Skip to main content

Please, Do Not Publicise Your Email Address

We've seen a few reports, recently, about stolen blogs, in Blogger Help Forum: Something Is Broken.
Why is my blog not on my dashboard - and why is somebody else publishing, and using my name?
There are so many reports from people who are not using Google "One Account" login properly, that the significance of this problem report was initially overlooked.

More than a few such reports started with the blog owner email address being openly disclosed - generally on the blog, or in comments. Too many blog owners want to be contacted - and they innocently provide their email addresses as a contact point.

We've known, for years, about disclosed email addresses, and brute force password guessing. That is not the only way your email address can be used, to gain access to your Blogger account, however.

Google recently had to deal with a very carefully executed hacking project, where Blogger and Google account owners received some well phrased advice, in their email.
Google treats policy violations and invalid activity very seriously in order to protect the users, publishers, and advertisers who make up our advertising ecosystem. While we usually notify publishers and take action for policy and invalid activity at the site level, there may be times when we will need to suspend or disable accounts due to policy violations or invalid activity.

Our hope is that you will be able to resolve your policy issues during the suspension period using This Link
I'm betting that the above message was written, very carefully, by hackers who studied the phrasing and wording of the many abuse / spam / TOS violation notices, sent out by Blogger Support constantly.

Many of the recipients of the email are the same crowd that I encountered, several years ago, when we saw similar numbers of reports about the same type of stolen blogs. The owners typically

  • Post their email address, or provide it for contact, visibly.
  • Participate in comment based networking, on their blog, and openly state their email address.
  • Participate in comment based networking, on similar blogs, and openly state their email address.

Each of these activities can be used, by the bad guys, to build lists of email addresses, of people who can be easily persuaded by an email message, to resolve their policy issues using the link provided. And this led to a number of reports, in the forums, about stolen blogs - and mentioning email, offering to sell the stolen blogs back, to the rightful owners.

If you want contact from your readers, there are more safe ways to allow this.


All of the above contact options give you a possibility of hearing from and / or networking with, your readers - and none of these options require you to disclose your ownership email address.

Just don't disclose your email address, to the world at large. Your email address is one half of the security measure, as designed by Google - that prevents unknown individuals, from taking control of your Blogger account and your blogs.

Finally, if you are not yet using Google 2-Step Verification, this is the time. If you were one of the victims of the recent attack, you know the despair. If not, you truly don't want to be. In either case, you should really want to protect your account, and your blogs.

Comments

Popular posts from this blog

Adding A Link To Your Blog Post

Occasionally, you see a very odd, cryptic complaint I just added a link in my blog, but the link vanished! No, it wasn't your imagination.

Embedded Comments And Main Page View

The option to display comments, embedded below the post, was made a blog option relatively recently. This was a long requested feature - and many bloggers added it to their blogs, as soon as the option was presented to us. Some blog owners like this feature so much, that they request it to be visible when the blog is opened, in main page view. I would like all comments, and the comment form, to be shown underneath the relevant post, automatically, for everyone to read without clicking on the number of comments link. And this is not how embedded comments work.

What's The URL Of My Blog?

We see the plea for help, periodically I need the URL of my blog, so I can give it to my friends. Help! Who's buried in Grant's Tomb, after all? No Chuck, be polite. OK, OK. The title of this blog is "The Real Blogger Status", and the title of this post is "What's The URL Of My Blog?".