Social Icons

Pages

Showing posts with label Google Account. Show all posts
Showing posts with label Google Account. Show all posts

Wednesday, 20 November 2013

Your Google Apps Account, And The New Administrative Google Login

In some cases, the earlier provided procedure, for accessing the limited access domain administrator account, may not work, for your Google Apps domain.

For some Google Apps domains, you will need to reset the password using the Google administrative reset. Instead of the wizard at "accounts.google.com", you may need the administrative reset wizard, at "https://admin.google.com".

A Google Apps administrative account reset uses the same set of displays, as the previously discussed limited access account reset.

When you request administrative account reset, you first try the using default account name.

For my domain, if it had been purchased after November 2012, the default account name would be "bloggeradmin@nitecruzr.net". Yours will be "bloggeradmin@yourdomainURL" - whatever "yourdomainURL" actually is.

Domains purchased before December 2012 will apparently still use a Google Apps token sent in email or linked from Google Wallet.

As previously advised, always use one browser for Blogger and other Google activity like GMail, and the second for the Google Apps session. For best results, first clear cache, cookies and sessions (yes, all 3!), and restart the second browser.

Use the same account name, as advised - just substitute the administrative reset sequence.
https://admin.google.com/


Click on "Need help?".

Select "I don't know my password".

Enter your limited access Google Apps account name.
In most cases, you will go into the expected administrative account reset sequence.

With a mature account, where you have previously setup a custom administrative account, "bloggeradmin@yourdomainURL" may not be accepted. Now, you must try an extended administrative account reset.


If the limited access account, for your domain, is not operational, don't panic.

Return to the previous screen, and select "I don't know my username".

Now, you have other details to provide.


Whether you use the standard administrative reset - or the extended administrative reset - Google will send a password reset email message, to the backup email account associated with the domain. The email account should be the one used by the Blogger account, under which you purchased the domain.

Other than the previously enumerated cases where you can't use the recovery email address, this should be a reasonably straightforward process.
  1. Access the new Google Administrator Login screen.
  2. Click on "Need help?".
  3. Request password reset.
  4. Access the right email account.
  5. Open, and execute the password reset email.
  6. Hopefully, you're done.
  7. If necessary, return to the previous screen.
  8. Select "I don't know my username".
  9. Provide additional details.
  10. Go to Step 3.
Once you're in the Admin Console, you can check / set the auto renewal option setting, or you can retrieve the login instructions to access the registrar's zone editor - or do whatever else you need to do.

The next time you need to access the Admin Console, try to remember the previously set account name and password. And, if you feel up to it, add recovery options to your administrator account.

>> Top

Wednesday, 6 November 2013

Your Google Apps Account, And The New Google Login

In the not so distant past, explaining how to login to Google Apps was a painfully tedious process.

If I wanted to login to the Google Apps account for this domain, "nitecruzr.net", I would construct a URL in the browser address window (or use a bookmark)
https://www.google.com/a/nitecruzr.net/ServiceLogin
The URL for your domain would be different - and explaining the difference was frequently a nuisance, in the login sequence instructions.

When explaining how to login to a recently created limited access Apps account, I would focus on the account reset process.
For this domain, "nitecruzr.net", I would access the account reset wizard as
http://google.com/a/cpanel/nitecruzr.net/ResetAdminPassword
or possibly
http://google.com/a/nitecruzr.net/ResetAdminPassword
Again, your URLs would differ. Maintaining separate bookmarks, for each different domain, was a time sink.

With the new Google Apps integrated account login, all of that has changed.

Any time you start a process which involves Google accounts, first clear cache, cookies and sessions (yes, all 3!), and restart the browser.

Since the Google Apps login uses a different Google account, you'll need to use two browsers - as you do when transferring control of your blog.

Use one browser for Blogger and other Google activity like GMail, and the second for the Google Apps session. For best results, first clear cache, cookies and sessions (yes, all 3!), and restart the second browser.

Next, to login to the limited access Google Apps account for this domain, you simply go to the standard Google login screen, using the second browser.
https://accounts.google.com/ServiceLogin
You then click on "Need help?". On the next screen, select "I don't know my password", and enter the limited access Google Apps account name, for your domain.

For my domain, if it had been purchased after November 2012, the default account name would be the limited access "bloggeradmin@nitecruzr.net". Yours will be "bloggeradmin@yourdomainURL" - whatever "yourdomainURL" actually is.

Domains purchased before December 2012 will apparently still use a Google Apps token sent in email or linked from Google Wallet.

Enter the appropriate account name, click "Continue", and follow instructions.


Click on "Need help?".

Select "I don't know my password".

Enter your limited access Google Apps account name.
After you submit the password reset request, Google will send a password reset email message, to the backup email account associated with the domain. The email account, for a new Apps account, should be the email account used by the Blogger account, under which you purchased the domain.

The only problem which you can have is if the necessary email account can't be accessed.In either case, without access to the right email account, you won't be able to reset the Google Apps account password - and you won't be able to gain / regain access to your Google Apps domain administrator account, aka the "Admin Console", for the domain in question.

Other than that one possible problem, it should be a straightforward process.
  1. Access the new Google Login screen.
  2. Click on "Need help?".
  3. Request password reset.
  4. Access the right email account.
  5. Open, and execute the password reset email.
Once you're in the Admin Console, you can check / set the auto renewal option setting, or you can retrieve the login instructions to access the registrar's zone editor - or do whatever else you need to do.

If you're logging into Apps for a second time, and you remember the account name and password, it's simpler still. Access the new Google Login screen, enter the domain administrator account name and password, and login. Now, Google Apps is just one more Google application - but with its own unique account name.


If you remember the domain admin account name and password from last time, just login - and you're there.

Again, always open Google Apps in a second browser.

Other than the need to use a second browser, logging into Google Apps is now a series of bookmarks and simple scripts.
In some cases, you may not be able to use the limited account reset sequence. Don't panic! Google also provides an administrative account reset process, for these situations!
>> Top

Sunday, 6 October 2013

Team Blog Ownership, And Abuse Classification

We see some people, posting in Blogger Help Forum: Something Is Broken, who have problems with blogs under team ownership, and abuse classification.
My blog was deleted as spam but I don't spam! BTW, one of the other administrators of my blog recently had his Google account blocked.
We've observed, a few times, that team blog relationships create interesting complications, with various Blogger issues - and this appears to represent yet one more complication.

In most cases, when a Blogger account or blog is deleted or locked, the owner of the account or blogs affected should see an online notification, and / or receive email informing of the action taken.

There are several reasons why notification - email or online - may not always be provided.
  • Blogger accounts, based on bogus or inactive email addresses, will not provide email notification.
  • A person who uses multiple Blogger accounts, accidentally or intentionally, will only see the dashboard for the account currently logged in.
  • An owner of a Blogger account, recently unlocked after detected suspicious / unusual activity, will see only an empty dashboard, when logging in.

The team blog ownership relationship appears to provide one more reason for lack of notification.
  • Administrators of blogs under team ownership may not see notification, when one of the team members has a Blogger account deleted or locked.

Both Blogger accounts deleted for non repentant abusive activity, and Blogger accounts locked when suspicious / unusual activity is detected, appear to present this complication, with blogs under team ownership.

When a Blogger account is deleted after the owner repeatedly produces TOS violations, all blogs owned by the account are apparently deleted. It's possible that, when a blog is deleted, team ownership issues are overlooked in the blog deletion process - and the blog simply disappears from the dashboards of the other team members. It's also possible that this is a predictable group action - comparable to affiliate network detection.

When a Blogger account is locked after suspicious / unusual activity is detected, all owned blogs simply disappear from the dashboard of the owner. Blogs owned by a locked account are under automatic security review, with no appeal by the owner being possible. Team administrators are unlikely to have any alternative appeal opportunity, for a blog under review when an owning account is locked.

The latter two scenarios represent two reasons why, if we see the complaint in Blogger Help Forum: Something Is Broken
My blog has disappeared from my dashboard, and is not online!
One initial question should be
Was the blog under team ownership?

>> Top

Wednesday, 28 August 2013

Being A Hacking Victim Is Not Always The Fault Of The Account / Blog Owner

Even though being the victim of a hacking attack is not (always) the fault of the account / blog owner, the blog owner may have to bear some of the responsibility.

Since hacking detection is a fuzzy process, it's not always going to be detected immediately. The previous article discusses what happens when Google does detect a hacking attack - and in some cases reacts too diligently.

If Google is not able to detect an attack, in some cases, an attack may be successful.

With some blogs, that are not updated frequently, a hacker may take control, and successfully hijack a blog.

Occasionally we see another report
I just discovered that my blog contains spam - and I can't access the dashboard, to clean the blog!
This may well be a successfully hijacked blog, discovered too late.

Unfortunately, the latter report may also be another devious attempt to steal control of somebody's blog. Blogger Support cannot, reliably, support hacking recovery, on an individual basis.

From what I can tell, Blogger / Google is working on the larger picture - making the automated detection process more reliable. Given this concern, Blogger / Google won't be frequently available to diagnose and return control of individual hijacked blogs - even when the issue is righteous.

In general, blog owners have to support themselves, and learn how to protect themselves. This may be yet one more reason why 2-Step Verification is becoming less optional.

>> Top

Monday, 26 August 2013

Repeated TOS Violations Are Punished Gradually

Some blog owners don't understand the serious nature of repeated violation of TOS Policy, in Blogger blogs - and how offenses are handled, by Google.

We've seen several reports, in Blogger Help Forum: Something Is Broken, from blog owners who appear to be unclear about the consequences of repeated TOS Violations.
I got email from Blogger, about my Blogger account.
We'd like to inform you that we've received another complaint regarding a blog that you administer. Upon review of your account, we've noted that you've repeatedly violated the Terms of Service: http://www.blogger.com/go/terms. Given that we've provided you with several warnings of these violations and advised you of our policy towards repeat infringers, we've been forced to disable your Blogger service.
How do I get my blog restored?

This example appears to represent the final step, in a multi step policy.

It appears that Google takes a multi step approach, towards repeated TOS violations - such as hosting of malware, porn, and / or spam - in Blogger blogs. This is similar to the DMCA Violations punishment process.
  1. Unlike DMCA violations, individual posts are not deleted.
  2. Deletion of offending blogs.
  3. Deletion of offending Blogger account(s) (and blogs).

With a TOS initiated blog deletion, the blog owner is expected to have the blog reviewed. If the review determines the blog to be unrighteously deleted, the blog is restored - though there may be side effects.

If the blog owner does not wish to have the blog reviewed, he / she is allowed to start over, with a new blog - but will have to publish to a new URL. Content lost must be recovered by the owner - and the owner should be more careful with future blogs.

If the blog owner continue to publish blogs which violate TOS, any Blogger accounts involved, along with any other blogs owned by the deleted accounts, will be deleted.

We see that an appeal is possible.
Next steps for suspended accounts: If you believe your access to this product was suspended in error, contact us.

With any blogs published to a non BlogSpot domain, the domain URL(s) will remain in use, in the Google database - though the domain owner is free to use the domain outside Google address space. If the offender wishes to start over, both new BlogSpot and non BlogSpot URLs will be required.

As with other issues with email delivered warnings, there will be cases when the owner may not receive warnings in a timely fashion. Even so, the owner is responsible, when he / she offends, repeatedly.

Blogs under team ownership are apparently vulnerable to action taken against any team member. In some cases, blogs will simply disappear from the dashboards of the other team members, with no appeal or review request being possible.

It's possible that legal notice, provided by Google through email, will supercede ongoing forum advice - even if email sent is not received by the owner.

>> Top

Friday, 26 July 2013

Repeated DMCA Violations Are Punished Gradually

Some blog owners don't understand the serious nature of DMCA Violations in Blogger blogs - and how offenses are handled, by Google.

We've seen several reports, in Blogger Help Forum: Something Is Broken, from blog owners who appear to be unclear about the consequences of repeated DMCA Violations.
I got email from Blogger, about my Blogger account.
We'd like to inform you that we've received another complaint regarding a blog that you administer. Upon review of your account, we've noted that you've repeatedly violated the Terms of Service: http://www.blogger.com/go/terms. Given that we've provided you with several warnings of these violations and advised you of our policy towards repeat infringers, we've been forced to disable your Blogger service.
How do I get my blog restored?

This example appears to represent the final step, in a 3 step policy.

It appears that Google takes a 3 step approach, towards DMCA violations. This is similar to the TOS Violations punishment process.
  1. Deletion of offending posts.
  2. Deletion of offending blogs.
  3. Deletion of offending Blogger account (and blogs).

We've noted the initial step - deletion of offending posts, before. Specific blog posts, which are identified as DMCA Violations, are saved as Draft content. This allows the blog owner to correct the offense, and re publish a corrected post, without losing the content.

If the owner chooses to ignore the initial DMCA Violation, and simply re publishes an offending post - or if the owner publishes multiple offending posts, the blog is deleted. The owner is free to publish another blog, at his convenience - but the offending blog is not recoverable.

If the owner publishes a new blog, containing the same offending material - or if the owner publishes multiple offending blogs, the Blogger account (and blogs) is deleted.

As with all email delivered warnings, there will be cases when the owner may not receive warnings in a timely fashion. Unfortunately, the owner is responsible, even so, when he offends, repeatedly.

>> Top

Tuesday, 25 June 2013

Use Google 2-Step Verification, To Protect Your Blogger / Google Account - And Your Blogs

Our Blogger accounts, and blogs, are under persistent attack by some rather nasty Internet users.

Hackers, using other peoples computers, are constantly attempting to "guess" our Blogger passwords, and take control of our Blogger accounts and blogs. Blogger accounts are particularly vulnerable to attack, because too many blog owners
  • Reveal their account names (email addresses) to the world.
  • Base their passwords upon real life details.
  • Publish blogs, where their real life details are visible to the world.

Some blog owners think that by using only one computer forever, they should be able to register that one computer as theirs, and require Google to simply deny access to their Blogger / Google accounts, from any other computer. This is a very simple solution - and it's one which is doomed to failure.

Google knows that even the most careful person will periodically use a different computer - or possibly forget their Blogger account name and / or password.

Rather than attempt to restrict us to using one single computer, for eternity, Google gives us an option to use a previously registered telephone as an authentication token, whenever we use a different computer. The telephone can use either text or voice, and provide us with a one use passcode, to enter after we successfully enter our account name and password.

This is not a foolproof solution.
  • Some people will not want to provide their phone number, to Google.
  • This strategy will only work with a preregistered phone - and registration can only be done when we are logged in to Google.
  • If the pre registered phone uses text (a smart phone / mobile computer), it will be usable only where cellular service is available.
  • If the pre registered phone uses voice, it will be usable only as well as we understand computer synthesised "speech".
  • In either case, in some cases, stress will contribute to the possibility of making a mistake.
  • Since a pre registered phone is required, we will be able to use this only as long as we carry our smart phone - or login from a pre determined location.

However, if we can deal with the above drawbacks, we have a much better chance of keeping our Blogger accounts and blogs under our control. Very few hackers, having successfully provided our account name and password, will be able to immediately use a pre registered telephone, to accept a one time use passcode.

>> Top

Wednesday, 29 May 2013

The Google Apps "bloggeradmin" Password Reset May Be Broken, For Some Domains

We've been seeing reports from some frustrated blog owners, about problems with the limited access Google Apps accounts.
I've reset my password numerous times and it still doesn't work.

Even given the recently provided "bloggeradmin" username, and the standard Google account reset process, some blog owners still cannot access Google Apps to manage their Blogger custom domain published blogs.

We do have one bit of hope. One such problem report, recently forwarded to Google Apps Support, was noted by a Google Apps Engineer with the advice
We identified a recent change which may have affected the password reset flow for some users. We expect it to either be fixed or rolled out shortly.

So, there is some hope for a few unhappy new domain owners. It's possible that this problem has been resolved, with Google Apps now using the new comprehensive Google login screen.

>> Top

Tuesday, 14 May 2013

The Google Apps "bloggeradmin" Password Reset Uses A Standard Google Account Reset

As Google Apps updates their limited function ("bloggeradmin") account setup process, we see reports from confused Blogger blog owners.
After I reset my password, I still get
The username or password you entered is incorrect
when I try to login, later!
and
I reset my password - and it changed my Blogger and GMail account - but I still can't login to Google Apps!!


The Google Apps password reset uses a standard Google account reset process - and is subject to normal account reset behaviour. If you don't reset the right account, you won't be able to login, later.

We've been warning people for years, about the need to use two browsers, to transfer a Blogger blog from one Google (GMail) account to another.

The Google Apps "bloggeradmin" account setup, like the Blogger blog transfer, works best using two browsers. The password reset, for "bloggeradmin@mydomain.com" (as an example, here) involves a Google account reset.
  1. You start the password reset from a Google Apps login screen, for "mydomain.com".
  2. After clicking on the "Can't access your account?" link, you use a standard Google account reset process.

When you attempt to login to Google Apps, click on "Can't access your account?". That takes you into the Google Account Reset process.


Provide the full account name of your Apps account.
bloggeradmin@mydomain.com
instead of
myemail@gmail.com

The Google Apps password reset, like blog account transfer, is one more process where you may need to use two different browsers. And, to be safe, clear cache, cookies, and sessions (yes, all 3!) - then restart the second browser, before opening the password reset email.

The password reset will be more likely to be successful, if your Blogger account is based on an active and real email address - this is not a good time to be anonymous.
(Update 2013/11/03): This process should be slightly simplified, with Google Apps now using the new Google comprehensive login screen.


>> Top

Sunday, 21 April 2013

Recovering And Protecting Your GMail Account

Blogger blog owners may have productive action, when their Blogger accounts are successfully hacked through an attack on their GMail accounts.

GMail account owners can get detailed instructions on recovering a successfully hacked account, and on preventing future hacking attacks from being successful. Some of the instructions are specific to GMail use - but overall, Blogger account owners will benefit from their use.

To benefit from the GMail instructions, one should consider the differences between Blogger, email, and Google accounts.

Gmail Account Recovery: Gmail Account Recovery and Security provides complete and detailed instructions for recovering a hacked and stolen GMail email account.

The Recovery instructions include specific mentions of Disabled / Suspended accounts, successfully Stolen accounts, and accounts locked or deleted because of Underage owners.

Accompanying the recovery advice is Gmail help and information: How NOT To Get Hacked. These are instructions for preventing a recurrence of a reported problem. This includes discussion of using a strong and secure password, identifying hacking techniques that involve the account owner, and preventing attacks which are conducted using the computer or network in use by the account owner.

The Prevention instructions, many which are common sense issues to any IT professional or security expert, are specifically written to apply to GMail account owners. There may be additional issues which apply in general, to Blogger accounts - and specifically, to Blogger accounts which are based on non GMail email accounts.

There are a few differences between Blogger blog ownership and GMail account ownership, which will cause issues that cannot be easily resolved by Blogger Support, or by GMail Support, to the satisfaction of the (former) blog owner.

GMail accounts are, by nature, single owner - and ownership of a GMail account is never transferred. In contrast, Blogger blogs can be under team ownership - and ownership can be transferred.
  • Intentional team blog ownership. Team blog ownership can cause problems with loss of blog control, when all known blog administrators (accidentally or intentionally) remove themselves as administrators, leaving an unknown administrator.
  • Intentional transfer of control. A blog owner may assign administrator status to another person, voluntarily - then later regret his decision.
  • Un intentional transfer of control. A blog owner may assign administrator status to another person, voluntarily - and the other person may then remove the former owner administrator status.
  • Ownership theft after account hacking. A hacker, having temporarily gained control of a Blogger account, may transfer ownership of a blog to another Blogger account.
All of these scenarios are regarded as simple transfer of blog ownership, by Blogger Support.

Though maybe not preferred by the (former) blog owner, the blog in question will now be under control of another person. It's possible that some of these scenarios are considered by Google Security, when reviewing Blogger / Google accounts after hacking activity is detected.

Blogger accounts, based on non GMail email addresses, will be subject to the typical uncertainty which accompanies any third party service in Blogger. Some details may be involve the email provider, while others will involve Blogger - and arbitrating between the two will be the responsibility of the Blogger account owner.

Owners of Blogger accounts which are based on non GMail email addresses will need to contact the providers of the actual email service, for resolution of some of these issues.

In general though, the GMail Account Loss Prevention and Recovery instructions provide good advice, for any Blogger account owner.

>> Top

Friday, 19 April 2013

Problems Being Observed, In Blogs Now Using Google+ Comments

A few blog owners, eagerly opting to use the latest Blogger enhancement, Google+ Comments, are seeing some changes which they did not anticipate.

Even after checking all of the settings, some blogs, with Google+ Comments enabled, may not show the comment form - or may show the form, but comments may not be visible. Besides the visibility of the form, there are other changes which some blog owners don't appreciate.

In many cases, Google+ Comments, like other new features, require an updated post template. This will be seen in blogs with customised post templates, most frequently - although newer, less customised blogs also may need a post template reset.

After getting Google+ Comments working in general, some blog owners find other unexpected changes.
  • Almost the entire "Comments" section, in the dashboard Settings - "Posts and comments" wizard, will disappear - though "Comment Location" will remain - and will default to "Embedded". None of these settings are relevant in Google+ Comments. On some blogs, there may be no "Comments" dashboard menu entry at all.
  • There are no controls for moderation, or for notification, of comments.
  • There is no ability to moderate comments, from the dashboard. Moderation is done under each post, one post at a time.
  • As a blog owner, you have no special ability to moderate comments, made against your blog.
  • There may be some comments, which you may not be able to moderate - but will publish against your blog.
  • If you Block somebody from Following you, that person may still be able to post a Comment on your blog. When you look at the comments, you will only see
    This post is hidden because you have blocked the author.
  • People without Google+ accounts won't be able to make - or view - comments (since comments are Circle dependent).
  • Visibility of the comment form, as with all embedded comments, is sensitive to cookie / script filters, on the client computers.
  • Comments posted outside Google Comments may not be immediately visible, though the comments remain in existence. Resetting various sections of the template may resolve this, when observed.
  • If you change the blog address - with either a simple BlogSpot address change, a non BlogSpot address republishing (aka "custom domain"), or export / import - existing Google+ Comments may not remain visible, with the blog. This may be a similar problem, with URLs subject to Country Code Aliasing.
  • With a blog using Google+ Comments, the Comments newsfeed will not be published. Any "Recent Comments" gadgets will be useless.
  • The "Export blog" wizard, which used to export both comments and posts, will only export posts.
  • The comment count, as displayed in the blog main page display, may show "0 comments" - even with comments actually present, and visible when clicking on "0 comments".
  • You may or may not get email notification of comments, when comments are not shared specifically with you - even if you own the blog. Other people, who do not own the blog, may get notifications when you do not.

Fortunately, in most cases any prematurely made decisions are reversible. Go to the dashboard Google+ menu entry, and unselect "Use Google+ Comments on this blog". The blog will simply return to native Blogger based Comments. Any comments made under Google+ will not be visible to you, from the blog - but everything else should return to normal.

I've now added a Problem Rollup discussion, in Blogger Help Forum: Feature Suggestions and Feedback, where your opinion is appreciated. Please be objective.

See my test blogs Google+ Comments, Dynamic Template Test and Google+ Comments, Simple Template Test if you wish.

Click here, for instructions to revert back to Blogger based comments. Note that you will lose ability to view all Google+ based comments - though the comments will still exist.

>> Top

Thursday, 18 April 2013

Blogger And Google+ Continue To Move Ever Closer Together

Today, Blogger announced the most innovative step in integrating Blogger and Google+, since sharing of Blogger posts to Google+.

The December 2011 sharing option lets us publish our blog posts to Google+. Today, Blogger added the ability to do the same - and more - with our blog comments. Like basic Google+ post sharing, Google+ Comments will be shared, and be visible, on a Circle by Circle basis.

The ability to post a comment, against a Blogger blog post shared in Google+, and have the comment publish to the blog will make for interesting comment based conversations.

There will be challenges to this feature, however. One of the most annoying problems with Blogger comments, right now, involves the embedded comment form, and security limitations caused by cookie filtering on many readers computers.

This blog uses a full page comment form, because too many of my readers need to post comments, in spite of the cookie filtering on their computer. Blogger Google+ Commenting requires use of the embedded comment form.
Google+ Comments lets you bring the following conversations together in one place, right under your blog post:
  • Comments made on your Blogger blog post
  • Comments on the blog post that you’ve shared to Google+
  • Shared content on Google+ that links to your blog post
Readers will need a Google+ page or profile to comment on your blog.

Anybody who publishes a blog, and has readers who do not understand the reason for allowing third party cookies, will not want to use an embedded comment form - and won't benefit from Google+ Commenting, either. Until either
  • Blogger resolves their "third party cookies" problem, with the embedded comment form.
  • All Blogger blog readers resolve their issues with filtering "third party cookies".
Google+ Comments will have a limited audience.

Many blog owners may find a problem, in the moderation process.
Once you enable Google+ Comments, you can moderate comments within the blog post itself.
Owners of large blogs may not enjoy having to check each post, one by one, to moderate comments.

I check my dashboard Comments menu, several times daily - and see all comments posted to the blog, in one convenient place. Having to look at each post, to moderate comments, won't be as convenient.

A third challenge will come from blog owners who want everybody to be able to comment, on their blogs. Requiring a Google+ account to comment won't be widely accepted by blog owners who have readers who comment either Anonymously, or using an OpenID.

One of the benefits of Google+ Commenting will be a reduction in comment based spam. The increasingly annoying "nice blog" spam - and the accompanying security risks from having it published on our blogs - should be eliminated, from blogs using Google+ Comments.

Google+ Comments is a feature that is needed, on some Blogger blogs - but it needs to remain optional, for some time.

If you're in one of my Circles, and wish to test this new feature, see if you can comment, on my recipes blog, Chuck's Kitchen.

>> Top

Friday, 22 February 2013

Browser Cache, And Confusion About Blogs Locked After Suspected Account Hacking

The effects of browser cache, upon our Internet life, are not always understood.

Most of us know, by now, to clear cache and restart the browser, after updating a blog, for consistent testing. Some folks know that blog security changes don't always take complete and immediate effect.

Recently, we're seeing a new effect, reported by owners of Blogger accounts locked, after hacking activity is detected.
I got a message mentioning suspicious account activity, when I logged in to Blogger. I provided my phone number, and I received a code on my phone, that I had to enter before I could then log in. My blog was working fine just after I logged in. A short while later, though, it was gone. Why was my blog deleted, because I unlocked my account?
This blog owner is just slightly confused, about the cause and effect here.

Google robotic processes are constantly monitoring account login activity, and watching for signs of hacking activity, such as brute force password entry.

When hacking is detected, the detection may not be immediate - so Google protects us by considering the possibility that the hacking could have been successful, and deletes or locks blogs owned by the account under attack. The blogs in question are taken offline, immediately, when hacking is detected.

If a blog owner has just been working on a blog, as is frequently the case, the blog contents will be cached somewhere between the owner and the Blogger servers. Blogger can take the blogs offline, on their servers - but any cache containing the blogs will remain. If the blog owner is working on a blog while the Blogger account is under attack, what's in cache will remain, visible to the owner, until cache expires.

If a Blogger account is attacked, and the attack is detected, shortly after the owner has viewed a blog, what's in cache will be used, until it expires. The owner won't see the effects of the blog being deleted until the cache expires, and the browser tries to retrieve a fresh copy from the Blogger servers.

The blog owner sees the blog go offline shortly after he verifies account ownership, and thinks that the verification process caused the blog to go offline. In reality, the blog was taken offline before the owner even knew of "suspicious" account activity.

Now, the blog owner can do nothing, except wait until the account and the blogs are examined for signs of tampering. In some cases, no notification of progress will be received - and the owner will see the blog(s) returned to service, sometime later.

How much later the blogs return to service will vary widely, depending upon several details - and this variation, added to the uncertainty caused by cache latency, leads to mystery.

>> Top

Saturday, 9 February 2013

Deleted / Locked Blogs Have Several Causes, And Various Resolutions

Many blog owners are occasionally confused, by the effects of several Blogger / Google security processes, when they are simply trying to login to Blogger and work on their blogs. We see the agony, daily, in Blogger Help Forum: Something Is Broken.

The side effects of the security processes are similar - and depending upon various owner specific details, can be easily confused for each other. The possibility of confusion requires careful initial analysis, when we are faced with an angry blog owner.
My blog was deleted, by Blogger. How could they do this? I do not publish spam!
This is a typical problem report, which can reflect any one of the processes, each requiring different action in the forums.

There are various Blogger / Google security / TOS enforcement processes, each of which will cause a Blogger account and / or blog to be unavailable for full access, at any time.Each different process has a different effect on the Blogger account and blogs owned - and requires different attention by the blog owners, by the forum helpers, and by Blogger Support and Google Security.

DMCA Violation

Accounts and blogs can be deleted, for progressive DMCA violations.

The DMCA violation process originated with complaints made by the major entertainment industry content enforcement organisations, citing theft of "intellectual property" which they control. In the USA, this would involve the "MPAA" (Motion Picture Association of America), and the "RIAA" (Recording Industry Association of America). I have been told that similar content enforcement organisations exist in other countries.

In more recent events, private citizens have been known to use the DMCA Violation complaint process, for miscellaneous copyright violation reporting.

DMCA Violations have a formal complaint and appeal process.

Hacking detection

Blogger / Google network monitors are constantly analysing account login activity, and looking for signs of brute force password hacking. When hacking activity is discovered, the Blogger account - and all blogs owned by the account - are deleted and locked, pending account verification by the owner, and blog integrity checking by Google Security.

The blog owner, after changing the account password, solving a CAPTCHA, and / or verifying account ownership by providing various personal details, is left waiting for the blogs owned by the account to be examined for signs of abuse by the hacker. Until the blog(s) are returned to online status, they appear in neither the "Deleted blogs" or "Locked blogs" dashboard lists. The owner, even when logged in to the right Blogger account, simply sees the dashboard advice
You are not an author on any blogs.
In this case, neither the blog owner nor the forum helpers can do anything useful, except wait, anxiously - possibly, with no notice provided. The blog being offline may not be immediately observed by the owner - and this may cause more confusion.

Malware detection

Blogger robotic processes are constantly checking the various blogs, looking for malicious blog accessories, components, and scripts. When a blog is subject to "Malware" classification, the blog will appear in one of two dashboard lists, in sequence.
  1. Initially, the blog will appear in the "Deleted blogs" list. While the blog is in "Deleted" status, the blog owner will be able to do nothing, except request "Restore".
  2. Once the owner has requested "Restore", the blog is undeleted, and placed into the "Locked blogs" list. While the blog is in "Locked" status, all authors can access the blog to remove malware - but the blog remains offline, to all viewers. Once all malware has been removed from the blog, the owner can "Request Unlock Review".

If the blog remains in "Locked" status for over 48 hours, the blog owner may report this in the forums, and may request a manual review. The forum helpers, and online viewers, will generally see the blog displayed as "TOS violation".
This blog is in violation of Blogger Terms of Service and is open to authors only

Adult Content / Porn Detection

Blogger will soon classify and delete blogs with "adult content", which host advertisements to commercial porn sites. Like spam classification, this will probably involve both false negatives and false positives.

Spam detection

Blogger robotic processes are constantly checking the various blogs, looking for signs of spam activity and content. When a blog is subject to "Spam" classification, the blog will be displayed in the "Deleted blogs" dashboard list. The owner can do nothing, except request "Restore".

If the blog remains in "Deleted" status for over 48 hours, the blog owner may report this in the forums, and may request a manual review. The forum helpers, and online viewers, will generally see the blog displayed as "Removed".
Blog has been removed
Sorry, the blog at xxxxxxx.blogspot.com has been removed. This address is not available for new blogs.

Repeated Offenses

We have recently noted that repeated TOS Violations, involving DMCA, Malware, Porn, and Spam, are being dealt with in increasing severity.

Owner deletion or rename

Mistakes made by the owner can be confused with Spam detection. When a blog is deleted by the owner, it will appear in the dashboard "Deleted blogs" list for up to 90 days. During the 90 days, the owner (or a team member, when applicable) may "Restore" the blog. After the 90 days expire, the blog will be removed from "Deleted blogs", and will be unrecoverable. Besides being unrecoverable, no other details have been determined.

If the blog is renamed (published under a different BlogSpot URL), the external symptom may be similar to deletion by the owner.
Blog has been removed

Sorry, the blog at myblog.blogspot.com has been removed. This address is not available for new blogs.
In this case, the blog will be listed in the dashboard "My blogs" list, under the right Title. The owner needs to setup a stub blog, pointing the readers to the new URL.

Team Ownership

Any blogs owned by a deleted / locked Blogger account may simply disappear from the dashboards of other team members. If the Blogger account is not restored / unlocked, the blogs owned by that account - including any team owned blogs - may remain deleted - and inaccessible to everybody.

The Confusion Accumulates

Because of anonymous blog ownership, loss of account control, team blog ownership, and use of inactive or non existent email addresses, any account / blog which is deleted or locked for hacking (actively / as a victim), malware, and / or spam may not be easily discovered or recovered by the owner. These issues cause further confusion and frustration.

These scenarios may appear, to the untrained eye, to be signs of fraudulent, malicious, and / or petty actions by Blogger - and are loudly claimed so by spammers with their own agenda. None of these accusations are true - the above processes simply represent Blogger and Google attempting, in the best possible way, to protect everybody against the various hacking, malware, porn, and spam attacks which are constantly in progress.

>> Top

Monday, 4 February 2013

Check Your Template, And Look For Unfamiliar JavaScript Code, Following Odd Blog Behaviour

Recently, we've been seeing some odd problem reports in Blogger Help Forum: Something Is Broken, suggesting deviously hijacked blogs.
My blog is requesting me to login, using a user name and password, when I view it.
Given the URL of the window requesting the login, it's a simple matter for us to use the right forensic Internet software, and to locate a relevant snippet of code, frequently installed as part of the blog template.

Sometimes, when we reply to the blog owner with advice to remove a bit of dodgy code, we get a response suggesting disbelief. Our advice
Use the Template Editor, and remove the highlighted code snippet.
may receive a confused or skeptical response.
Where did that bit of code come from? I never installed that!
How did the code in question get installed? Discussion of one possible scenario may require thinking outside the box. Not every unrecognised blog change is being caused by memory loss by the blog owner, after an intentional accessory install or template tweak.

Looking at the subject / theme of some blogs involved in recent problem reports, we're seeing a beginning of a trend, which may indicate a new - and very subtle - blog hijacking technique. We know that Blogger blogs are subjected to brute force password guessing attacks, and we know that Blogger / Google has to consider the possibility that a brute force attack detection is made after the attack was successful.

Current blog security, and defense against blog hijacks, involves detection of hijack attempts, by Google Security. It's possible that some blogs, with some owning Blogger accounts and passwords, are more vulnerable to sophisticated password guess hacking.

When you login to Blogger or Google, you hopefully know the right account name and password, and are generally able to get logged in - after maybe one or two mistakes. You learn, soon enough, that if you have to guess your account name or current password - and you require more than a couple tries - you may have to solve yet another CAPTCHA, or request account unlock, to continue.

The ever unpopular CAPTCHA / locked account comes from Google, detecting a possible brute force attack in progress, and protecting your account and your blogs. A Blogger blog, with its content providing enough clues, combined with a simple account password that is easily guessed, may allow an experienced hacker to login to your account in one or two tries, without being detected by Google attack monitors.

It's alternately possible that some attacks are being conducted by very patient hackers, who are able to use days, and / or thousands of different computers, to conduct a throttled brute force password attack. Again, just attack without providing a detectable pattern.

This may help to explain the mysterious spam blog setups, of last year.

A hacker, able to login to a Blogger account without being detected, could install small changes in a blog template without ever being discovered. The blog owner would never discover subtle template changes, made by an easily satisfied hacker.

Finally, install latent code that does not activate immediately, as we observed during Winter 2009 / 2010, so no blogs show symptoms until the hack is installed on thousands of blogs. If one or two blog owners discover the odd code in their blogs, who would ever suspect their blog being part of a massive cloud of victims?

If you report odd behaviour by your blog, you write to Blogger Help requesting advice, and you are advised to remove a bit of dodgy code from the template - and you do not remember having installed the noted dodgy code - you may want to review your Blogger / Google password, and make the password harder to guess. Better still, start using 2-step verification for logging in to your Blogger / Google account.

>> Top

Thursday, 17 January 2013

Confusion Over Recovery From Locked Blogger / Google Accounts

Not all blog owners understand the reasons behind the locked Blogger / Google accounts.

Even less understand why recovery of locked accounts, and of the blogs owned by the locked accounts, is not immediate. We see the occasional report, in Blogger Help Forum: Something Is Broken.
I had to change the password on my account - and now my blogs are deleted! Why should I wait another "24 to 48 hours" to get my blogs back?
This blog owner does not understand the possible reasons for the locked account - and the work that goes on after the account is unlocked.

Brute force hacking of our Blogger / Google accounts, by hackers / spammers, who have use of the various botnets in the Internet, is a constant activity. Opposing activity, by the Security teams in Blogger / Google, to not let hackers and spammers take control of our accounts and blogs, is just as constant.

Some of the Security activity requires our patience - and blog owners, having to recover their deleted blogs, are not always patient.

The Security processes, in Blogger / Google hacking prevention, have to work from a worst case scenario, when detecting hacking activity.

Account hacking cannot always be detected instantly. When hacking is detected, the hacking prevention process has to consider the possibility that the accounts under attack have already been compromised.

When Blogger / Google Security detects possible brute force hacking against an account, they lock the account - and delete the blogs owned by the account. Alternatively, they quarantine the computers used in the hacking activity. This is where we see the notice of "suspicious account activity" - and possibly the dreaded "403 Forbidden".

When we discover a locked account, and request its restore, the security process looks for signs of security weaknesses allowed by the account owners - or possibly added by the (temporarily) successful hacker. In some cases, the owner may be required to change the account password, and receive instruction on using a more secure ("strong") password.

Ongoing efforts by Blogger / Google, to make the account recovery easier for the blog owners to endure, may cause mystery about blogs missing from the dashboard, without obvious recovery options.

After the Blogger / Google account is restored, the integrity of the blogs owned by the account must be verified.
  • The blog content must be examined for spammy content added.
  • The blog Permissions list must be checked, for backdoor accounts added.
  • The Mail-to-Blogger settings must be considered as a possible backdoor.

These are simply examples of what must be done, to ensure that our blogs were not compromised, even temporarily, by the hacking just detected. After you get your account back, it's not a bad idea for you to verify this, on your own. If you just got your blog back, after resetting your Blogger account password and / or verifying your phone number, check your template carefully, looking for references to unfamiliar JavaScript code, hosted outside Google address space.

The process of account and blog integrity verification will require an unpredictable time period - and needs to be done with the blogs inaccessible to anybody but the Blogger / Google security processes. The blog being offline may not be immediately observed by the owner - and this may cause more confusion.

Blogger Support is aware that nobody wants to deal with the stress of having a locked or deleted blog - especially after they have gone through the process of verifying their account. They are also well aware of the frustration that is present when someone reports
Somebody is publishing spam on my blog - and I can't access the dashboard to remove the spam!

Locking the owned blogs, after hacking activity is detected, complements the ongoing policy of not disclosing the account names, in helping to keep our blogs under our control.
>> Top