Showing posts with label Travel. Show all posts
Showing posts with label Travel. Show all posts

Sunday, December 28, 2014

GeoLocation, And Our Use Of Blogger

Recently, we've seen signs of confusion, from people who have problems with their Internet service, which shows them moving around their geographic region.
I logged in to Blogger, with no problem, yesterday. Today, after logging in successfully, I am asked for more details, to prove my identity!!
This blog owner has a problem with location based security.

Not all Blogger blog owners or readers understand that Country Code Alias Redirection, and the ability to access one's Blogger / Google account (and prevent others from accessing it), both depend upon the ability to determine the geographical location of each blog reader.

Various Google features, like Country Code Alias Redirection, and Google login, use geolocation, to identify the location of each reader.

For people using the Internet, Geolocation uses the Internet connection, to determine physical location. Unfortunately, for many blog owners, the Internet Service Provider, the Internet connection, and the Internet customer (or Blogger blog reader) may each be in a different location.

My own location - even when I am at home - may, at times, appear to move in a 30 mile radius. My ISP routes my connection through any of half a dozen different connection points, in my region, depending upon current network activity.

Some smaller ISPs, located near a country border, may actually get service through a larger ISP in another country. Customers of the smaller ISP may appear, through geolocation, to reside in the other country.

This can be an unfortunate problem, with country code alias redirection, with language detection, with login authentication, and / or the Location option in Post Editor.

People located in one country, reading an unfamiliar language, or seeing their latest post show up in the wrong province / state - or even country - may not appreciate the confusion which is caused. And people who login, and appear to move from city to city in the region, grow tired of having to prove their identity - after successfully entering account name and password.

Thanks to domain based filtering, this may become a security issue for some blog owners, near country borders, who may not be able to maintain / publish their blogs.

Unfortunately, geolocation, using the Internet Address (aka "IP" address), will never return consistent and precise results. Any location based processes will always provide fuzzy results, thanks to Internet services which load balance their network connections.

Friday, December 26, 2014

If You Travel, Be Prepared To Prove Identity

We're seeing reports from people who claim to be traveling, and who can't login and access their blogs.

Google appears to now authenticate us using current location, as well as account name / password. We see occasional reports, in Blogger Help Forum: Get Help with an Issue, about new security procedures.
I am traveling, and I need to access my Blogger account from another country. I know my account name and password - and I logged in successfully. But after logging in, I am still being asked to prove my identity!!
This blog owner is finding a problem, with Google taking extra measures to protect our accounts and blogs.

Google is trying to protect us, from people who access the Internet from different countries - and who try to access our Google accounts, and steal control of our blogs.

Somebody in a foreign land, accessing your account, may not be you.

If you normally access the Internet from your home, and you travel to another location and try to login to Blogger / Google, you may be asked for additional details, to prove that you are the legal owner of your Blogger account. You may feel like you are being treated discourteously, when this happens.

In reality, Blogger is simply trying to keep your blogs under your control, by preventing people other than you from stealing your Blogger account, blogs, and email account - and possibly, your friends Blogger account, blogs, and email account.

When you travel, you spend time preparing for the trip.

When you prepare to travel to a distant country, you are responsible for getting your travel documents (passport), permissions (visas), maybe make health preparation (update immunisations, get extra medications) - and learn a minimum amount of the local language, before you go.

Maybe you should also spend some time getting your Blogger / Google account in order (update any backup details, such as backup email address and phone number). Even, plan an account recovery, from time to time.

This is an excellent time to try 2-Step Verification.

You might even consider setting up Google 2-Step Verification - and generating a set of one time backup authentication codes.

If you don't prepare your account for travel, you may have to wait until you get home, to post to your blog. You may even be asked for proof of identity, when you get home, too.

Monday, November 17, 2014

Clearing Cache, Cookies, And Other Website Data

Most of us, as we surf the Internet, are going to surf some websites, repeatedly.

Everybody has favourite websites. When we surf the same website, over and over, some of what we do and see may not change a lot.

To keep us from wasting our time, and generating unnecessary network traffic, our browsers keep track of the websites that we visit over and over, save records of what we do and copies of what we see, and note what has changed. The website content, stored locally, is known as "private" data.

There are times when we need to clear "private" data. Note the different browsers - and the different menus and selections, provided by each browser.

  • If you have a problem when viewing your blog - or if you wish to immediately refresh your personal view of your blog, you should clear "cache".
  • If you have a problem maintaining or publishing your blog - maybe when switching between Draft and Production Blogger, you should clear "cookies".
  • Whenever you clear cookies, you should clear cache, also - so, if you have a problem when maintaining or publishing your blog, you should clear "cache, cookies, and sessions".

There are other reasons for clearing private data - but there are also reasons for not clearing private data, indiscriminately. It will be worth your time, to understand what and when you should clear - and not clear.

Normally, you would not, routinely, clear private data.

What if you use a publicly shared computer - maybe in a coffee shop or library? Or maybe, you carry your computer to a coffee shop or library? Do you want your private details - such as account names, passwords, even a list of what websites you surf - being available for other patrons of the coffee shop or library, after you leave?

Most of us do not want our private details, visible to any curious fellow patron - or maybe to our family either. But not all data is equally as damaging, if revealed to strangers, or to people who know us.

To help us keep our private lives private - yet not waste time or generate unnecessary network traffic, our browsers offer us the opportunity to save some content, and to delete other content - when we know what options are available to us.



Cache is simply locally stored copies of code and static pages, that you and other people, using the computer, might accumulate. Cache contains no sensitive, personally identifying material - other than (again) possibly identifying what websites you have visited.

If you share a computer with another person, identifying what websites you visited, and what websites the other person visited, will require knowing times each of you used the computer. There are no personal identifiers which indicate which of you visited a given website.

Forms contain online entered data, such as account names. Forms are slightly less sensitive than passwords, since they may contain large volumes of random data. Look at the boxes in the Blogger dashboard - those are all forms. Hidden in the forms, you may find an account name - or an email address. It's like asking how dangerous a needle may be, in a stack of hay.

History is a log, describing what websites, and website pages, that you have visited. History might be important if having people, other than you, know that you visit certain websites; other than the personal embarrassment possibility, history is relatively harmless.

Passwords are the most sensitive bit of data, that you can store on your computer. Someone extracting your passwords, on a per website basis, can use your account in each website, to operate as you. An online password is just as sensitive as the password (aka "PIN") that you might enter at an ATM.

Preference cookies (aka "cookies") are local storage of website relevant details. Preference cookies are miscellaneous settings, used to remember choices which you might make, when viewing a given website, repeatedly. Some browsers identify "preference cookies", and "session cookies", collectively, as just "cookies". Firefox, in various places, identifies "preference cookies" as "cookies", and "session cookies" as "sessions".

Session cookies (aka "sessions") are a cookie, designated by some browsers, as containing login identifiers, and other data relative to one website visit (but let you extend one "visit" to include multiple browser openings and closings). Firefox designates the Blogger login cookie as a session cookie. This is why, when I advise you to clear Blogger dashboard problems, I always specify clear "cache, cookies, and sessions".

In order of sensitivity, I would rank the above elements in a different order.

  • Passwords.
  • Forms.
  • Session cookies.
  • Preference cookies.
  • History.
  • Cache.

Look at cache, to start. Cache is locally stored copies of content, from remote servers. Other than inadvertently revealing our favourite naughty content, there is no danger in cache content being seen to other people. There are three scenarios, when we might want to clear cache.

  • To clean up the computer, when it is running slower than normal.
  • To provide an up to date copy of a website, immediately.
  • When investigating a website login problem, such as a Blogger dashboard problem, which requires clearing cookies.

Cache takes up thousands as much space as cookies, and as passwords.

At the other end of the sensitivity scale, you find Passwords. My personal advice is to not store passwords, period. If you want convenience when accessing a website like Blogger, which offers long term login sessions - when you use a private and safe computer - simply don't log out, from Blogger. If you never clear session cookies, you never have to log out.

If you enjoy the convenience of online banking, on the other hand, you should always log out after an online banking session. If you never store passwords, for online banking, you never have to worry about clearing passwords.

In the middle of the scale, we find Cookies. A cookie is a small, encrypted file, which contains a single setting that lets us visit the same website repeatedly, without having to re enter something.

The Google login cookie (aka "session" cookie) lets us visit Google (and Blogger), and maintain our blogs, without having to login, over and over. This is the infamous "third party" cookie which we need, to use Blogger readily.

Cookies, since some provide login data, are encrypted. Open a cookie file, using a text reader, and see what is there (But do not use "Save" to close the text reader), if you wish to understand.

If you have a problem when viewing your blog - or if you wish to immediately refresh your personal view of your blog, you might clear "cache". If you have a problem with your Blogger dashboard - maybe when switching between Draft and Production Blogger, on the other hand, you would want to clear "cookies". Whenever you clear cookies, you should clear cache, also - so, if you have a problem when maintaining or publishing your blog, you will be advised to clear "cache, cookies, and sessions".

If you have inconsistent private data (cookies don't properly match cache or scripts), you may have to deal with one of the mysterious bX codes. When this happens, then clearing "cache, cookies, and sessions" may be one of the first things to try.

Note that not all problems involving "cache" or "cache, cookies, and sessions" may be solved by "clearing cache" or even "clearing cache, cookies, and sessions". Some problems may require corrected filtering. Also, not all problems, that involve cache, can be necessarily solved by clearing browser cache.

All of these are personal preferences, which I exercise - when using my own personal computer, in the privacy of my home. Other people may be more strict - or some computer owners may never clear anything. When using your computer outside your home - or maybe, when using a public computer - you may wish to be more careful.

My personal advice, for using a public computer, is simple.

  • Never, except in an absolute emergency, use a public computer for online banking.
  • Whenever finishing a session on a public computer, always clear all private data, and restart the computer.

Some short term use public computers, such as stand up terminals in libraries and shopping centres, are specially designed to reload the entire system configuration, and operating system, and wipe all "private" data, after each individual person has used the computer. If you must use a public computer, those would be the safest ones to use.

Similarly, if you carry your own computer outside your home, you may be concerned with other people seeing what's on your computer, intercepting your network activities (if you use a public network), and / or stealing the computer. Depending upon which possibility concerns you, you might take any or all precautions, before carrying the computer out the door.

  • Clear passwords (if you store passwords, locally).
  • Clear history and cache (if you fear people browsing your computer).
  • Clear all private data (if you fear theft).

Who knows what embarrassment (financial, and personal) you might save yourself, by thinking ahead?

Thursday, April 3, 2014

The New Google Login, And Using Public / Shared Computers

I've written a few times about protecting your Blogger / Google account, when you use public / shared computers.

Generally, any concern about use of public / shared computers discusses cookies, which are simply invisible traces that you might leave behind when using any computer. If you only use your own computer - and never share your computer - this issue is probably of no concern to you.

If you use a computer that someone else, who you know, also uses, cookies are a small concern. If you use a computer that other people, who you don't know, also use - as in a public computer in a coffee shop or library - this should be a larger concern.

If you look at the Google login screen, you'll see a common option, on many login screens.
Stay signed in.
If you hover the mouse over the option, you'll see a small popup.
For your convenience, keep this checked. On shared devices, additional precautions are recommended. Learn more.
Clicking on "learn more", you get to read Securely signing in to Google.

The Google Help article mentions cookies as a significant risk to you, when using a public computer ("Devices used by lots of people").
Public computers, if well-maintained, automatically clear a user’s web history and cookies. If you’re unsure, we recommend that you use the private browsing feature of the browser. If private browsing isn’t available, clear the browser’s history, cache, and cookies before and after you use the device.
With a shared computer ("Devices shared with a few people"), the risk is less alarming.
If you only plan to use the device briefly, such as when visiting a friend or relative, we suggest using private browsing.

If you plan to use the device often (say, for example, it’s your family computer), then we suggest creating a user profile either in the operating system or in the browser so you can keep your information private from other users. We recommend you leave the "Stay signed in" checkbox selected to take advantage of Account Chooser and longer sessions. Learn how to add user profiles on an Android device or in Chrome.
And the final note.
If none of these security options are available to you, we strongly suggest you do not sign in to your Google Account. If you do sign in, we recommend deselecting the "Stay signed in" checkbox in case you forget to sign out.

I've discussed clearing cache, cookies, and sessions, in a few articles - and in more than a few forum discussions. In many cases, before the new Google Login (2014) was developed, cookies were moderately significant. Cookies, along with cache and sessions, are normal bits of data, which a knowleagable hacker might find hidden away, on a computer.

With the new Google login display, cookies are a more significant concern. Look at a typical Account Chooser login screen might look like, on a computer shared by a number of people who use Google products.

Would you want any later user of your computer, checking out Account Chooser, and finding your email address in plain view?


If you, personally, only use one Google account, and never use a public or shared computer, you may never see the Account Chooser login screen. If you do see Account Chooser, in its native state (un erased), you will see the account name ("Display Name" in Blogger) and email address of each Google account owner who has used the computer, since cookies were last cleared. Note that the screen print, shown here, has display name and email address, for each of the 5 previous users, erased.

With the Google login display (2014), and Account Chooser, we have gone from account vulnerability to any knowleagable hacker, to account vulnerability to anybody who cares to click on "Use a different account".

Obviously, when using a public computer - and probably a shared computer - you would not want to ever select "Stay signed in". Also, if you ever have to use a public computer, I would always use 2-Step Verification.

>> Top

Navigate» Become author for this Blog