Social Icons

Pages

Showing posts with label Hacking Restriction. Show all posts
Showing posts with label Hacking Restriction. Show all posts

Wednesday, 28 August 2013

Being A Hacking Victim Is Not Always The Fault Of The Account / Blog Owner

Even though being the victim of a hacking attack is not (always) the fault of the account / blog owner, the blog owner may have to bear some of the responsibility.

Since hacking detection is a fuzzy process, it's not always going to be detected immediately. The previous article discusses what happens when Google does detect a hacking attack - and in some cases reacts too diligently.

If Google is not able to detect an attack, in some cases, an attack may be successful.

With some blogs, that are not updated frequently, a hacker may take control, and successfully hijack a blog.

Occasionally we see another report
I just discovered that my blog contains spam - and I can't access the dashboard, to clean the blog!
This may well be a successfully hijacked blog, discovered too late.

Unfortunately, the latter report may also be another devious attempt to steal control of somebody's blog. Blogger Support cannot, reliably, support hacking recovery, on an individual basis.

From what I can tell, Blogger / Google is working on the larger picture - making the automated detection process more reliable. Given this concern, Blogger / Google won't be frequently available to diagnose and return control of individual hijacked blogs - even when the issue is righteous.

In general, blog owners have to support themselves, and learn how to protect themselves. This may be yet one more reason why 2-Step Verification is becoming less optional.

>> Top

Tuesday, 25 June 2013

Use Google 2-Step Verification, To Protect Your Blogger / Google Account - And Your Blogs

Our Blogger accounts, and blogs, are under persistent attack by some rather nasty Internet users.

Hackers, using other peoples computers, are constantly attempting to "guess" our Blogger passwords, and take control of our Blogger accounts and blogs. Blogger accounts are particularly vulnerable to attack, because too many blog owners
  • Reveal their account names (email addresses) to the world.
  • Base their passwords upon real life details.
  • Publish blogs, where their real life details are visible to the world.

Some blog owners think that by using only one computer forever, they should be able to register that one computer as theirs, and require Google to simply deny access to their Blogger / Google accounts, from any other computer. This is a very simple solution - and it's one which is doomed to failure.

Google knows that even the most careful person will periodically use a different computer - or possibly forget their Blogger account name and / or password.

Rather than attempt to restrict us to using one single computer, for eternity, Google gives us an option to use a previously registered telephone as an authentication token, whenever we use a different computer. The telephone can use either text or voice, and provide us with a one use passcode, to enter after we successfully enter our account name and password.

This is not a foolproof solution.
  • Some people will not want to provide their phone number, to Google.
  • This strategy will only work with a preregistered phone - and registration can only be done when we are logged in to Google.
  • If the pre registered phone uses text (a smart phone / mobile computer), it will be usable only where cellular service is available.
  • If the pre registered phone uses voice, it will be usable only as well as we understand computer synthesised "speech".
  • In either case, in some cases, stress will contribute to the possibility of making a mistake.
  • Since a pre registered phone is required, we will be able to use this only as long as we carry our smart phone - or login from a pre determined location.

However, if we can deal with the above drawbacks, we have a much better chance of keeping our Blogger accounts and blogs under our control. Very few hackers, having successfully provided our account name and password, will be able to immediately use a pre registered telephone, to accept a one time use passcode.

>> Top

Thursday, 17 January 2013

Confusion Over Recovery From Locked Blogger / Google Accounts

Not all blog owners understand the reasons behind the locked Blogger / Google accounts.

Even less understand why recovery of locked accounts, and of the blogs owned by the locked accounts, is not immediate. We see the occasional report, in Blogger Help Forum: Something Is Broken.
I had to change the password on my account - and now my blogs are deleted! Why should I wait another "24 to 48 hours" to get my blogs back?
This blog owner does not understand the possible reasons for the locked account - and the work that goes on after the account is unlocked.

Brute force hacking of our Blogger / Google accounts, by hackers / spammers, who have use of the various botnets in the Internet, is a constant activity. Opposing activity, by the Security teams in Blogger / Google, to not let hackers and spammers take control of our accounts and blogs, is just as constant.

Some of the Security activity requires our patience - and blog owners, having to recover their deleted blogs, are not always patient.

The Security processes, in Blogger / Google hacking prevention, have to work from a worst case scenario, when detecting hacking activity.

Account hacking cannot always be detected instantly. When hacking is detected, the hacking prevention process has to consider the possibility that the accounts under attack have already been compromised.

When Blogger / Google Security detects possible brute force hacking against an account, they lock the account - and delete the blogs owned by the account. Alternatively, they quarantine the computers used in the hacking activity. This is where we see the notice of "suspicious account activity" - and possibly the dreaded "403 Forbidden".

When we discover a locked account, and request its restore, the security process looks for signs of security weaknesses allowed by the account owners - or possibly added by the (temporarily) successful hacker. In some cases, the owner may be required to change the account password, and receive instruction on using a more secure ("strong") password.

Ongoing efforts by Blogger / Google, to make the account recovery easier for the blog owners to endure, may cause mystery about blogs missing from the dashboard, without obvious recovery options.

After the Blogger / Google account is restored, the integrity of the blogs owned by the account must be verified.
  • The blog content must be examined for spammy content added.
  • The blog Permissions list must be checked, for backdoor accounts added.
  • The Mail-to-Blogger settings must be considered as a possible backdoor.

These are simply examples of what must be done, to ensure that our blogs were not compromised, even temporarily, by the hacking just detected. After you get your account back, it's not a bad idea for you to verify this, on your own. If you just got your blog back, after resetting your Blogger account password and / or verifying your phone number, check your template carefully, looking for references to unfamiliar JavaScript code, hosted outside Google address space.

The process of account and blog integrity verification will require an unpredictable time period - and needs to be done with the blogs inaccessible to anybody but the Blogger / Google security processes. The blog being offline may not be immediately observed by the owner - and this may cause more confusion.

Blogger Support is aware that nobody wants to deal with the stress of having a locked or deleted blog - especially after they have gone through the process of verifying their account. They are also well aware of the frustration that is present when someone reports
Somebody is publishing spam on my blog - and I can't access the dashboard to remove the spam!

Locking the owned blogs, after hacking activity is detected, complements the ongoing policy of not disclosing the account names, in helping to keep our blogs under our control.
>> Top

Thursday, 22 November 2012

Use A Well Protected Browser, To Block Redirecting From Misbehaving Code And Gadgets

Regularly, in Blogger Help Forum: Something Is Broken, we advise people about problem code or gadgets in their blogs.

Generally, this follows reports by blog owners, that their readers are being redirected to unexpected and unwanted blogs and websites, from their blogs. Sometimes, we get the reply
I can't remove the code. Every time I login to Blogger, I am redirected, just as my readers are being treated!

When we see the latter complaint, we recognise yet one more blog owner who does not know how to properly protect himself, from malicious code and websites. Most people, who know about Layered Security, know that proper browser security is an essential complement to a properly chosen and maintained anti malware filter.

Many people, who care about browser based security, use Firefox with NoScript.

This combination provides Unix level security, "deny by default, permit by exception". Simply install NoScript as an add-on, to Firefox, to get started. Alternately, you may use Chrome with ScriptSafe, or Opera with NotScripts.

When using your browser with a script filter, there will be specific Blogger / Google websites which you should trust, and others which you should not trust.

Every time you surf to a different website - and decide that the owners of the website, which you are now viewing, have your best interests in mind - configure NoScript to allow that website, to display properly on your computer. When you find that a trusted host website does not display properly, examine the NoScript taskbar and the list of websites used by the host website. Look at the NoScript Options menu, carefully. Allow specific websites which you trust, and Forbid all other websites which you do not trust.

Deciding which websites to trust, based on their presence in the NoScript Options menu, will be a learning experience for a while. For some host website pages, which use a large number of unfamiliar websites, you may have to carefully select to "Temporarily allow all this page" - or you can "Temporarily allow" each single website, one by one, until the host website page displays properly.

When you decide to (permanently) "Allow" any website, that website will be "Allowed" on all other host websites where you may surf. Conversely, any website which you never select to "Allow" - such as the problem website which is providing the misbehaving code - will never execute on your computer again. This will prevent redirection on your computer, allow you to safely use the Blogger dashboard, and edit or remove any dodgy code which may be part of your blog.

After removing any dodgy code from your blog, always clear cache and restart Firefox, to test the effects of your editing.

>> Top

Tuesday, 13 November 2012

Blogger Comments Being Posted Using An Anonymous Blogger Email Address

Some Blogger blog owners use their Blogger blogs as the center of their peer to peer networking life.

Many blog readers are expected to post comments - and to leave their email addresses, as part of their message or profile, to allow direct contact. Long ago, I used the email address of my commenters, as part of an easy "Contact Me" form, on this blog.

Recently, we've been noting that Blogger comments don't always include a useful email addresses - many comments simply describe the commenter as
noreply-comment@blogger.com
Not all blog owners - and readers - appreciate this change.
When I leave a comment using my google profile, it isn't linking my profile with my email address. How do I get my email address properly displayed?
and
Why do so many comments, published to my blog, show the email address of "noreply-comment@blogger.com"? How do I email my readers?


For some time, we've known of the dangers of revealing your email address to the world, in general.

Blogger blog owners have been a known special risk, with their email addresses. Google developed Google+, with the Google+ profile, to allow everybody to network with their friends - both old and new - without the risk of revealing one's email address.

Google+ replaces email completely. You can share comments, messages, photos, and videos with anybody, in a self contained universe - and you can define your own, personal universes. This leaves the need to reveal your email address completely unnecessary (though you can use email, if you wish, without knowing anyone's address - or revealing yours).

After Google+ became popular, Blogger added the option to link our Blogger blogs with our Google+ profiles. Blogger profiles, based on Google+, are cleaner, and use the Google+ displays to update.

To encourage people to use Google+ for peer to peer networking activity, and to make our Blogger accounts and blogs safer, Blogger has eliminated our email addresses from all outside correspondence - including when we publish comments on Blogger (and non Blogger) blogs, using a Google+ based Blogger profile.

If we publish a comment on somebody's blog, and the blog owner has enabled comment moderation or notification, our comment shows up in the email inbox of the blog owner - but with our email address displayed as "noreply-comment@blogger.com".

With email addresses not displayed, this helps protect our Blogger account names from becoming unnecessarily revealed. Blog owner - reader comment communication is still possible - but again, without the email address of the reader being known.

Some time ago, I discovered an odd type of comment spam, which I termed "nice Blog" spam.
Nice blog. I will keep visiting this blog very often.
This spam, from what I can tell, has been published by the millions, in various blog comments. It's likely that this particular spam is being published as a very imaginative form of email address mining, and recently became even more imaginatively produced.

All that the spammer has to do is publish a spam comment, and select the option to "Send me replies". Any comments published later, and including the commenters actual email address, would be delivered directly to the spammers inbox. Knowing the email address - and the blog URL (how many comments do not include a link to a blog?) - the hacker would go straight to work.

Later, we would see forum reports.
I can't control my blog, any more - and somebody has updated it with spam!
This was a direct result of the former blog owner, having left a comment on somebody else's blog.

By eliminating our email addresses from our comments, Google is helping to protect our accounts and blogs, while letting us continue to comment on each others blogs - and to eliminate one type of unnecessary spam from our blogs.

Google+, which replaces email for networking, uses a "Friend of a Friend" relationship to let you expand your universe infinitely, with each comment, message, photo, and video that you share. It lets you control the expansion of your universe - if you wish. And, it helps keeps your Blogger blog under your control.

>> Top