Who is accessing your Gmail account?
antoniocangiano.com
antoniocangiano.com
> Also, wiping your computer or using 1Password isn't going to stop you from giving your password to random web apps...
I'm not incautious with my password in the least. It's generally not hazardous to sign in with Google elsewhere, provided you trust the site. You can make an assessment of the risks and benefits of singing in through your Google account yourself on a site-by-site basis. If you have reason to believe that they've violated your trust or that a security breach has happened, you can revoke access (from that site) and change your password (or even decide to be paranoid and never login elsewhere again).
Also, man, what is the point of DBANing your install? Is software that is no longer accessible to the OS or likely even any consumer level hardware going to magically log your keystrokes, I mean make you give your usernames and passwords to websites and then be surprised that they use them?
I've never given my username and password directly to websites, except for Etacts. For the other sites, I simply authorized them (through the Google interface) to access certain functionalities. Behind the scenes Google doesn't provide them with my password: https://www.google.com/support/accounts/bin/answer.py?answer...
They also put such sites on a list of that is accessible from your account. You can remove sites from that list at any time.
> Also, man, what is the point of DBANing your install?
Yeah, that's sort of unrelated. I've been planning a clean install for a while.
> you give your usernames and passwords to websites and then be surprised that they use them?
When THEY use them? No. When someone else does, yes.
Anyway, we have beaten this horse to death many times over.
"I've never given my username and password directly to websites, except for Etacts." This is all about Etacts right? How do you expect someone to be accessing your account? You gave them your user and password. The point is, you hand out your username and password, it just makes you look silly to suggest that your account is being compromised by covert wifi sniffers (you are using encryption right?), etc.
I still don't understand why you need to DBAN to do an OS reinstall unless you are just using the term DBAN loosely.
Agreed. IMO, asking for your password when there are API's readily available is alone enough to disqualify a company from being "trustworthy". Just the idea of keeping a bunch of GMail passwords in some decryptable database is quite a bit scary.
The command
gzip -d < download.gz | gzip -d
shows an html document.It's pretty simple to keep someone out of your email, don't give anyone the password.
Of course if I suspect an intrusion, I'm going to ensure that proper action is taken to cover all of my bases. I was planning a cleanup of my laptop anyway, so I may as well do it now.
Don't read too much into my changing the password on a wired desktop. It was one of the computers at hand, so I went with the most secure option, however unlikely it may be to make a difference (doing so didn't require any extra effort on my part).
> It's pretty simple to keep someone out of your email, don't give anyone the password.
This will be a moot point when Google will implement OAuth for IMAP.
PS: At this point, I believe it was a legitimate access by Etacts.
(also posted [EDIT: unsucessfully-attempted-to] this on the blog.)
Update: I have also Etacts with enabled access. I had completely forgotten about them.
You do the same with your credit card whenever you purchased from a site or in a store. You trust them, but then verify that you are not being screwed over.
The credit card comparison doesn't really make sense as credit cards were especially designed to be used the way we use them.
Email accounts haven't been designed to be used in such a fashion as to allow 3rd party applications access them. Especially not the kind of email services where you don't have access to the server / firewall. What Google is providing is a nice thing but you only get the see the last 10 entries or so. What happens when you go on vacation ? What happens if you use some other email provider ?
My point is that the main conclusion of your blog post should be about how you control this but how you should avoid doing this in the first place.
I use an older (faster) version of gmail on my (slower) netbook, which doesn't have the "account activity" link. After reading this article, I switched versions and checked: 6 days ago, there was an alert about an access from China with this IP: 116.30.36.239
The emails in question have stopped for the last couple of days. It seems that google automatically detected and solved the problem, without me even being aware of it. Good google.
There are 17 other potential ones, but I had moved them to my spam folder, so I can't tell where they came from originally. Looking closer, the first email in each chain seems to come from my account, but they are spread over several days, not just the day of the access.
Unfortunately, they could have potentially accessed any other services whose "forgotten password" emails go to this one, and then deleted the replies. But it looks like an automated spam attack.
When I realized today, I now logged out all other users (there didn't seem to be any) and changed my password. Maybe I should check all my linked accounts.
EDIT The header of their email has:
Received: from PC-201004061503 ([116.30.36.239])
Where that IP is the hacker's IP. Comparing with mail I've sent, the Received line includes my IP and "with HTTP". So it looks like they weren't using the web interface, but some direct one (IMAP? POP3?). If they're a spammer, it would be automated. BTW their emails all had the same content, most of them with the subject " 请在这里编辑主题...", which I'm guessing is "buy viagra" in Chinese.EDIT: The server is still having issues.
One of these days I have to migrate all of my Apache-hosted Wordpress blogs to Nginx.
I second this. For years I tried to tame the beast that is Apache. After switching to nginx I could not be happier.
How can this be verified, given that sent messages can be deleted as well?