<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WARNING: Google&#8217;s Gmail security failure leaves my business sabotaged</title>
	<atom:link href="http://www.davidairey.com/google-gmail-security-hijack/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.davidairey.com/google-gmail-security-hijack/</link>
	<description>David is a graphic designer passionate about brand identity. Here&#039;s his portfolio and a wonderful community of 100K+ designers subscribed to his blog.</description>
	<lastBuildDate>Sat, 11 Feb 2012 23:16:53 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: David Airey</title>
		<link>http://www.davidairey.com/google-gmail-security-hijack/comment-page-13/#comment-162402</link>
		<dc:creator>David Airey</dc:creator>
		<pubDate>Fri, 03 Feb 2012 23:04:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.davidairey.co.uk/google-gmail-security-hijack/#comment-162402</guid>
		<description>Sorry to read it happened to you, Bill. Good of you to share what you learned with the readers here, and I hope it&#039;s the last of your online troubles.</description>
		<content:encoded><![CDATA[<p>Sorry to read it happened to you, Bill. Good of you to share what you learned with the readers here, and I hope it&#8217;s the last of your online troubles.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bill</title>
		<link>http://www.davidairey.com/google-gmail-security-hijack/comment-page-13/#comment-162035</link>
		<dc:creator>bill</dc:creator>
		<pubDate>Fri, 27 Jan 2012 08:14:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.davidairey.co.uk/google-gmail-security-hijack/#comment-162035</guid>
		<description>Things a Gmail account owner can to to at least stay abreast of a hacker...

You can periodically look at &quot;ALL&quot; mail on the left side options, you should be able to see Bolded messages which the hacker either forwarded or deleted. At least that worked for me.

&quot;All Mail&quot; is a hidden option but there nonetheless.

Otherwise you can periodically look at your filter and forwarding settings to see if a hacker has changed them.

If you find them, you can delete them.

You can also switch to another email provider and hope for the best.</description>
		<content:encoded><![CDATA[<p>Things a Gmail account owner can to to at least stay abreast of a hacker&#8230;</p>
<p>You can periodically look at &#8220;ALL&#8221; mail on the left side options, you should be able to see Bolded messages which the hacker either forwarded or deleted. At least that worked for me.</p>
<p>&#8220;All Mail&#8221; is a hidden option but there nonetheless.</p>
<p>Otherwise you can periodically look at your filter and forwarding settings to see if a hacker has changed them.</p>
<p>If you find them, you can delete them.</p>
<p>You can also switch to another email provider and hope for the best.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bill</title>
		<link>http://www.davidairey.com/google-gmail-security-hijack/comment-page-13/#comment-162034</link>
		<dc:creator>bill</dc:creator>
		<pubDate>Fri, 27 Jan 2012 07:58:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.davidairey.co.uk/google-gmail-security-hijack/#comment-162034</guid>
		<description>Anyone who says Gmail has fixed their security problem is mistaken. 

I had my Gmail account hacked today. Yep, the hacker added the following filters:

Matches: from:(from:enquiry OR from:consulta OR from:abritel OR from:inquiry OR from:fewo-direkt OR from:homelidays OR from:aanvraag OR from:vacationrentalagent.com OR from:flipkey.com OR from:ownersdirect OR from:rentals OR from:holidaylettings OR from:richiesta OR from:enquiries OR from:demande OR from:envoi OR from:estadísticas OR from:pureholidayhomes.com)
Do this: Never mark it as important 

Notice that this creep did not seem to forward anything - just &quot;never mark as Important? Strange. How did this help him?

What was really happening was that emails arriving in my inbox with certain content would vanish within a few seconds of arrival - as if they had been forwarded and deleted. How was this done as there was nothing in forwarding and just the note mentioned above in filters?  

Was he like a Trojan horse residing in my pc? Was he somehow in Gmail&#039;s server? Was it all by remote control based on pre-set settings which I could not see?

Turns out that the hacker was answering them as if he was me, and then attempting to collect funds which were payable to me, often in excess of 5 figures USD, in each of the emails. A lot of money.

The unsuspecting senders of the emails had no clue and thought they were getting a response from me as to where to send their money! Little doubt that any money sent likely went to Russia or China.

This guy is a hard cold criminal, much like the guy in David&#039;s situation, except he has ashed in on some major $.

Has he done this 100 times, a 1000 times, or maybe a million times?

I&#039;ve reported this to gmail. Haha. And to the FBI and to the law enforcement cyber consortium to which they belong.

I expect Gmail to do nothing, and for the FBI to get nowhere with this.

Is there any excuse for Gmail not fixing their security problem? Is there any reason that Gmail can&#039;t notify an account owner when someone from a foreign county has accessed your account? We know the answer is NO. Why won&#039;t they? It&#039;s really hard to understand, as they become unwitting accomplices to the criminal and don&#039;t seem to care!

Several things I learned like David:

1. When you get hacked you are on your own.
2. It is nearly impossible to identify the point of entry or the weakness.
3. There seems to be no way to protect yourself, because if this creep got in once, there is nothing keeping him or others from doing it again.
4. I gave my password to no one, nor did I click on any greeting cards nor click on any executable files from unknown senders.
5. I have concluded that NO ONE is safe from a hacker.
6. Humans wrote the code creating Gmail, and those men or women are free to be hackers or to give or sell the code to hackers.
7. As long as humans create the security, there will never be any true security.
8. It is as if you have a high $ safe for valuables in your home, and there are 1,000 guys one the street who literally have a key to it.
9, No person is safe. No government is safe. No bank account is safe. No corporate or government or military secrets are safe.
10 The Internet has brought with it a monster akin to, but far more powerful than Frankenstein. Once created, literally no one can stop him, and his evil doing is unending. He controls us all. There seems to be no solution.

The basis for David&#039;s and all other poster&#039;s frustration is very understandable. Our Internet world is absolutely insecure.</description>
		<content:encoded><![CDATA[<p>Anyone who says Gmail has fixed their security problem is mistaken. </p>
<p>I had my Gmail account hacked today. Yep, the hacker added the following filters:</p>
<p>Matches: from:(from:enquiry OR from:consulta OR from:abritel OR from:inquiry OR from:fewo-direkt OR from:homelidays OR from:aanvraag OR from:vacationrentalagent.com OR from:flipkey.com OR from:ownersdirect OR from:rentals OR from:holidaylettings OR from:richiesta OR from:enquiries OR from:demande OR from:envoi OR from:estadísticas OR from:pureholidayhomes.com)<br />
Do this: Never mark it as important </p>
<p>Notice that this creep did not seem to forward anything &#8211; just &#8220;never mark as Important? Strange. How did this help him?</p>
<p>What was really happening was that emails arriving in my inbox with certain content would vanish within a few seconds of arrival &#8211; as if they had been forwarded and deleted. How was this done as there was nothing in forwarding and just the note mentioned above in filters?  </p>
<p>Was he like a Trojan horse residing in my pc? Was he somehow in Gmail&#8217;s server? Was it all by remote control based on pre-set settings which I could not see?</p>
<p>Turns out that the hacker was answering them as if he was me, and then attempting to collect funds which were payable to me, often in excess of 5 figures USD, in each of the emails. A lot of money.</p>
<p>The unsuspecting senders of the emails had no clue and thought they were getting a response from me as to where to send their money! Little doubt that any money sent likely went to Russia or China.</p>
<p>This guy is a hard cold criminal, much like the guy in David&#8217;s situation, except he has ashed in on some major $.</p>
<p>Has he done this 100 times, a 1000 times, or maybe a million times?</p>
<p>I&#8217;ve reported this to gmail. Haha. And to the FBI and to the law enforcement cyber consortium to which they belong.</p>
<p>I expect Gmail to do nothing, and for the FBI to get nowhere with this.</p>
<p>Is there any excuse for Gmail not fixing their security problem? Is there any reason that Gmail can&#8217;t notify an account owner when someone from a foreign county has accessed your account? We know the answer is NO. Why won&#8217;t they? It&#8217;s really hard to understand, as they become unwitting accomplices to the criminal and don&#8217;t seem to care!</p>
<p>Several things I learned like David:</p>
<p>1. When you get hacked you are on your own.<br />
2. It is nearly impossible to identify the point of entry or the weakness.<br />
3. There seems to be no way to protect yourself, because if this creep got in once, there is nothing keeping him or others from doing it again.<br />
4. I gave my password to no one, nor did I click on any greeting cards nor click on any executable files from unknown senders.<br />
5. I have concluded that NO ONE is safe from a hacker.<br />
6. Humans wrote the code creating Gmail, and those men or women are free to be hackers or to give or sell the code to hackers.<br />
7. As long as humans create the security, there will never be any true security.<br />
8. It is as if you have a high $ safe for valuables in your home, and there are 1,000 guys one the street who literally have a key to it.<br />
9, No person is safe. No government is safe. No bank account is safe. No corporate or government or military secrets are safe.<br />
10 The Internet has brought with it a monster akin to, but far more powerful than Frankenstein. Once created, literally no one can stop him, and his evil doing is unending. He controls us all. There seems to be no solution.</p>
<p>The basis for David&#8217;s and all other poster&#8217;s frustration is very understandable. Our Internet world is absolutely insecure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Boissiere</title>
		<link>http://www.davidairey.com/google-gmail-security-hijack/comment-page-13/#comment-162025</link>
		<dc:creator>Mark Boissiere</dc:creator>
		<pubDate>Thu, 26 Jan 2012 22:19:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.davidairey.co.uk/google-gmail-security-hijack/#comment-162025</guid>
		<description>I really don’t know what to say, David, this is bloody awful. I have just spent a whole year getting my domain to the front and if it was stolen I really don’t know what I would do.</description>
		<content:encoded><![CDATA[<p>I really don’t know what to say, David, this is bloody awful. I have just spent a whole year getting my domain to the front and if it was stolen I really don’t know what I would do.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Airey</title>
		<link>http://www.davidairey.com/google-gmail-security-hijack/comment-page-13/#comment-157182</link>
		<dc:creator>David Airey</dc:creator>
		<pubDate>Fri, 02 Dec 2011 23:28:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.davidairey.co.uk/google-gmail-security-hijack/#comment-157182</guid>
		<description>I don&#039;t know, Marco. You can still find me checking my Gmail filters every now and again, just to be sure.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t know, Marco. You can still find me checking my Gmail filters every now and again, just to be sure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marco</title>
		<link>http://www.davidairey.com/google-gmail-security-hijack/comment-page-13/#comment-157171</link>
		<dc:creator>Marco</dc:creator>
		<pubDate>Fri, 02 Dec 2011 20:42:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.davidairey.co.uk/google-gmail-security-hijack/#comment-157171</guid>
		<description>I read all of this. Was linked from Chris Coyer&#039;s site, but  you are saying this flaw has been fixed already in GMAIL?</description>
		<content:encoded><![CDATA[<p>I read all of this. Was linked from Chris Coyer&#8217;s site, but  you are saying this flaw has been fixed already in GMAIL?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rah</title>
		<link>http://www.davidairey.com/google-gmail-security-hijack/comment-page-13/#comment-149360</link>
		<dc:creator>Rah</dc:creator>
		<pubDate>Mon, 27 Jun 2011 13:25:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.davidairey.co.uk/google-gmail-security-hijack/#comment-149360</guid>
		<description>Start using google apps then. At least yo have control of your email.
After all gmail.com is not our own and it&#039;s always good to have a system where yo can back your self.</description>
		<content:encoded><![CDATA[<p>Start using google apps then. At least yo have control of your email.<br />
After all gmail.com is not our own and it&#8217;s always good to have a system where yo can back your self.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rich</title>
		<link>http://www.davidairey.com/google-gmail-security-hijack/comment-page-13/#comment-149244</link>
		<dc:creator>rich</dc:creator>
		<pubDate>Mon, 20 Jun 2011 22:42:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.davidairey.co.uk/google-gmail-security-hijack/#comment-149244</guid>
		<description>I just got off the phone with Google… they refused to help, stating that I violated the terms of their agreement. 

Wow!

Guess anyone who uses gmail’s in for a big surprise WHEN THEY GET HACKED. AND YOU WILL GET HACKED and don’t expect google to help you. Frankly, I wish someone had posted this problem before I joined back when they first started. If I were you, I’d cancel my account right now. All my personal information was in there, thank god I made some tweaks to it before this. Is your personal info in your gmail account? Facebook, Linkedin, Tweeter are also going to cause you problems and you’ll get hacked…. I TRUSTED THESE FOLKS and I trusted these websites. Guess I’ll read the next Terms before signing on to anyone for free.

this email&#039;s no longer mine, it&#039;s been hacked. richcarbajal@gmail.com along with facebook, tweeter, linkedin, and so on... NO thanks to GMAIL.</description>
		<content:encoded><![CDATA[<p>I just got off the phone with Google… they refused to help, stating that I violated the terms of their agreement. </p>
<p>Wow!</p>
<p>Guess anyone who uses gmail’s in for a big surprise WHEN THEY GET HACKED. AND YOU WILL GET HACKED and don’t expect google to help you. Frankly, I wish someone had posted this problem before I joined back when they first started. If I were you, I’d cancel my account right now. All my personal information was in there, thank god I made some tweaks to it before this. Is your personal info in your gmail account? Facebook, Linkedin, Tweeter are also going to cause you problems and you’ll get hacked…. I TRUSTED THESE FOLKS and I trusted these websites. Guess I’ll read the next Terms before signing on to anyone for free.</p>
<p>this email&#8217;s no longer mine, it&#8217;s been hacked. <a href="mailto:richcarbajal@gmail.com">richcarbajal@gmail.com</a> along with facebook, tweeter, linkedin, and so on&#8230; NO thanks to GMAIL.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rah</title>
		<link>http://www.davidairey.com/google-gmail-security-hijack/comment-page-13/#comment-142995</link>
		<dc:creator>rah</dc:creator>
		<pubDate>Tue, 01 Feb 2011 22:13:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.davidairey.co.uk/google-gmail-security-hijack/#comment-142995</guid>
		<description>would have been good if Google Actually looked at this and responded here.

They should have a better way to manage these filters.
Firstly I do agree that this post is 3 years old and I hope there are improvements in gmail accounts.

There are many business starting to use Gmail for Business which apparently says it provides:

SSL enforcement for secure HTTPS access	
Customizable spam filtering	
Customize password strength requirements	
Email routing and email gateway support	
Customizable policies to filter email containing sensitive information	
Email encryption using standard TLS protocols

==

I really don&#039;t know if this is going to help solve anything for future problems.

And for the person who has hijacked your domain, I am sure that person will have to pay for what it has done.

Glad to hear that you got it back.

==

Cheers</description>
		<content:encoded><![CDATA[<p>would have been good if Google Actually looked at this and responded here.</p>
<p>They should have a better way to manage these filters.<br />
Firstly I do agree that this post is 3 years old and I hope there are improvements in gmail accounts.</p>
<p>There are many business starting to use Gmail for Business which apparently says it provides:</p>
<p>SSL enforcement for secure HTTPS access<br />
Customizable spam filtering<br />
Customize password strength requirements<br />
Email routing and email gateway support<br />
Customizable policies to filter email containing sensitive information<br />
Email encryption using standard TLS protocols</p>
<p>==</p>
<p>I really don&#8217;t know if this is going to help solve anything for future problems.</p>
<p>And for the person who has hijacked your domain, I am sure that person will have to pay for what it has done.</p>
<p>Glad to hear that you got it back.</p>
<p>==</p>
<p>Cheers</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: alex</title>
		<link>http://www.davidairey.com/google-gmail-security-hijack/comment-page-13/#comment-142289</link>
		<dc:creator>alex</dc:creator>
		<pubDate>Fri, 14 Jan 2011 14:55:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.davidairey.co.uk/google-gmail-security-hijack/#comment-142289</guid>
		<description>@Manjunath, this post is over three years old.</description>
		<content:encoded><![CDATA[<p>@Manjunath, this post is over three years old.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
<!-- This Quick Cache file was built for (  www.davidairey.com/google-gmail-security-hijack/feed/ ) in 0.30728 seconds, on Feb 12th, 2012 at 4:31 am UTC. -->
<!-- This Quick Cache file will automatically expire ( and be re-built automatically ) on Feb 12th, 2012 at 5:31 am UTC -->
