Social Icons

Pages

Showing posts with label Blog Access. Show all posts
Showing posts with label Blog Access. Show all posts

Friday, 21 December 2012

Visitor Logs Cause Undue Concern, When Visitors Click On Cached Icons

We see periodic concern, expressed in Blogger Help Forum: Something Is Broken, over apparent visitor access to blog maintenance wizards, using the Quick Edit icons.
I found this entry, in my StatCounter log. How did this person get access to my blog?
http://www.blogger.com/post-edit.g?blogID=7834826019588534175&postID=890014875501476492&from=pencil
Was my blog hacked?


This may not be a justified reason to panic, however. One may first wish to check that Stats (or whatever visitor log is in use, in this case) is properly configured, to not track your own activity. The link that you see may reflect your activity.

Even if the visitor log entry in question does not appear to reflect your own activity - even when allowing for the vagaries of geo location, you may still do well to remain calm.

Thanks to the unpredictable nature of cache, in your browser, on your computer, or even on your network, the Quick Edit icon which provides you with access to the sensitive wizards, which control the content of your blog, may also be visible to the casual visitor to your blog. Any idly curious visitor may even click on such an icon, when visible.

However, visibility of the icon does not guarantee access to sensitive blog controls. Here's what I saw, when I clicked on the link above.

D'Ohh!!!

Maybe, you'd like to verify that your blog is safe?
  1. Extract the URL, from a Quick Edit pencil, on your blog.
  2. Save the URL, somewhere safe.
  3. Clear cache, cookies, and sessions (yes, clear all 3!).
  4. Restart your browser.
  5. Load the saved URL.
  6. What do you see?

Similar to the problem with phantom visitors reading a private blog, this may not be an issue to concern you. Calm down, and get back to work.

>> Top

Wednesday, 15 August 2012

A Team Blog With No Administrators Is Given To The Authors, For Their Control

We have known, for a while, that every Blogger blog has to have at least one administrator.

That rule is enforced by the Permissions wizard, which gives any administrator the choice to demote or remove any administrator, from the Permissions list - but only when there is at least one other administrator in the list.

When the Permissions list is displayed, if there are at least two members with administrative authority, each administrator entry, in the list, has a link to demote or remove that member. If there is only one member with administrative authority, there is no such link - and that member can be neither demoted or removed from the list.

As long as only the Permissions wizard is used, to demote or remove administrators, this article would be meaningless (see the above link). But, there is another way for administrators to be removed - and this occasionally leaves blogs with no administrator.

If the only way to lose an administrator (or member) from a blog was by using the Permissions list to demote or remove, then the Permissions list setup, as described above, would be sufficient.

Unfortunately, the Blogger - and Google - account deletion processes don't consider the member lists for the blogs owned by the account. When a Blogger account is deleted, the fate of the blogs owned, by that account, has to be decided later.

Any blogs which have only one member (the owner) are either frozen or deleted - as with only one owner, there is no need to keep those blogs. Any blogs with more than one member simply lose that one member. But what if a blog has more than one member, but only one administrator - and that one administrator takes a hike?

With a team blog with one administrator, and one or more authors, losing the one administrator would leave a blog that was being published (by the authors), but could not be managed (because there was no administrator). This would, in the past, lead to panic in the forum.
The administrator for my blog deleted his Blogger account - and now my blog has no administrator! What do we do now?

With no administrator existing, Blogger Support would be summoned, and would have to determine whether a blog:
  • Had no administrators.
  • Had at least one author.
  • Was being requested by a person who had a legitimate need to request control (a former administrator, or a current author).
Failure to ensure that each condition was being properly met could, with the right problem report, allow a hijacker to improperly assume control of someone's blog - with only Blogger Support to blame for enabling the hijacking.

To allow control recovery without needless delay, and avoid the need for endless detail in verifying any such panicky report, Blogger Engineering made a simple procedural change. The "Forgot your username or password?" wizard, when control recovery is requested for a blog with no administrator, simply sends the appropriate access tokens (aka "login instructions") to all blog authors - as long as the membership list is well maintained.

Any blog authors, able to receive the login instructions, then become de facto administrators - and can jointly determine the fate of the blog. The control recovery process can be automated, and the risk of possible hijacking of actively owned (administered) blogs is reduced. This simply requires that at least one blog author uses a Blogger account based on an active and genuine email address - and if necessary, can search persistently for the email sent.

When this reset process is done, each author of the blog initially has the same power as each of the other authors. Blogger leaves it to all authors to act honourably - and to politely choose one or more authors to be administrators. As long as the author submitting the reset process is able to locate the email message in his Inbox immediately, he can make himself the sole administrator - if he decides.

If one of the authors has problem locating the email, it's possible that the other newly appointed administrators could unwisely hijack control of the blog. If this happens, it will be up to the authors to jointly establish order. Blogger Support will not be involved in any conflict.

The more authors a given blog may have, the greater the chance that one author, receiving the email message, may act dishonourably, and hijack the blog. In cases where there are a large number of authors (precise number not known, right now), Blogger will defer to the author requesting the reset.

In this case, the author requesting the account reset can enter his email address, that is used by his Blogger account, to have the password reset email sent directly to him.

>> Top

Tuesday, 24 July 2012

Having A Blogger Blog Removed Or Restored, After Death Of The Blog Owner - The Next Chapter

The question of disposition of blogs, left behind by deceased blog owners, comes up in Blogger Help Forum: How Do I?, from time to time.

As Blogger blogs - and similar Google products - become mature, and as more people who publish Blogger blogs become susceptible to old age and death, this problem will become more critical. As recently as 2010, in order to assume control (or request deletion) of such a blog, Blogger required only a faxed copy of the death certificate.

We are now seeing that the death certificate is only one part of a formal procedure, which Blogger / Google now uses, in the dual role of
  • Compassion, in allowing a friend or loved one to appropriately assume control of blogs left behind.
  • Due Diligence, in preventing fraudulent claims by people who have no legal or moral right to assume control of blogs.
Both roles are righteous, and are needed to help Google reduce hijacking of active Blogger blogs.

As part of an improved procedure for disposition of Blogger blogs left behind by deceased owners, Blogger now uses GMail Help: Accessing a deceased person's mail as guidelines. The new guidelines
  1. Use a two part process - a preliminary review, followed by a formal court documented process.
  2. Include a dedicated facsimile transmission / postal mail address.
  3. Include additional requirements, which formally identify the relationship of the person requesting control of the blog in question, to the deceased.

The preliminary review specifies a facsimile transmission / postal mail address:
Google Inc.
Gmail User Support - Decedents’ Accounts
c/o Google Custodian of Records
1600 Amphitheatre Parkway
Mountain View, CA 94043
Fax: 650-644-0358
and a formal list of material required, for Part 1 - preliminary review.
  1. Your full name.
  2. Your physical mailing address.
  3. Your email address.
  4. A photocopy of your government-issued ID or driver’s license.
  5. The Gmail address of the deceased user.
  6. The death certificate of the deceased user. If the document is not in English, please provide a certified English translation prepared by a competent translator and notarized.
  7. The following information from an email message that you have received at your email address, from the Gmail address in question:
    • The full header from the email message. See instructions on how to find headers in Gmail and other webmail email providers. Copy everything from 'Delivered-To:' through the 'References:' line
    • The entire content of the message
When specified by Blogger Support, we were instructed to substitute the blog URL, for the Gmail address (as #5). No addendum referencing the email message (as #7) was provided.

The instructions for Part 2 are not as well defined, as for Part 1.
Part 2 will require you to get additional legal process including an order from a U.S. court and/or submitting additional materials. Please note that submitting these materials will not guarantee that we will be able to provide Gmail content so we recommend not embarking on Part 2 until you hear back from us regarding Part 1.

These requirements may seem onerous to the less observant. Actually, by formalising the process, this should reduce the number of fraudulent claims, and make it easier for Google personnel to legitimately process claims, while exercising both compassion and due diligence.

>> Top