are the only administrator, your member entry will have no ability to delete or demote. This prevents you from having a blog with no administrator.
Of course, as noted elsewhere, when the blog has at least 2 administrators, any administrator can be deleted or demoted at the decision of any other administrator. Also, team status is not checked when accounts are deleted.
If you are demoted, only an administrator can promote you.
The bottom line here is, if you suddenly find yourself without administrative access to your blog, the advice that you will get will be to
Ask one of the blog administrators to restore your status.
To prevent blog theft, only another administrator can restore your status.
Many bloggers are confused about how to protect their blogs, both from unauthorised administrative access, and unauthorised viewing. An example of the confusion is the occasional questionHow do I set a password in my blog, to prevent unwanted viewers?
and the correct answer here is simple.You can't set a password. Blogger uses two factor authentication, to protect your blog.
If you own a house or a car, you may occasionally wish to provide guest access to your house or car. Maybe you have an extra key, which you lend to your guests, so they may use your house or car at their convenience. If you've done this, you may observe inconveniences caused by availability of a shared key.- A key may be lost, necessitating re keying of the locks, and distribution of a new key to all who have access.
- You may not wish for your guests to have access to the entire house or car, at all times.
- You may not wish for your guests to have access to the entire house or car, permanently.
- Your guests may decide that carrying another key, on a separate key ring, may be too much trouble. They may wish to put your key on their key ring. This can cause more complications.
- Distributing, and maintaining, a key library to everybody may simply be a lot of work.
In higher priced houses or cars, people have discovered the advantages of using electronic locks, which can provide more choices than simply providing a single key, available identically to everybody.
Blogger uses two factor authentication, which is equivalent in sophistication to the electronic lock which you use (or may wish to use) on your house or car. This allows you, and your guests, convenient and protected access to your blog. Two factor authentication provides more convenience, and protection, to both of you.- You identify your guest by their public email address, and send them an invitation to your blog.
- Your guest accepts the invitation, using the Blogger account of their choice, and using their own personal password.
- You are safe from your guest, and your guest is safe from you, from either of you knowing too much about each other.
If you wish to provide additional access to your blog - either another administrator, another author, or a designated reader, use the Settings - Permissions wizard, and add a member of the appropriate type. That's how you manage blog access.
>> Top
Long ago, Blogger blogs had a very simple membership permissions policy.
Each blog had an owner, and members. The owner was the administrator of the blog, and ownership could not be transferred.
This simple policy was a problem, because some blog owners would eventually lose interest in a blog, and want to cede ownership to someone else. In other cases, people were known to die suddenly, leaving blogs with no live owners. In both cases, Blogger Support would become involved, and would manually transfer ownership.
Later, Blogger developed the Permissions wizard, and added a class of member called "Administrator". The original publisher of a blog becomes the first administrator, who may, at his / her discretion, designate additional administrators.
The ability to designate an "Administrator" solved the problem of nontransferable ownership, but introduced a second problem.
Any administrator could, at her / his discretion again, remove him / herself (or any other administrator) from the administrators list.
Initially, this improvement created two problems.
- Some bloggers managed to remove all administrators from the list, creating blogs with no administrators.
- Some bloggers, newly made administrator, would inappropriately remove other bloggers (including the original administrator aka "owner") from administrative status.
Blogger fixed the first problem, by adding a safeguard - making the Permissions wizard check for the presence of other administrators in the membership list, before removing administrator permission from any one member. However, there remain two problems, now.
- The safeguard works only if you can guarantee that all administrators can perform as administrators.
- This policy works only if you can guarantee that all administrators will perform honourably.
If blog membership is to be fully transferrable, all administrators to a blog have to have equal status. If you have an "owner" class of administrator, and a suddenly dead owner, you have a blog with no active owner. Or, you have blogs with non transferrable ownership status.
Right now, anybody who is a blog administrator is a blog owner. If you make someone an administrator, and that person removes you (and any other administrators) from administrator status, that person becomes the blog owner.
If you have an administrator who dies, you do not prune the administrator list, and you are able to remove yourself from administrator status, you may end up with a blog with no live owner.
The administrator(s) / owner - whoever she / he may be - has the right to decide over disposition of comments and posts - and of who to make a member, and to make an administrator. Blogger cannot, legally, "restore" anybody's previous rights.
If the "owner" deleted the blog, it's going to remain deleted. Contributors, and former "owners", have no say in the matter. If deleted content must be recovered, it may be possible to do this on a page by page (post by post) basis - possibly from blog cache or a blog posts newsfeed.
Possession is the law, for Blogger blogs. If you gave up control (voluntarily or even involuntarily), it's not your blog.
When you invite a designated reader to your private blog, or invite a member to your private or team blog, you use the Settings - Permissions wizard to send an email to the prospective member or reader. You select the email address to send the invitation to, based upon the known address of your prospective member or reader.
The prospective member / reader, upon receiving the email, is free to send it on, to any other email address that he or she uses, and to accept the membership by using any Blogger account - current, or setup at the time of accepting the invitation.
This allows anonymity in membership, by permitting somebody to accept membership, period. You have no way of knowing, nor should you know, what account or what email address your new member uses to accept membership. The only thing that you know is that a membership invitation was accepted, by a given prospective member.
Unfortunately, just as you don't know what account the membership was accepted under, you have no way of knowing how many people other than your targeted member were sent a copy of your invitation. That's a possible reason for some blogs mysteriously exceeding the 100 member limit.
The bottom line here is, just as you must choose your blog administrators wisely, so should you choose your members and readers. Don't just send an invitation to somebody, without considering the possibilities.
Occasionally, we see a confused queryHow do I allow access to my blog, and keep my GMail account private to me?
orHow do I have my friends using my blog, and each person use their own name in publishing posts?
These are people who do not understand the concept of team blogs.
Team blogs use a separate Blogger / Google account for each member, they do not require everybody to share one Blogger / Google account. You add each team member as an Author, in Settings - Permissions. When you do this, note two cogent details.- Each blog is limited to 100 Members (Authors + Administrators + Owners), in total.
- You can invite members, using the email address that you know. People can accept membership using what email adddress (Google account) they wish. People may be able to accept multiple member entries, which may affect the 99 author limit.
If either of those two details are a problem to you, perhaps you should look at Content Management Systems. A CMS may give you more control over access to your blog.
>> Top
We've known for a while that private blogs have limitations, such as latency.
If you originally publish your blog as public, and later make it private, cached copies of the blog will be all over the Internet, for anybody to read, after it's supposedly private. This week, we see another, possibly more serious limitation.Why was my coworker able to read my very private, personal, password protected blog yesterday? I had it set to "Blog Author Only" and yet she found it and was able to read the whole thing.
It has never, ever been public. I started it last September and set the permissions to "blog author only" at the start for all posts. I have never invited anyone else to read it...and have never, ever logged into it at work.
The private blog interstitial may not be loaded, for any would be reader, for several reasons.
The private blog interstitial won't be loaded, before every access to the blog.
People with blog content cached locally - either on their computer, or their network - won't always requires Blogger server access, when a blog page is displayed. Some visitor logs will detect blog access, even when cached content is retrieved - and even when the private blog interstitial is not involved.
Some readers may inadvertently provide access to other network users.
Occasionally, while using slow Internet access, I might load a private blog.
As the blog loads, the browser identifies the various components of the blog, such as various pictures loading, in the browser status area. An odd interstitial notice might be seen.
This blog is open to invited readers only
It doesn't look like you have been invited to read this blog. If you think this is a mistake, you might want to contact the blog author and request an invitation.
This might come up well after the blog main page contents have loaded.
If you are surfing from a network which uses a caching proxy server, it's possible that one person who has permission could properly load the blog in their browser. With the blog having been loaded once, the proxy server may not load the interstitial page again. Anyone else on the network could later view the blog without the interstitial page - even if they do not, supposedly, have permission to do so.
If your Blogger profile is part of your public blogs, or people link to your profile while surfing profiles, and your private blog is listed as one of your blogs, someone may click on the link, and may get a view of the blog.
Invited readers may intentionally share their recently received invitations.
A second problem comes when you invite people as members of your blog. The invitation goes to specific people, who are free to forward the invitation to their other email accounts, and even to the email addresses of their friends. You may invite one person, and you may see a dozen persons later reading the blog. This may even account for a known discrepancy with the 100 member limit.
These security deficiencies are not ones that you can control. You have no way of denying anybody access to your profile, if it's published publicly. Nor can you stop people who you invite to your blog, from forwarding the invitation to their friends.
If you want to keep your blog private, it would be a good idea to at least remove it from the list of your blogs, in your profile.
Private blogs are not immune to referer spam.
Some entries in some visitor logs might make us think that unauthorised people are reading a private blog. Referer spam is not blocked by the private blog interstitial - since referer spam does not involve actual blog access.
As previously stated, visitor logs are not 100% accurate.
These various issues contribute more reasons why no visitor meter will ever be 100% accurate.