Skip to main content

Team Ownership, And Blog Security

A well known adage describes multi-personal issues, in general
A chain is only as strong as its weakest link.
In terms of blogs with multiple owners, each individual owner becomes one link, in the chain of blog security.

Any blog with multiple administrators ("owners") is subject to its abuse by any one of the owners. Whatever the abuse involves
  • Installation of dodgy code.
  • Dodgy installation practices.
  • Addition of untrustworthy members or administrators.
  • Theft of the blog by removing all other administrators.
You (the original creator of your blog) absolutely must exercise discretion, in inviting other people to jointly administer a blog with you.

Any one administrator can install malicious code, can use an EZ Install procedure to invite a hijacked Blogger account, can add another administrator who can do any of these things, or can even remove all other administrators. Just one person (the "weakest link") can cause chain breakage (a damaged, hijacked, spam locked, or stolen blog).

Blog authors can also cause problems - either with dodgy links or posts.

You simply must choose your administrators - and team members, with great care. Blogger cannot intervene in internal issues which involve team membership.

>> Top


Betty Soapmaker said…
SO true! Thanks for the reminder.
JK said…
I have a question, if you don't mind answering. A little off topic, but I wasn't sure where to leave it. If I am signed in to my Google account, and click on a blog link - and then see the page that says "This blog is open to invited readers only," will that blog owner be able to see that I (from my e-mail address or Google account) attempted to read the blog, or access the page?
Thanks so much for any insight.
Chuck said…

Many visitor logs will show your access to the home page of the blog, when the overlaying "interstitial notice" page "This blog is open to invited readers only" is displayed.

So yes, you may show up, in some access log (or be counted by Stats, for instance) as having read the home page. This is one reason why the individual numbers in Stats won't ever add up to equal the other individual numbers. In the Popular Posts list, there is no entry for "Home Page" - just for individual posts.

However - and please do not panic here - no access log will have the ability to display your email address or Google account. Your Google login state is only available to Blogger / Google code, such as the comment wizard, or the private blog access checking (which leads to the interstitial display). Your Google login state is not available in any visitor log.
A little off-topic perhaps, but reading about blog security, reminded me of this. Sometimes when leaving a comment on a blog, it asks for your email address saying it won't be published. Can the owner of that blog see your email address and how secure is this?
I now a void leaving a comment on blogs which ask for this just in case.
Thank you in advance.
Chuck said…

If this is a Blogger comment form, your email address is only used to authenticate you to Blogger - and what is published to the blog is the username, and a profile pointer. I examined my incoming comment email, and that's all that shows.

In other words, what you see published above is what I know about you. Nothing more.

On the other hand, if you're asking about a comment posted outside Blogger, that's completely unpredictable.

It's not impossible that a non Blogger / Google website based email mining scheme is being used, as the start to a Blogger blog hijacking operation. With that said, even unwisely sharing one's email address / Blogger account name isn't an immediate doorway into one's Blogger account.

You've asked a good question though, and one that deserves some thought.

It's interesting reading about Blogger comment forms and comments posted outside Blogger. The blogs where I found an email address was required were (from memory) mainly Wordpress and ones that had Nuff Nuff on them.
Thanks for letting me know that the email address can't be seen.
Chuck said…

I'd trust WordPress, equally as I'd trust Blogger / Google. "Nuff Nuff" though is too cute a name for me to trust their service. I'm not getting any useful hits, from Googling "nuff nuff".
gerald chan said…
Nice blog you have! keep up the good work =)

Popular posts from this blog

Stats Components Are Significant, In Their Own Context

One popular Stats related accessory, which displays pageview information to the public, is the "Popular Posts" gadget.

Popular Posts identifies from 1 to 10 of the most popular posts in the blog, by comparing Stats pageview counts. Optional parts of the display of each post are a snippet of text, and an ever popular thumbnail photo.

Like many Stats features, blog owners have found imaginative uses for "Popular Posts" - and overlook the limitations of the gadget. Both the dynamic nature of Stats, and the timing of the various pageview count recalculations, create confusion, when Popular Posts is examined.

Help! I Can't See My Blog!

I just posted to my blog, so I know that it's there. I can tell others are looking at it. But I can't see it.

Well, the good news is you don't have a blog hijack or other calamity. Your blog is not gone.

Apparently, some ISPs are blocking *, or maybe have network configuration or infrastructure problems. You can access or you can access, but you can't access, or

You can't access them directly, that is. If you can access any free, anonymous proxy servers, though, you may be able to access your blog.

Note: You can use PKBlogs with the URL pre packaged. Here is the address of this post (with gratuitous line breaks to prevent the old post sidebar alignment problem):

And an additional URL, to provide to those suffering from this problem, would be the WordPress version of this post: