Social Icons

Pages

Showing posts with label Blog Security. Show all posts
Showing posts with label Blog Security. Show all posts

Saturday, 28 September 2013

Team Blogs, And Confusion About Blogs Locked After Detected Account Hacking

We've been discussing deleted blogs, resulting from Blogger accounts locked after suspicious account activity is detected, for some time.

Recently, we've seen a variant on the account lock / deleted blogs problem.
I made one of my friends an admin for my blog. When Blogger deleted His Blogger account and his blogs, they deleted my blog also.
Here, we see the possibility of detected hacking, affecting other members in a team blog ownership.

If someone sets up a blog, then invites his friends to be administrators, everybody on the team becomes equal owners. This can also happen when one person maintains two or more Blogger accounts - whether accidentally or intentionally.

That's the definition of a team blog - and it's one known problem with team blogs. This case shows us another problem with team blogs.

If somebody on the team has a Blogger account locked for detected hacking, all blogs owned by that account are taken offline, for security checking. Any blogs owned by that account are going to simply disappear from the dashboards of all owners - because all owners produce the same security risk, to any owned blogs.

When a Blogger account is locked, review of blogs owned by the account starts after the account is unlocked. If the team member with the locked Blogger account doesn't get the account unlocked, the blogs owned can't be reviewed.

Once again, we see why it's a good idea to only have active team members, as blog owners.

>> Top

Sunday, 9 June 2013

Blog Content, And Confusion About Blogs Locked After Detected Account Hacking

One Blogger mystery involves the varying periods of blog unavailability, after hacking activity is detected.
My blog just disappeared from my dashboard - and no, it's not listed under "Deleted blogs"!

When the owner mentions the notice about "suspicious" / "unusual" account activity, or having unlocked the account (by solving a CAPTCHA, receiving a phone message, changing the password) - and is advised to wait "24 to 48 hours" - many ask the obvious.
Is "24 to 48 hours" really accurate?

In reality, the legendary "24 to 48" hour time period is only a ball park figure - and both Blogger / Google, and the blog owner, contribute to the uncertainty.

The well known advice to "Wait 24 to 48 hours", after a Blogger account is locked for suspected hacking activity, is only an estimation of the waiting time, which the owner may have to endure. This is account / blog integrity verification.

There are several factors which can contribute to the accuracy of "24 to 48 hours" (which maybe should be stated as "one to two business days").
  • Availability of essential Blogger / Google personnel.
  • Current hacking activity level, and ongoing Blogger / Google workload.
  • Blog content, which complicates hacking payload analysis.

We've referenced the first two factors (personnel, and hacking activity level) in the well known Blogger FAQ How long will it take?. The third involves detail which only the blog owner can provide. Many blog owners contribute to this uncertainty, in the development of their blogs.

There are several types of content, which hackers like to add, to blogs temporarily under their control.
  1. Advertising - and similar shiny accessories.
  2. Custom code - and various template tweaks.
  3. Links to other blogs - and to websites outside Google address space.
  4. Team memberships - and multiple blog owners.
All of these features, also added by the owner - and allowed (and encouraged) by Blogger - can require extra effort as a blog is validated, after detected hacking activity.

Blogger / Google security experts, in examining an account / blog, must look for features possibly added by the hacker. Security experts have no immediate knowledge what was added by the owner, long ago - as opposed to by a hacker, more recently.

Any advertising, custom code, external links, or team memberships, intentionally added by the owner, will contribute to time spent validating blog integrity.
  • Leave a setting or tweak added by the hacker - and the blog remains a security risk, when returned to service.
  • Remove a setting or tweak added by a blog owner - and the blog becomes broken, when returned to service.
Neither is desired, by the blog owners - nor by Blogger / Google.

More accessories and tweaks == more time spent by security experts == more time the blog remains offline, while the owner waits in uncertainty.


This uncertainty, added to delayed deletion caused by cache latency, leads to mystery.

All of this brings to mind the old adage.
KISS
Keep it simple, stupid.

>> Top

Friday, 10 May 2013

Comment Moderation In Blogger Blogs, Using Google+ Comments

With more Blogger blogs being updated to use Google+ Comments, we're seeing a few questions in Blogger Help Forum: How Do I?, about comment moderation.
How do I moderate comments, with Google+ Comments enabled on my blog?

This is a question for which there is no easy answer - and this is one of the least appreciated feature limitations of Google+ Comments.

Native Blogger commenting allowed the option to moderate comments before or after they were published.

Google+ Comments, for Blogger blogs, provides no ability to moderate before publishing. All comments must be moderated after they are published. Moderation now simply consists of the ability to declare a comment as abusive - and this ability is shared equally by all users of Google+, who are in the right Circle to read and mark any comment.

With native Blogger Commenting, you (the blog administrator / owner) could moderate comments (before or after publishing), using either email, or the dashboard Comments section. With Google+ Comments, you have no such ability - and the dashboard won't even have a Comments section, listing comments made against the blog. You can view comments made - when you are able to view them - on a post by post basis, under each post.

As the blog owner, you do not have control over all comments, published against your blog. If you allow comments using Google+, anybody who is in one of your Circles can publish a comment against your blog. If you Share a blog post to the Public - or if someone else Shares a post from your blog to the Public - and a third person comments, you may not even see the comment made, against your blog.

You cannot see comments published by people who are not in your Circles, unless the comments are posted Publicly - even if the comments are published against your blog.

For these reasons, this blog remains with Blogger Commenting.

We have a Problem Rollup discussion where we are soliciting feedback from each blog owner, who sees this new feature - Google+ Comments - to be unacceptable as designed. If you are able to provide your opinion, in the rollup discussion, please keep your remarks brief and polite - and stay on topic.

>> Top

Friday, 22 February 2013

Browser Cache, And Confusion About Blogs Locked After Suspected Account Hacking

The effects of browser cache, upon our Internet life, are not always understood.

Most of us know, by now, to clear cache and restart the browser, after updating a blog, for consistent testing. Some folks know that blog security changes don't always take complete and immediate effect.

Recently, we're seeing a new effect, reported by owners of Blogger accounts locked, after hacking activity is detected.
I got a message mentioning suspicious account activity, when I logged in to Blogger. I provided my phone number, and I received a code on my phone, that I had to enter before I could then log in. My blog was working fine just after I logged in. A short while later, though, it was gone. Why was my blog deleted, because I unlocked my account?
This blog owner is just slightly confused, about the cause and effect here.

Google robotic processes are constantly monitoring account login activity, and watching for signs of hacking activity, such as brute force password entry.

When hacking is detected, the detection may not be immediate - so Google protects us by considering the possibility that the hacking could have been successful, and deletes or locks blogs owned by the account under attack. The blogs in question are taken offline, immediately, when hacking is detected.

If a blog owner has just been working on a blog, as is frequently the case, the blog contents will be cached somewhere between the owner and the Blogger servers. Blogger can take the blogs offline, on their servers - but any cache containing the blogs will remain. If the blog owner is working on a blog while the Blogger account is under attack, what's in cache will remain, visible to the owner, until cache expires.

If a Blogger account is attacked, and the attack is detected, shortly after the owner has viewed a blog, what's in cache will be used, until it expires. The owner won't see the effects of the blog being deleted until the cache expires, and the browser tries to retrieve a fresh copy from the Blogger servers.

The blog owner sees the blog go offline shortly after he verifies account ownership, and thinks that the verification process caused the blog to go offline. In reality, the blog was taken offline before the owner even knew of "suspicious" account activity.

Now, the blog owner can do nothing, except wait until the account and the blogs are examined for signs of tampering. In some cases, no notification of progress will be received - and the owner will see the blog(s) returned to service, sometime later.

How much later the blogs return to service will vary widely, depending upon several details - and this variation, added to the uncertainty caused by cache latency, leads to mystery.

>> Top

Saturday, 9 February 2013

Deleted / Locked Blogs Have Several Causes, And Various Resolutions

Many blog owners are occasionally confused, by the effects of several Blogger / Google security processes, when they are simply trying to login to Blogger and work on their blogs. We see the agony, daily, in Blogger Help Forum: Something Is Broken.

The side effects of the security processes are similar - and depending upon various owner specific details, can be easily confused for each other. The possibility of confusion requires careful initial analysis, when we are faced with an angry blog owner.
My blog was deleted, by Blogger. How could they do this? I do not publish spam!
This is a typical problem report, which can reflect any one of the processes, each requiring different action in the forums.

There are various Blogger / Google security / TOS enforcement processes, each of which will cause a Blogger account and / or blog to be unavailable for full access, at any time.Each different process has a different effect on the Blogger account and blogs owned - and requires different attention by the blog owners, by the forum helpers, and by Blogger Support and Google Security.

DMCA Violation

Accounts and blogs can be deleted, for progressive DMCA violations.

The DMCA violation process originated with complaints made by the major entertainment industry content enforcement organisations, citing theft of "intellectual property" which they control. In the USA, this would involve the "MPAA" (Motion Picture Association of America), and the "RIAA" (Recording Industry Association of America). I have been told that similar content enforcement organisations exist in other countries.

In more recent events, private citizens have been known to use the DMCA Violation complaint process, for miscellaneous copyright violation reporting.

DMCA Violations have a formal complaint and appeal process.

Hacking detection

Blogger / Google network monitors are constantly analysing account login activity, and looking for signs of brute force password hacking. When hacking activity is discovered, the Blogger account - and all blogs owned by the account - are deleted and locked, pending account verification by the owner, and blog integrity checking by Google Security.

The blog owner, after changing the account password, solving a CAPTCHA, and / or verifying account ownership by providing various personal details, is left waiting for the blogs owned by the account to be examined for signs of abuse by the hacker. Until the blog(s) are returned to online status, they appear in neither the "Deleted blogs" or "Locked blogs" dashboard lists. The owner, even when logged in to the right Blogger account, simply sees the dashboard advice
You are not an author on any blogs.
In this case, neither the blog owner nor the forum helpers can do anything useful, except wait, anxiously - possibly, with no notice provided. The blog being offline may not be immediately observed by the owner - and this may cause more confusion.

Malware detection

Blogger robotic processes are constantly checking the various blogs, looking for malicious blog accessories, components, and scripts. When a blog is subject to "Malware" classification, the blog will appear in one of two dashboard lists, in sequence.
  1. Initially, the blog will appear in the "Deleted blogs" list. While the blog is in "Deleted" status, the blog owner will be able to do nothing, except request "Restore".
  2. Once the owner has requested "Restore", the blog is undeleted, and placed into the "Locked blogs" list. While the blog is in "Locked" status, all authors can access the blog to remove malware - but the blog remains offline, to all viewers. Once all malware has been removed from the blog, the owner can "Request Unlock Review".

If the blog remains in "Locked" status for over 48 hours, the blog owner may report this in the forums, and may request a manual review. The forum helpers, and online viewers, will generally see the blog displayed as "TOS violation".
This blog is in violation of Blogger Terms of Service and is open to authors only

Adult Content / Porn Detection

Blogger will soon classify and delete blogs with "adult content", which host advertisements to commercial porn sites. Like spam classification, this will probably involve both false negatives and false positives.

Spam detection

Blogger robotic processes are constantly checking the various blogs, looking for signs of spam activity and content. When a blog is subject to "Spam" classification, the blog will be displayed in the "Deleted blogs" dashboard list. The owner can do nothing, except request "Restore".

If the blog remains in "Deleted" status for over 48 hours, the blog owner may report this in the forums, and may request a manual review. The forum helpers, and online viewers, will generally see the blog displayed as "Removed".
Blog has been removed
Sorry, the blog at xxxxxxx.blogspot.com has been removed. This address is not available for new blogs.

Repeated Offenses

We have recently noted that repeated TOS Violations, involving DMCA, Malware, Porn, and Spam, are being dealt with in increasing severity.

Owner deletion or rename

Mistakes made by the owner can be confused with Spam detection. When a blog is deleted by the owner, it will appear in the dashboard "Deleted blogs" list for up to 90 days. During the 90 days, the owner (or a team member, when applicable) may "Restore" the blog. After the 90 days expire, the blog will be removed from "Deleted blogs", and will be unrecoverable. Besides being unrecoverable, no other details have been determined.

If the blog is renamed (published under a different BlogSpot URL), the external symptom may be similar to deletion by the owner.
Blog has been removed

Sorry, the blog at myblog.blogspot.com has been removed. This address is not available for new blogs.
In this case, the blog will be listed in the dashboard "My blogs" list, under the right Title. The owner needs to setup a stub blog, pointing the readers to the new URL.

Team Ownership

Any blogs owned by a deleted / locked Blogger account may simply disappear from the dashboards of other team members. If the Blogger account is not restored / unlocked, the blogs owned by that account - including any team owned blogs - may remain deleted - and inaccessible to everybody.

The Confusion Accumulates

Because of anonymous blog ownership, loss of account control, team blog ownership, and use of inactive or non existent email addresses, any account / blog which is deleted or locked for hacking (actively / as a victim), malware, and / or spam may not be easily discovered or recovered by the owner. These issues cause further confusion and frustration.

These scenarios may appear, to the untrained eye, to be signs of fraudulent, malicious, and / or petty actions by Blogger - and are loudly claimed so by spammers with their own agenda. None of these accusations are true - the above processes simply represent Blogger and Google attempting, in the best possible way, to protect everybody against the various hacking, malware, porn, and spam attacks which are constantly in progress.

>> Top

Monday, 4 February 2013

Check Your Template, And Look For Unfamiliar JavaScript Code, Following Odd Blog Behaviour

Recently, we've been seeing some odd problem reports in Blogger Help Forum: Something Is Broken, suggesting deviously hijacked blogs.
My blog is requesting me to login, using a user name and password, when I view it.
Given the URL of the window requesting the login, it's a simple matter for us to use the right forensic Internet software, and to locate a relevant snippet of code, frequently installed as part of the blog template.

Sometimes, when we reply to the blog owner with advice to remove a bit of dodgy code, we get a response suggesting disbelief. Our advice
Use the Template Editor, and remove the highlighted code snippet.
may receive a confused or skeptical response.
Where did that bit of code come from? I never installed that!
How did the code in question get installed? Discussion of one possible scenario may require thinking outside the box. Not every unrecognised blog change is being caused by memory loss by the blog owner, after an intentional accessory install or template tweak.

Looking at the subject / theme of some blogs involved in recent problem reports, we're seeing a beginning of a trend, which may indicate a new - and very subtle - blog hijacking technique. We know that Blogger blogs are subjected to brute force password guessing attacks, and we know that Blogger / Google has to consider the possibility that a brute force attack detection is made after the attack was successful.

Current blog security, and defense against blog hijacks, involves detection of hijack attempts, by Google Security. It's possible that some blogs, with some owning Blogger accounts and passwords, are more vulnerable to sophisticated password guess hacking.

When you login to Blogger or Google, you hopefully know the right account name and password, and are generally able to get logged in - after maybe one or two mistakes. You learn, soon enough, that if you have to guess your account name or current password - and you require more than a couple tries - you may have to solve yet another CAPTCHA, or request account unlock, to continue.

The ever unpopular CAPTCHA / locked account comes from Google, detecting a possible brute force attack in progress, and protecting your account and your blogs. A Blogger blog, with its content providing enough clues, combined with a simple account password that is easily guessed, may allow an experienced hacker to login to your account in one or two tries, without being detected by Google attack monitors.

It's alternately possible that some attacks are being conducted by very patient hackers, who are able to use days, and / or thousands of different computers, to conduct a throttled brute force password attack. Again, just attack without providing a detectable pattern.

This may help to explain the mysterious spam blog setups, of last year.

A hacker, able to login to a Blogger account without being detected, could install small changes in a blog template without ever being discovered. The blog owner would never discover subtle template changes, made by an easily satisfied hacker.

Finally, install latent code that does not activate immediately, as we observed during Winter 2009 / 2010, so no blogs show symptoms until the hack is installed on thousands of blogs. If one or two blog owners discover the odd code in their blogs, who would ever suspect their blog being part of a massive cloud of victims?

If you report odd behaviour by your blog, you write to Blogger Help requesting advice, and you are advised to remove a bit of dodgy code from the template - and you do not remember having installed the noted dodgy code - you may want to review your Blogger / Google password, and make the password harder to guess. Better still, start using 2-step verification for logging in to your Blogger / Google account.

>> Top

Thursday, 22 November 2012

Use A Well Protected Browser, To Block Redirecting From Misbehaving Code And Gadgets

Regularly, in Blogger Help Forum: Something Is Broken, we advise people about problem code or gadgets in their blogs.

Generally, this follows reports by blog owners, that their readers are being redirected to unexpected and unwanted blogs and websites, from their blogs. Sometimes, we get the reply
I can't remove the code. Every time I login to Blogger, I am redirected, just as my readers are being treated!

When we see the latter complaint, we recognise yet one more blog owner who does not know how to properly protect himself, from malicious code and websites. Most people, who know about Layered Security, know that proper browser security is an essential complement to a properly chosen and maintained anti malware filter.

Many people, who care about browser based security, use Firefox with NoScript.

This combination provides Unix level security, "deny by default, permit by exception". Simply install NoScript as an add-on, to Firefox, to get started. Alternately, you may use Chrome with ScriptSafe, or Opera with NotScripts.

When using your browser with a script filter, there will be specific Blogger / Google websites which you should trust, and others which you should not trust.

Every time you surf to a different website - and decide that the owners of the website, which you are now viewing, have your best interests in mind - configure NoScript to allow that website, to display properly on your computer. When you find that a trusted host website does not display properly, examine the NoScript taskbar and the list of websites used by the host website. Look at the NoScript Options menu, carefully. Allow specific websites which you trust, and Forbid all other websites which you do not trust.

Deciding which websites to trust, based on their presence in the NoScript Options menu, will be a learning experience for a while. For some host website pages, which use a large number of unfamiliar websites, you may have to carefully select to "Temporarily allow all this page" - or you can "Temporarily allow" each single website, one by one, until the host website page displays properly.

When you decide to (permanently) "Allow" any website, that website will be "Allowed" on all other host websites where you may surf. Conversely, any website which you never select to "Allow" - such as the problem website which is providing the misbehaving code - will never execute on your computer again. This will prevent redirection on your computer, allow you to safely use the Blogger dashboard, and edit or remove any dodgy code which may be part of your blog.

After removing any dodgy code from your blog, always clear cache and restart Firefox, to test the effects of your editing.

>> Top

Tuesday, 13 November 2012

Blogger Comments Being Posted Using An Anonymous Blogger Email Address

Some Blogger blog owners use their Blogger blogs as the center of their peer to peer networking life.

Many blog readers are expected to post comments - and to leave their email addresses, as part of their message or profile, to allow direct contact. Long ago, I used the email address of my commenters, as part of an easy "Contact Me" form, on this blog.

Recently, we've been noting that Blogger comments don't always include a useful email addresses - many comments simply describe the commenter as
noreply-comment@blogger.com
Not all blog owners - and readers - appreciate this change.
When I leave a comment using my google profile, it isn't linking my profile with my email address. How do I get my email address properly displayed?
and
Why do so many comments, published to my blog, show the email address of "noreply-comment@blogger.com"? How do I email my readers?


For some time, we've known of the dangers of revealing your email address to the world, in general.

Blogger blog owners have been a known special risk, with their email addresses. Google developed Google+, with the Google+ profile, to allow everybody to network with their friends - both old and new - without the risk of revealing one's email address.

Google+ replaces email completely. You can share comments, messages, photos, and videos with anybody, in a self contained universe - and you can define your own, personal universes. This leaves the need to reveal your email address completely unnecessary (though you can use email, if you wish, without knowing anyone's address - or revealing yours).

After Google+ became popular, Blogger added the option to link our Blogger blogs with our Google+ profiles. Blogger profiles, based on Google+, are cleaner, and use the Google+ displays to update.

To encourage people to use Google+ for peer to peer networking activity, and to make our Blogger accounts and blogs safer, Blogger has eliminated our email addresses from all outside correspondence - including when we publish comments on Blogger (and non Blogger) blogs, using a Google+ based Blogger profile.

If we publish a comment on somebody's blog, and the blog owner has enabled comment moderation or notification, our comment shows up in the email inbox of the blog owner - but with our email address displayed as "noreply-comment@blogger.com".

With email addresses not displayed, this helps protect our Blogger account names from becoming unnecessarily revealed. Blog owner - reader comment communication is still possible - but again, without the email address of the reader being known.

Some time ago, I discovered an odd type of comment spam, which I termed "nice Blog" spam.
Nice blog. I will keep visiting this blog very often.
This spam, from what I can tell, has been published by the millions, in various blog comments. It's likely that this particular spam is being published as a very imaginative form of email address mining, and recently became even more imaginatively produced.

All that the spammer has to do is publish a spam comment, and select the option to "Send me replies". Any comments published later, and including the commenters actual email address, would be delivered directly to the spammers inbox. Knowing the email address - and the blog URL (how many comments do not include a link to a blog?) - the hacker would go straight to work.

Later, we would see forum reports.
I can't control my blog, any more - and somebody has updated it with spam!
This was a direct result of the former blog owner, having left a comment on somebody else's blog.

By eliminating our email addresses from our comments, Google is helping to protect our accounts and blogs, while letting us continue to comment on each others blogs - and to eliminate one type of unnecessary spam from our blogs.

Google+, which replaces email for networking, uses a "Friend of a Friend" relationship to let you expand your universe infinitely, with each comment, message, photo, and video that you share. It lets you control the expansion of your universe - if you wish. And, it helps keeps your Blogger blog under your control.

>> Top

Friday, 26 October 2012

Blogger Blogs Redirecting To "blogspot - ping . com"

Today, we see the latest in the never ending saga of blog owners, who previously (maybe / maybe not recently) installed some deviously created software - whether intentionally or not - and who now find their readers unable to view their blogs, and themselves even unable to access the template editor to remove the malicious code.
My blogs are redirecting auto to ping . blogspot - ping . com", can anybody tell me how to fix this?


The malicious redirecting appears to be cause by a small snippet of JavaScript code - which has been installed, in most cases, as template HTML. Alternatively, some blog owners have added separate HTML / JavaScript gadgets, to host this code.

It's easy enough to identify - not so easy to remove, as some owners have found. In many cases, we are seeing reports that even when directly accessing the Layout wizard or Template Editor, the malicious code activates, and redirects the blog owner's browser.

Since the redirect is running from a snippet of JavaScript code, blocking the malicious code will prevent the redirection, and allow corrective access to the Layout wizard or Template Editor.
<script src='http : // ping . blogspot - ping . com / ping . js' type='text/javascript'></script>
Whichever GUI wizard you use to remove the code, remember to clear cache and restart the browser after removal and before testing for success.

Since I routinely - and consistently - use Firefox with NoScript to browse, I was able to access one victim blog without the redirection occurring, view the blog source, and extract the above code. If you use NoScript, you (the blog owner) should be likewise able to access your dashboard, and the Template Editor, and remove the bogie.

Please note that the code snippet, excerpted above, has extra spaces inserted into the URLs, to prevent advertising of the actual hijacking domain.

Anybody who knows where this bogie originated, and how it was deviously conned upon the blog owners, can help a lot of people by identifying the origin. Only when this is done, can we try to prevent the problem - rather than advise how to remove the problem.

First, install the popular Mozilla browser, Firefox. Having added Firefox, install the add-on NoScript. NoScript uses a Unix level security policy.
Deny by default, permit by exception.
Keep in mind the different trust levels of Blogger and BlogSpot - with NoScript, you will have to allow Blogger, yet forbid BlogSpot. Code from unknown domains, such as "blogspot - ping . com", will not run on any NoScript protected computer - unless you, intentionally, enable it. Knowing the threat from this bogie, you will hopefully choose to not enable this domain.

>> Top

Wednesday, 12 September 2012

How Not To Make Your Blog Private

Blog owners have been asking, for years, how to protect their blogs against viewing by undesired or unknown readers.
How do I password protect my blog?
When told that Blogger password protection involves membership invitations, accepted using a Blogger Google account, some would be private blog owners decline the suggestion.
That's too complicated for my readers! Can't I just give everybody a password?
But Blogger does not use common passwords.

Some blog owners, who are technically astute, find add on template code, provided by third parties - which demands a password, in a popup window, to continue. This is where their problems start.

The addition of third party supplied JavaScript code, to our blogs, has always been a dodgy process. With third party JavaScript code used to provide password protection against unknown readers, this is even more hazardous to your blog.

This month, we have a blog owner who installed password protection code in his blog template - and subsequently found his blog locked.
I received email saying that my blog has been removed, and has been marked as spam. The email is as follows:
Your blog has been reviewed and confirmed as in violation of our Terms of Service for: MALICIOUS_JAVASCRIPT. In accordance to these terms, we've removed the blog and the URL is no longer accessible.
Can you please review and unlock my blog?

But the story does not end there. Subsequent review of the blog was denied, by Blogger Support.
Your password prompt is not dismissable - and forces users to close their entire browser session, as the Cancel button does nothing. This is malicious behavior, and prevents anyone one on our team from even reviewing your blog content.
This leaves the blog owner with a deleted / locked blog, and no chance of getting the blog back.

Besides the potential threat above, which becomes actual only after spam classification detects the add-on code as malicious, any security expert will recognise two reasons why this solution is worthless.
  1. JavaScript code can be blocked, by any reader with a well implemented security policy.
  2. If not blocked, anybody can view source code and find the "password" right there, in plain sight.
This "solution" is therefore worthless for two reasons.
  1. It is risky.
  2. It does not work.

Why risk loss of your blog, for a risky solution that does not work? There's only one way to protect your blog from unknown readers.
  1. Send each would be blog reader a membership invitation, using the Permissions wizard.
  2. Instruct each reader to open and accept the invitation, using any preferred Blogger account.

>> Top

Saturday, 8 September 2012

Blogger Supports Their Customers - But They Support Their Active Customers More

Every week, in Blogger Help, we see the cries of frustration.
Many years ago I had a Google account with a "gmail.com" e-mail address. But I deleted this account, because I didn't need it anymore. Later, I wasn't able to login to Blogger, to delete my blog. And I also wasn't able to remove it by contacting Blogger. Why doesn't Blogger support their customers?
The point being overlooked here is that both Blogger and Google do support their customers.

Blogger / Google, like every commercial enterprise worldwide, simply supports their active customers more than their not-so-active customers.
  1. They have millions of customers, who spend much time maintaining and publishing their blogs.
  2. They also have some customers, who start blogs, and leave them dormant for many years - then require assistance recovering access to their Blogger accounts, because they have forgotten the account name or password, and the backup email address can't be used.
Considering that Blogger / Google is not a non profit organisation, and needs to support customer activity, which group of customers should they support most readily?

Blogger / Google wants to encourage us to maintain and to publish our blogs regularly. People who don't use their services regularly, then demand special assistance when needing to use their services, are not going to receive the same level of support.
  1. People who use Blogger regularly will develop a level of proficiency - and won't require special assistance as much as those who don't use Blogger regularly.
  2. People who use Blogger regularly simply require a working Blogger interface, and a level of security that keeps their blogs under their control. People who don't use Blogger regularly need a different and more complicated Blogger interface - and a lower level of security, so they can continue to access their Blogger accounts.
The needs of the few (who don't use Blogger regularly) have to be considered against the needs of the many (who do use Blogger regularly).

Recently, we had a series of well organised hijackings of actively published Blogger blogs. After Blogger / Google recognised this ongoing threat - which endangers all Blogger blog owners - they tightened down their security, and restricted assistance to those needing help recovering access to their Blogger accounts. People who don't use Blogger regularly don't understand the reasoning behind this reduced level of assistance, and increased level of security.

Unfortunately, understand it or not, we all have to learn to live with it - if we wish to continue publishing Blogger blogs.

>> Top