Social Icons

Pages

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Friday, 2 August 2013

Recovering Stolen Blogs Is Not An Open And Shut Case

Recently, we've seen a few problems reports, in Blogger Help Forum: Something Is Broken, requesting return of blogs stolen from the rightful owner.

Supposedly, the "rightful" owner is the person posting the problem report. We've learned from past experiences that this may not always be the case, however.

Long ago, when a stolen blog claim was posted in the forum, we could report it to Blogger Support as a "blog theft".

In many cases, given enough patience, Blogger Engineering and Google Legal would carefully examine the blog ownership history, and eventually restore the blog to its "rightful" owner. Unfortunately, even with the most careful forensic examination, the "blog theft" claim was occasionally used by hackers, to steal other peoples blogs.

Most recently, when "blog theft" is reported, Blogger Support declines to consider the case. Considering all of the issues, we generally see that they are making a responsible business decision.

Instead of spending massive amounts of time verifying individual claims, Blogger Engineering appears to be working on overall improvements to Blogger - to encourage blog owners to not put themselves, or their accounts and blogs, in unrecoverable positions.

Any blog which contains abusive material - whether malware, porn, or spam, or illegally obtained material - can be reported using the proper complaint form. Blogs which do not contain abusive material are the property of the current owner - and Blogger / Google will respect and support the current owner.

Blog owners, claiming theft, can generally report a stolen blog as abusive - if the current content justifies that claim. Other than that, the best solution is to hire a lawyer and convince a judge to issue a court order - and require Google Legal to become involved.

The issue of Blogger account and blog recovery is a long and painful one - for many people.

>> Top

Friday, 1 March 2013

Blogger And Mobile Computers

Using the term "mobile computer" is an example of the challenges involved, in using this variety of computer.

Even identifying this device, which is present in so many different manifestations, is confusing.
  • Mobile Computer.
  • Mobile WiFi device.
  • Personal Digital Assistant.
  • Pocket phone.
  • Smart Phone.
  • Tablet.

As the use of mobile computers becomes more common, we're seeing more and more problem reports and questions, from people unable to use Blogger.
  • Some folks would like to maintain and publish their own blog.
  • Others would like to post comments to their friends blogs.
  • And still others don't understand why all of the various gadgets on their blog don't work for their friends, who are also using their own mobile computers.

One of the challenges of mobile computers involves the use of smaller displays, and the need to simplify the content displayed. This requires the use of special browsers and templates, which are designed to accommodate the limitations. The need to support additional browsers and templates creates more work for Blogger Engineering, who now has more different products to support.

Also, many mobile computers are designed to work over proprietary networks, provided by various "phone" companies. Blogger has traditionally supported use of alternate services - email, and SMS - for publishing posts to their blogs.

All of these differences create complexity, and additional possibilities for failure. And we see more problem reports, attributed to use of "mobile" computers.

Full function ("desktop" / "laptop") computers have challenges - but they are still easier to use.

We know about the different major browser brands, and the differences created by the use of each browser, on our desktop and laptop computers.

Chrome, Firefox, Internet Explorer, Opera, Safari all have their various peculiarities. These differences are multiplied, when considering the issues involved in developing new features - and in keeping up with new browser versions, and continually updating the various Blogger features and wizards, when required.

Besides the various different browsers, we have to consider the different activities involved in using Blogger. Browsing blog posts, browsing comments, publishing comments, maintaining the blog, and publishing posts, are all different activities - and have their own different needs.

The relative lack of limitations in "desktop" / "laptop" computers still makes each different activity simpler for the blog owner or reader. The process of developing and supporting the different Blogger features is easier for Blogger Engineering. These differences are not so transparent, when using a "mobile" computer.

Mobile computers have known limitations.
  • Reduced display size.
  • Reduced display colour depth.
  • Reduced processor speed.
  • Lack of various system features and utilities.
  • Lack of a physical keyboard.
All of these details require mobile browsers and templates which operate differently, and the various Blogger features and processes must be used differently.

Try performing the various tasks identified above, using your desktop and mobile computer - and observe the differences. You'll quickly realise the differences, when browsing blog posts, browsing comments, publishing comments, publishing posts, and maintaining your own blog.

One of the workarounds, used by Blogger, to deal with the reduced functionality of a mobile browser / computer, is the "mobile" template. The mobile template, which is optional for all modern Blogger blogs, displays only text and pictures - and eliminates the many accessories, gadgets, and shiny formatting which may be seen in any blog with a "normal" template.

The different layouts of the posts and comments, on a mobile template, makes posting comments a different experience - and the lack of the various gadgets will produce different visitor activity.

The differences between the various "desktop" browsers are considerably less noticeable than the differences between some "mobile" browsers and computers. Most desktop computers use 3 different operating systems.
  • Apple / Macintosh.
  • Linux / Unix.
  • Microsoft Windows.
Even with the different operating systems, the realities of marketplace competition creates some interoperability between the different desktop operating systems - and the different browsers are similarly common in design.

The better known mobile computers also have 3 major different operating systems.
  • Android.
  • Apple/iOS.
  • Microsoft Windows.
Not all PDAs and smart phones use the standard 3 operating systems, however - some use proprietary browsers and operating systems, unique to the manufacturers. And the proprietary networks, provided by the different phone companies, further reduce the possibility of interoperability.

Lack of interoperability is going to create differences in how well different applications, such as Blogger, operate on the different mobile computers. These differences will be more significant than the differences created by the various "desktop" browsers, and operating systems - and we'll see more complaints from blog owners who can't use Blogger on their tablet, or whose readers can't post comments, using their smart phones.

Increasingly common use of multimedia content (both music and video) on mobile computers - combined with the lack of consistent support for cookies and scripts (and possibly, filtering of cookies and scripts) - will make availability of content differ, from computer to computer. Another problem here is lack of consistent support for the Adobe Flash product - which makes some YouTube content non playable, on some mobile computers.

Also consider the various security issues which may be different with mobile computers. Both the different security threats, and the different protective features, will make secure use of mobile computers a challenge - particularly when carried in public.

Fortunately, as mobile computers benefit from ongoing technological advances, improved design of mobile computers may make some limitations less significant. Improved displays, operating systems, and additional security devices are all coming.

As people buy and use more mobile computers, the differences between "desktop" and "mobile" computers will narrow. And use of different new desktop and mobile features, like innovative computer desktops, and products like Google Glass, will force desktop, laptop, and mobile computers to converge in functionality.

>> Top

Tuesday, 12 February 2013

Blog Owners, Logging In To Blogger, Receiving Malware Warnings

We've been seeing a few problem reports, in Blogger Help Forum: Something Is Broken, from blog owners seeing malware warnings for unknown blogs or websites.
I get a warning from Google Chrome, when I login to Blogger.
Content from www.unknownblog.com, a known malware distributor, has been inserted into this web page. Visiting this page now is very likely to infect your computer with malware.
We know that our blogs are subject to malware and spam classification - but now we see that we can also get warnings for other blogs and websites, that we don't own.

A blog owner, seeing this warning when logging in, will probably find the source of the problem in the Reading List, where content from other people's blogs is routinely found. In some cases, the problem will be in blogs that are intentionally Followed, and blatantly contain malware - and in other cases, blogs that are intentionally Followed may be redirecting the post feed, in a vain attempt to extend their reader base.

In either case, the only solution is to identify the problem blog or website, by examining each individual Reading List entry, one by one, until the noted blog or website is found - then discontinue Following the problem blog or website.

One mysterious scenario can involve blogs using favicons which are detected as malicious, by image scanning malware protection - or which are hosted from a domain which is known for malicious activity. Favicons, tiny icons which represent a blog or website, are used to decorate blog headers and feed gadgets, and are sometimes served by third party services. A "malicious" favicon may be found on entries in the Reading List, or on entries in a bloglist, which will then affect our readers ability to view our blogs.

The bottom line here is that we are responsible for the content of the blogs and websites which we link to from our blogs - and which we Follow - as well as the content on our own blogs.

>> Top

Monday, 7 January 2013

We Are At The Mercy Of Every Anti-Malware Protection Program Imaginable

We see reports, from time to time, in Blogger Help Forum: Something Is Broken, about blogs which people can't read, from their computers.
One of my readers claims that I have a virus on my blog. He provided the following information:
AVG anti-virus detected the following threat on the site:
File Name: www.mydomain.com/favicon.ico

Threatname: Exploit Black Hole Exploit Kit
How do I fix this?

Similar to the many reports that we process here, about spurious spam classification, the above report is frequently determined to be a false positive. An anti-virus alert, even if a false positive, is generally not as simple to resolve as a spurious Blogger spam classification, though.

One of the frustrating problems with false malware alerts is that they come from so many different anti-malware products.

I've contributed my opinion about computers, and the suggestion that no two privately owned computers are identical, many times. One way which many computers vary is the complement of security software, which is chosen by each different computer owner.

At any time, any different anti-malware product may decide that some component of your blog is unsafe.
  • Maybe, a single file mentioned in your blog code (as above, "favicon.ico") is suspect.
  • Maybe, content hosted by "blogspot.com" is unsafe.
  • The code may be an accessory that we added, intentionally.
  • The code may be content in another blog - hosted by your blog in a bloglist, a linklist, or maybe in the Reading List on your dashboard.
In either case, you (or your reader) won't be allowed to view the blog - or may be allowed to view the blog, but given a stern warning which very few chose to accept.

Like many problems with layered security, any malware detection can come from
  • A native browser filter.
  • A filter in a browser add-on.
  • A filter installed on the computer.
  • A filter in a network appliance.

Listen to your computer. some time. Your anti-virus protection may update automatically - and may audibly announce the update. On a typical day, I hear the Avast client on my several computers announce an update, several times - and I am not (contrary to some misconceptions) seated in front of my computer on a 24 x 7 basis.

Avast (my personally and professionally recommended choice, to many people) is only one of dozens of various anti-malware products which receives automatic updates, when the host computer is online. Any one of these products may be updated, at any time -and somebody's access to your blog (or my blog) becomes blocked.

If you get a message from one of your would be readers
I can't view your blog!
this could be someone reporting that your blog just went offline, for one reason or another - or it can be someone just discovering that the anti-malware program, on his computer, has decided that BlogSpot hosted content is unsafe. In either case, there is not a lot that you can do, except wait it out - and concentrate on the readers who can access your blog.

>> Top

Friday, 21 December 2012

Visitor Logs Cause Undue Concern, When Visitors Click On Cached Icons

We see periodic concern, expressed in Blogger Help Forum: Something Is Broken, over apparent visitor access to blog maintenance wizards, using the Quick Edit icons.
I found this entry, in my StatCounter log. How did this person get access to my blog?
http://www.blogger.com/post-edit.g?blogID=7834826019588534175&postID=890014875501476492&from=pencil
Was my blog hacked?


This may not be a justified reason to panic, however. One may first wish to check that Stats (or whatever visitor log is in use, in this case) is properly configured, to not track your own activity. The link that you see may reflect your activity.

Even if the visitor log entry in question does not appear to reflect your own activity - even when allowing for the vagaries of geo location, you may still do well to remain calm.

Thanks to the unpredictable nature of cache, in your browser, on your computer, or even on your network, the Quick Edit icon which provides you with access to the sensitive wizards, which control the content of your blog, may also be visible to the casual visitor to your blog. Any idly curious visitor may even click on such an icon, when visible.

However, visibility of the icon does not guarantee access to sensitive blog controls. Here's what I saw, when I clicked on the link above.

D'Ohh!!!

Maybe, you'd like to verify that your blog is safe?
  1. Extract the URL, from a Quick Edit pencil, on your blog.
  2. Save the URL, somewhere safe.
  3. Clear cache, cookies, and sessions (yes, clear all 3!).
  4. Restart your browser.
  5. Load the saved URL.
  6. What do you see?

Similar to the problem with phantom visitors reading a private blog, this may not be an issue to concern you. Calm down, and get back to work.

>> Top

Thursday, 20 December 2012

Use Of Google+ For Networking, And Keeping Your Blogger Account And Blogs Safe

One constant activity in Blogger Help Forum: Something Is Broken involves blog owners whose blogs were deleted - either righteously or spuriously - as part of the ongoing battle against spam, in Blogger blogs. Generally, the problem comes directly from the blog content.

Sometimes, the problem is more subtle.
When I tried to login to Blogger, I got a screen that said my account needed to be verified, due to "unusual activity on my account". Having verified my account, I see that my blogs have been deleted.
This is part of one of the more intriguing episodes, in the never ending fight against hacking and spam, in Blogger.

Some Blogger blog owners participate in comment based discussions, and provide their email addresses there. Some state their email addresses openly, in the body of the comments, for the world to see when viewing the comments. Others post comments using their Blogger accounts, knowing that the blog owners can see their email address in the comment moderation / notification email messages - and can contact them using email.

Spammers use comment based networking, to their advantage. They subscribe to any comment thread, using the "Notify me" option - then wait while blog readers comment using their Blogger accounts. As the email comes in, from blog readers commenting, they scrape the email addresses from the email content. Since most people commenting either openly state their blog URLs in the comment bodies - or link to a list of their blogs - the spammer now has two essential ingredients, to be used for hacking someone's Blogger account, and gaining control of the blogs owned by the account.

Google now provides Google+, where we can network with a designated audience, and avoid spam in our email. Using Google+, our email addresses are not revealed, and spammers have less incentive to use Google+ for email address harvesting. This protects our Blogger accounts and blogs against hacking, and relieves us from email based spam.

For people who update their Blogger accounts to use Google+ based profiles, but continue to network using Blogger comments, Blogger now protects us by using anonymous email addresses in all comment generated email. This leaves people who continue to comment, using Blogger accounts with native Blogger profiles, vulnerable to ongoing email address harvesting, and account hacking.

Blogger account hacking, using email addresses harvested from Blogger blog comments, will typically involve brute force password guessing. Blogger, detecting brute force attempts against a vulnerable Blogger account, will lock the account and the blogs. Once we verify ownership of our Blogger account - and hopefully change the Blogger account password to something less vulnerable to guessing - the blogs owned by a possibly compromised account remain locked, until they can be examined for signs of tampering, by Google security / spam analysts.

We also must consider the possibility that not all brute force password guessing attacks are being detected by Google - and some Blogger accounts are being deviously, and temporarily, hijacked.

People who setup Blogger accounts based on bogus email addresses - or who have accounts based on old email addresses which they can't use - continue to present a challenge here. These people will never receive essential email advising them of a problem in either verifying their Blogger account - or their blogs. This will continue to make our initial spam lock advice relevant.
Can you login to Blogger? Do you have a dashboard link "Deleted blogs"? That's where you start.

You wait 24 to 48 hours after submitting a Restore request - then you post back here, and we take the next step.

>> Top

Thursday, 22 November 2012

Use A Well Protected Browser, To Block Redirecting From Misbehaving Code And Gadgets

Regularly, in Blogger Help Forum: Something Is Broken, we advise people about problem code or gadgets in their blogs.

Generally, this follows reports by blog owners, that their readers are being redirected to unexpected and unwanted blogs and websites, from their blogs. Sometimes, we get the reply
I can't remove the code. Every time I login to Blogger, I am redirected, just as my readers are being treated!

When we see the latter complaint, we recognise yet one more blog owner who does not know how to properly protect himself, from malicious code and websites. Most people, who know about Layered Security, know that proper browser security is an essential complement to a properly chosen and maintained anti malware filter.

Many people, who care about browser based security, use Firefox with NoScript.

This combination provides Unix level security, "deny by default, permit by exception". Simply install NoScript as an add-on, to Firefox, to get started. Alternately, you may use Chrome with ScriptSafe, or Opera with NotScripts.

When using your browser with a script filter, there will be specific Blogger / Google websites which you should trust, and others which you should not trust.

Every time you surf to a different website - and decide that the owners of the website, which you are now viewing, have your best interests in mind - configure NoScript to allow that website, to display properly on your computer. When you find that a trusted host website does not display properly, examine the NoScript taskbar and the list of websites used by the host website. Look at the NoScript Options menu, carefully. Allow specific websites which you trust, and Forbid all other websites which you do not trust.

Deciding which websites to trust, based on their presence in the NoScript Options menu, will be a learning experience for a while. For some host website pages, which use a large number of unfamiliar websites, you may have to carefully select to "Temporarily allow all this page" - or you can "Temporarily allow" each single website, one by one, until the host website page displays properly.

When you decide to (permanently) "Allow" any website, that website will be "Allowed" on all other host websites where you may surf. Conversely, any website which you never select to "Allow" - such as the problem website which is providing the misbehaving code - will never execute on your computer again. This will prevent redirection on your computer, allow you to safely use the Blogger dashboard, and edit or remove any dodgy code which may be part of your blog.

After removing any dodgy code from your blog, always clear cache and restart Firefox, to test the effects of your editing.

>> Top

Friday, 21 September 2012

What Is This New "CNAME", Anyway?

Ever since Blogger finally restored the custom domain publishing feature, blog owners have been asking about the addition to the domain setup process - the new "CNAME".
Do I really need this? My old blogs don't have it, and they are fine.
and
My registrar won't let me add a second "CNAME" - they allow one "CNAME" / domain (my "www").
and
My registrar won't allow long addresses, such as what you have for "Destination" / "Target" / "Points To".
And we are learning that this requirement is going to be a problem for blog owners using some registrars, who can't provide this "CNAME" in their customers domains.

When we started out 3 days ago, all that we had to reference was an example setup document. As the problems were diagnosed and resolved, some blog owners were able to contribute what they had learned. Those insights I added to my FAQ, Why is my domain still in "12" / "404" State? Blogger Support later contributed a simple Guide, Custom Domain and CNAME setup.

In technical terms, the new "CNAME" is an ownership certificate, provided in a one way encryption. If you have WiFi in your home (likely) - and are using encryption (hopefully), you have a similar one way encrypted certificate - the WPA / WPA2 key / passphrase. For an allegorical (easy to read) discussion about certificate encryption, see Designing an Authentication System.

Only you, the blog owner (and anybody who you trust, on your behalf), are able to install the certificate for your domain, into your domain DNS addresses. This helps Blogger help you keep your domain under your control - as long as you pay the yearly registration fee for your domain.

The domain ownership certificate has 3 keys.
  1. A private key, which Blogger appears to change regularly (some say daily) - and one which they control.
  2. The BlogSpot URL.
  3. The domain URL (entered in "Advanced settings").


It has two significant values.
  1. "Name" / "Label" / "Host". This is now known as the "short token".
  2. "Destination" / "Target" / "Points To". This is now known as the "long token".

Note the three labels used to identify each "value" - which reflect the diversity of the registrars which may provide DNS hosting for our domains (when they are able to fulfill our specific needs). When you look at the Domain Manager wizard for your domain, you may see any of the three (possibly, others) used - as there is no authoritative label for these two DNS address components.

Let's look at the two "CNAME"s, together, so you can compare the similar structure.

This is the first "CNAME" - the "www" alias DNS address. This "CNAME" is identical for all Blogger blogs, using the asymmetrical DNS address convention.
  1. "Name" / "Label" / "Host". www
  2. "Destination" / "Target" / "Points To". ghs.google.com

This is the second "CNAME" - the domain ownership certificate. This "CNAME" will vary, for each different domain. Here we see the original example (which has since changed).
  1. The "short token". vptre6sub6jm
  2. The "long token". gv-g47p6dir6kfenzufifywsqjjpdyfzk4sqmuuiuflylcqd4oigdfa.domainverify.googlehosted.com


See the final period, at the end of the "Destination" / "Target" / "Points To" address, below? It's not in the example, above. Be very careful here, some registrar's will automatically insert the "." for you - and if you insert it also, you'll have a problem. Other registrars will need you to add it - and if omitted, you'll have a problem. Regardless, its presence, in the final product, is essential.
gv-g47p6dir6kfenzufifywsqjjpdyfzk4sqmuuiuflylcqd4oigdfa.domainverify.googlehosted.com.


If you know the value for the short token, you can Dig and extract the long token - when the second "CNAME" is properly setup.

Once you provide the above examples to the Domain Manager, the following two DNS addresses are generated and added to the domain server. The "3600" represents the TTL, a setting provided by the registrar. The "IN" is part of the Dig log extract syntax.

www.mydomain.com. 3600 IN CNAME ghs.google.com.
and
vptre6sub6jm.mydomain.com. 3600 IN CNAME gv-g47p6dir6kfenzufifywsqjjpdyfzk4sqmuuiuflylcqd4oigdfa.domainverify.googlehosted.com.
Both "CNAME"s point to specific Google servers. The second "CNAME" is only slightly obscure. Both "CNAME"s are essential.
  1. The first lets you, and your readers, view your blog.
  2. The second lets Google verify that you own the domain, and you should be allowed to publish your blog to the domain URL.

Nobody but you, the blog owner, will ever know the values of the tokens. Nobody but you, the domain owner, can install that "CNAME" into the domain DNS addresses. If DNS resolution of the short token address points back to the right Google server, then you, the owner of the blog, and the owner of the domain are verified as the same person. And the ownership certificate is "decrypted", using DNS name resolution.
  • Short token. vptre6sub6jm
  • Long token. gv-g47p6dir6kfenzufifywsqjjpdyfzk4sqmuuiuflylcqd4oigdfa.domainverify.googlehosted.com


Since the private Blogger key changes regularly, if anybody learns what tokens you used, in the short 3 step domain verification process, the values will have likely changed, and their time will have been wasted. Your blog and domain remain your blog and domain.

So, do the necessary. Blogger provides instructions, specific for 7 known registrars - and a general purpose instruction for others, in Google Help: Create a CNAME record for my custom domain. If their instructions conflict too much with your reality, try setting up third party DNS hosting.
  1. Get the short token and long token values, for your unique blog / domain.
  2. Add the new "CNAME" to your domain.
  3. Publish the blog to the domain URL.
That's it (subject to observed timing issues). You are now done with the domain ownership verification process, and with these encrypted values. Start planning the migration - this will happen faster than you think. And it is your responsibility, to get this done.

>> Top

Friday, 10 August 2012

Comments Posted, Using Google / Google+ Profiles, Use "noreply" Email Addresses

Recently, we've noted a number of complaints about Blogger commenting, in Blogger Help Forum: Something Is Broken
.My comments all use a "noreply" email address, instead of my actual email address. How do I have people email their replies to my comments?
These are people who have updated their Blogger accounts, to use a Google or Google+ profile. Neither Google or Google+ profiles provide the option to
Show my email address

It appears that, with the deployment of the new Google / Google+ profiles to Blogger, Google is making yet one more attempt to convince us to network using Google+ - and keep our email addresses to ourselves. If you moderate or monitor comments to your blog, you may have recently noticed many non anonymous comments labeled with a common email address of "noreply-comment@blogger.com", instead of personal email addresses.

People who intentionally wish to expose their email addresses in their comments will need to revert their Blogger accounts to the Blogger profile. If this is a concern for you, go to your dashboard. From the menu attached to the gear icon at the top right, select "Revert to Blogger profile", and you'll have your Blogger profile back. Then edit your profile, select "Show my email address" under Privacy, and you'll be back to sharing your email addresses in your comments.

It's likely that the noreply email addresses are being offered to keep many bloggers from, inadvertently, exposing their email addresses to email mining techniques. In remembering the long ago discovered "nice blog" spam, it's possible that "nice blog" spam was originally developed to help the spammers gather email addresses.

All that an imaginative spammer has to do is to post a "nice blog" comment, select "Email follow-up comments to me" - then watch as the Inbox fills up with follow up comments from bloggers, willingly giving up their email addresses to every stranger also selecting "Email follow-up comments to me", in that comment thread.

The people willingly providing their email addresses, to the world in general, are perfect targets for hackers later trying to brute force access to the Blogger accounts, using their email addresses.

If you decide to revert to a Blogger Profile for posting comments - or even if you don't - consider using Google 2-Step Verification, to protect your Blogger / Google account from hacking.

>> Top

Friday, 6 July 2012

Blog Control And URL Availability Hacking - Four Sides Of The Same Story

Occasionally, in Blogger Help Forum: How Do I?, we see various queries about our blogs, and how to gain or regain control.
  • How do I get a blog, which is attacking me (impersonating me, insulting me, publishing my secrets), removed from Blogger?
  • How do I claim a dormant URL?
  • How do I recover control of my blog?
  • My blog is now under somebody else's control! How do I get my blog back?
In some cases, all of these queries are simply one more attempt to gain control of a blog, or a URL. As we gain experience in reading between the lines in Blogger Help Forum, and as Blogger Support gains experience in researching blog histories, we can start to see patterns, and signs of multiple attempts to assume control of the blog - or the URL - in question.

Many blog or URL hacking attempts start quite innocently. Two of the more common ones are quite naive, and completely separate, tales.
Some people, denied recovery of the blog, because they can't prove ownership, will try another tactic.
I'll tell them that the blog was stolen from me. Surely if they think the blog was hacked, I can get it back, since I used to be the owner!
People trying to gain control of a dormant blog will likewise use their imagination.
If I get the blog deleted as spam, I can grab the URL. Surely a Dormant blog is just another type of Spam, in Blogger!
Unfortunately, these techniques have been used, already - and have resulted in still other tales of anguish.

It requires the wisdom of Solomon - and the patient persistence of Gil Grissom - to sort through the problems reports. Claims
I just graduated from college, and I can't use my email address to recover the password!
and
I just woke up from a 7 year coma, to find my family blog under control of a hacker!
and let us not overlook
My friend just died. Can I please have control of the blog, so I can put a notice to all of his friends, on the blog?
and
I never updated my Blogger only account to a Blogger / Google account - and I never got any email, warning me of the impending change!
All of these tales have enormous human interest - and seem to justify mercy for the plaintive requests.

Unfortunately, these stories - and others like them - are not always what they seem. What we sometimes see are the other side of the story.
  • Attempts to steal control of an active blog.
  • Attempts to gain control of the URL which would be perfect for their new blog, if only the URL was available.
  • Attempts to probe and reveal the identity of a blog owner, who is guaranteed anonymous blog ownership, by Blogger policy.

So, if you beg and plead for attention
None of these tools help me, in the least. Can I please speak to a live human, so I can explain my special need?
Please, do not be surprised to be directed to read about why Blogger Help is the only contact, and why you absolutely must prove ownership of the blog, before being given control. And even the ultimate insult, you must provide a copy of the death certificate plus get a court order, as you grieve for the loss of your friend or loved one.

The bottom line here is that, if you intend to publish a Blogger blog, it is your responsibility - and only your responsibility - to maintain control of your blog. You are an adult (or are presumed to be one) - and you have responsibilities, as an adult.

>> Top

Saturday, 23 June 2012

Norton Safe Web Is Claiming That All BlogSpot Blogs Are Fraudulent

We are seeing a steadily increasing flood of reports, in Blogger Help Forum: Something Is Broken, from people who use Norton Safe Web, and who are now seeing some distressing advice.
When I try to view any BlogSpot blog, I see
This web page is a known fraudulent web page. It is recommended that you do NOT visit this page.

For your protection, this web page has been blocked. Visit Symantec to learn more about phishing and internet security.
What is Google doing about this false alert?

Since Norton (aka Symantec) is not a part of Google, there is not a lot that Blogger or Google can do about this problem.

You have just 2 choices, with this problem.
  1. Get help from Norton.
  2. Get rid of Norton.
Norton is a third party product. Like all third party products, neither Blogger nor Google supports Norton.

Blogger does not control what accessories you run, on your personal computer. That's your choice - and that's your responsibility, to support.


(Update 20:30 PST): One blog owner claims to have had a Live Chat with an online Symantec representative, with a promising result.
This is an ongoing issue with the Symantec server and we are aware of this issue & working on it to get it fixed. I request to run the Live Update after 24 hours until all the updates are installed and check the status.
And subsequently,
I just ran live update... FOR me the problem is fixed.


>> Top