
This entry is an addition to the entry I just made below. It might help if you read that one first....okay, are you done with that one now?
Well, I wasn't entirely forthcoming about the randomness of the blog I was accidentally logged into. The blog actually belongs to a friend of mine, and I just called him to see if he'd logged into his blog on my computer, and he said he didn't think so, and that he hadn't updated his blog for awhile.
I then went to the question mark next to the Remember Me text on the initial login screen, and clicked the question mark to see how Google handled the Remember Me option. Well, here's a screen shot of what it said. Notice that it says the cookie expires in two weeks for any automatic login. This means that even if my friend did happen to login to his blog on my computer, which he doesn't think he did, and if he did happen to click the Remember Me checkbox, which I can't imagine he would have, it STILL would have expired after two weeks. But the initial screen shot I took (see below), says his blog was last updated Nov. 20, 2006 which was well over A YEAR AGO!
I'd love to know Google's explanation for this huge hole in the security of this blog service.
No comments:
Post a Comment