After spending hours upon hours tracking through the home and office networks, I’ve come to the conclusion that neither network was breached, and that one of two things has happened:
1) One of Google’s authentication servers has had a major hiccup. This is supported by the numerous reports of similar issues, reports from people I know having sporadic difficulties logging in and out, and reports that Google is possibly beta-testing new features (though I hold those reports mostly at bay…) I’ve seen similar things happen on other sites — One day you login fine; the next you can’t get in at all, and when it finally happens to enough people the host sits up and pays attention. It’s certainly a possibility.
However, the problem with this is that there is no way for the people having the problem to get to a person in an effort to fix it.
2) The account was hacked on their end or records somehow munged, resulting in a loss of my secondary email address and leaving me without any recourse but to wait 5 days for the password reset opportunity. Why 5 days? Because Google doesn’t have a way to access my password and just send it to me. I have to wait 5 days with no account activity and then try to log in, at which point I will have the opportunity to access the security question and answer it to get a new password at my current secondary address.
Today I tried the gmail-lockdown@google.com address. I received an automated response saying that if I’d been locked out for excessive activity or violations of TOS, I would be readmitted after some unspecified period of time. It also asked for specifics of my situation, which I sent to them along with attached screenshots. So far, no reply to THAT email, but I did receive an automated response to my complaint sent to mail-support@google.com, giving me a URL to visit with a form to complete reporting abuse. I’ve already done that with no response, but did it again in the hopes that perhaps this one would yield a reply.
A friend also sent me some contact info for people inside Google, which I will also use if I can’t go through the usual remedies. I am waiting because I want to try and exhaust the normal remedies first and blog it, if for no other reason than to have a series of steps on the blog for anyone else who might have this happen to them. I’m keeping screenshots and copies of my email so that I can create a complete record of what happened and when.
In the meantime, I just deactivated my forwards from my “real” email addresses and fired up Outlook, so I’m not completely screwed. I am missing any email that was sent to me between Sunday at about 11pm through Monday at 10AM when I discovered the problem. It’s been a huge time-waster when I don’t have time for it…
Dealing with the question of whether the network has been compromised has been the biggest pain. This is a situation where I could say with 95% certainty that the problem wasn’t on my end, but there’s always that 5% margin of doubt..that niggling question…”Did I really lock it down as well as I thought I did?” So you go through all the tracing steps, do all the extra virus scans, pull all the logs and check ‘em. It all takes time. As an added measure of caution, I decided it was time to upgrade some of the wireless security measures and lock down the kids’ laptops just a bit tighter. All time, but I’m hoping time well spent.
It annoys me to no end that it’s time well-spent because of what someone with malicious intent and too much time on their hands feels free to do. After all, I’m not Microsoft or some big mega-company…I’m a sole proprietor with a second job who relies on the Internet, email and technology to get the job done. Problem is, hackers don’t care. They just like doing it because they can…and until we figure out how to make it so they can’t, they’ll continue to try to have big fun at our expense. Literally.
Technorati Tags: google, gmail, hack
Sphere: Related Content