The latest tips and news from the Blogger team
Keeping Your Blog Secure
October 09, 2009
While October is to many a month of candy and costumes, it also happens to be
National Cyber Security Awareness Month
in the U.S. In that spirit, we thought we'd take a minute to look at a few different things you can do to make sure both your content and account are secure on Blogger.
Third Party Code
Adding site counters, templates, and other third-party code to your blog can be a great way to add some flare to your content, but can also leave your blog vulnerable to malicious activity if you aren't familiar with its source.
Over the years we've seen a number of third party scripts disguise themselves as helpful add-ons, when in fact they are performing a malicious operation behind the scenes. For example, a site counter widget may indeed be providing your blog with helpful tracking data, but at the same time may also be discreetly sending that information to advertisers for the purpose of collecting the online habits of your readers. A blog template you downloaded from a third party site might include pop-up ads or links to dangerous sites that install malware on visitor's computers.
The good news though is that most of the add-ons you will run across are perfectly legitimate. To protect yourself from the small minority of add-ons that are nefarious, we've put together a few tips to keep in mind when adding third party code to your blog:
Take a moment to review the code and look for anything that seems out of place.
For example, if you are adding a weather gadget to your blog and notice in the code that there are links pointing to unrelated sites, take that as a red flag and keep searching for another weather gadget. There is no reason that a weather gadget should include a snippet like
<a href="http://completelyfreemoney.com">Make Money Online!</a>
Before saving new template code, always preview first.
Malicious template designers may sometimes include pop-ups or other unexpected ads in the template code, which will usually be revealed with a quick preview. If anything unexpected shows up in the preview, go ahead and discard the new code by clicking
Clear Edits
.
Backup your template!
Whenever making significant changes to your blog's template, it's always a good idea to backup your content beforehand just in case you need to reverse changes.
You can easily do this from the
Layout | Edit HTML
tab by clicking the
Download Full Template
link and saving the .XML file to your hard drive. You'll then be able to revert back to this downloaded version by clicking the
Upload
button, also right under the
Layout | Edit HTML
tab.
Look first to 'trusted' code repositories for a new template or widget.
There are probably thousands of places across the web where you can find widget and template code, but it may be helpful to first check out some of the more widely known and trusted sources.
For templates, we've actually done a bit of scouting work already and collected a handful of great resources laid out
in this Buzz post
from earlier in the year. That collection comes from a number of well-established designers, and should provide plenty of secure template options to dig though.
For widgets and other scripts, there are a handful of places worth your time.
Mashable's 50 Great Widgets for Your Blog
is a very nice compilation that covers a broad range of categories.
Widgetbox
is another great portal to countless widget creations, all organized into easily browseable categories. Finally, Blogger's own Gadget Directory has hundreds of gadgets to look through. Simply click the
Add a Gadget
link under the
Layout | Page Elements
tab to access them all.
Permissions
Finally we thought it's worth touching on another security area which has proven problematic for some bloggers in the past, and that is your blog's
Permissions
settings.
Almost every day our support team receives reports from users who've been locked out of their own blog, the result of giving admin privileges to an unfamiliar blogger. Remember, you can always add more authors to your blog, but only extend admin privileges if you absolutely trust the person.
For more information about National Cyber Security Awareness Month, please check the
StaySafeOnline.org
page as well as the security series on the
Official Google blog
.
Labels
+1
3
10th Birthday
13
2010
1
accessibility
1
ads
1
adsense
7
Amazon
1
Android
2
Blog2Print
1
Blogger
26
Blogger birthday
1
Blogger Fiesta
2
Blogger Meetup
2
Blogger Stats
2
Blogger Template Designer
1
Blogger2Print
1
blogspot
2
BlogThis
1
blogworld
2
Buzz
1
calendar
1
Chrome
2
code
1
commenting
2
community
8
conference
2
custom domain
1
developers
2
DMCA
1
draft
1
dynamic views
5
events
2
feedburner
2
feeds
1
firefox
1
follow by email
1
following
2
foxytunes
1
FTP
1
gadgets
10
GAN
3
Google Analytics
1
Google Buzz
1
Google Sites
1
google+
10
grandcentral
1
help
2
ios
1
jump
1
knol
1
lightbox
1
mobile
5
monetize
3
music
1
navbar
2
New UI
4
next blog
1
OneTrueFan
1
openid
1
OpenSky
1
Page Creator
1
pages
1
pixelodeon
1
polls
1
post summaries
1
read more
1
recommend
1
SEO
2
Share
3
support
1
SXSW
1
template designer
2
twitter
1
video
2
videoblogging
1
Viglink
1
web fonts
1
webcall
1
youtube
3
zemanta
1
Archive
2020
May
2019
Jan
2018
May
2017
Mar
2016
Nov
May
Apr
Mar
2015
Dec
Sep
Jun
May
Jan
2014
Feb
2013
Dec
Sep
Aug
Jun
Apr
2012
Dec
Nov
Oct
Sep
Aug
Jul
Jun
May
Apr
Mar
Feb
Jan
2011
Dec
Nov
Oct
Sep
Aug
Jul
Jun
May
Apr
Mar
Feb
Jan
2010
Dec
Nov
Oct
Sep
Aug
Jul
Jun
May
Apr
Mar
Feb
Jan
2009
Dec
Nov
Oct
Sep
Aug
Jul
Jun
May
Apr
Mar
Feb
Jan
2008
Dec
Nov
Oct
Sep
Aug
Jul
Jun
May
Apr
Mar
Feb
Jan
2007
Dec
Nov
Oct
Sep
Aug
Jul
Jun
May
Apr
Mar
Feb
Jan
2006
Dec
Nov
Oct
Sep
Aug
Jul
Jun
May
Apr
Mar
Feb
Jan
2005
Dec
Nov
Oct
Sep
Aug
Jul
Jun
May
Apr
Mar
Feed