Latest News

Showing posts with label Layered Security. Show all posts
Showing posts with label Layered Security. Show all posts

Adding Whitelist Entries, To Adblock Add-Ons

Ad blockers are popular Chrome add-ons, which let us manage various websites abilities to serve ads in our browsers.

Many ad blockers include a script blocker. Like NoScript in Firefox, ad blockers may interfere with various Blogger features - such as the "Don't track" script, in the dashboard.

If you publish a Blogger blog, and you have a problem with any pages in the Blogger dashboard, you will want to whitelist "blogger.com" in your ad blocker.

You will do better if you not whitelist "blogspot.com". BlogSpot includes many Blogger blogs - and third party code on those blogs. If you are not very picky about what Blogger blogs you view, you won't do well permitting scripts on every Blogger blog.

Adblock Plus is an extension, in Chrome.

I use "Adblock Plus" as an ad blocker, on my Chrome installations. "Adblock Plus" installs as an app, or an extension.


There are several ad blockers available, for Chrome.



I use the "Adblock Plus" extension, in my Chrome installations.


Start with "More tools" - Extensions.




Select "Options" for "Adblock Plus".




Adblock Plus "options" are also accessible from the browser toolbar. Right click on the ABP icon, and select "Options".




Select the "Whitelisted domains" tab.




Let's whitelist "addthis.com".




Paste / type "addthis.com" into the box. Hit "Add domain".




And now, "addhis.com" is whitelisted.



And having whitelisted "addthis.com", I can support a useful third party social sharing blog accessory, by permitting ads that they host.



Some #Blogger blog owners use ad blockers in their browsers - and see problems with using various Blogger features. The Stats "Don't track", for instance, is vulnerable to ad blockers, and similar filters.

Fortunately, it's not difficult to whitelist "blogger.com" in your adblocker.
target="_blank"

Microsoft Windows Security Updates, May 2016

If you use a computer that runs Microsoft Windows, you may have been affected by Microsoft supplied updates, distributed 3 weeks ago.

May 10 was the day termed "Patch Tuesday" - the day when Microsoft releases important security related patches, to its various Internet updated products. During the 3 weeks after May 10, we've seen a significant number of security related discussions, in Blogger Help Forum: Get Help with an Issue.

It appears that Microsoft updates, for May 2016, affect use of Blogger.

The Microsoft Security updates, applied May 2016, appear to have affected various Blogger features, that are known to be vulnerable to layered security.

  • CAPTCHA visibility when daily post limit is exceeded.
  • Publishing comments, or replying to published comments.
  • Quick Edit icons.
  • Followers / Reading List maintenance.
  • Stats self initiated pageviews.

All of these features are known to be affected by cookie filters, and / or by script filters.

If you are using a computer that runs either Microsoft Windows 7 or Windows 10, and you are experiencing a problem with publishing comments, or with using Quick Edit, or with blocking your own views in Stats, or similar problems, you may want to check your cookie and script filters.

I note that some of the reports mention the browser used as Chrome or Firefox. You'll want to check filter settings in Windows Security Essentials.

Being realistic, it's also possible that Microsoft broke something within Windows - but we'll have to wait patiently, for them to admit that.

If you need different or more advice, please start a new topic in Blogger Help Forum: Get Help with an Issue.



Microsoft released monthly security updates May 10, 2016 - and since that date, there have been a number of security filter related issues, reported in Blogger Help Forum. It appears that the the Microsoft Updates involve cookie or script filters, which affect use of Blogger.


Effectively Testing Reader Access To Your Blog

People reporting a problem with blog access / performance, in Blogger Help Forum: Get Help with an Issue, will be frequently advised to diagnose their problems using affinity / differential testing.

Some diagnostic advice starts with simple instructions to "clear cache, cookies, and sessions". Some people, alternately, advise "use a different browser" - and test as a reader. These different strategies, seemingly redundant, will frequently lead to different results.

When you test reader access to a blog, some experts will casually advise you to "use a different browser" or "use a second computer".

There are specific reasons why this strategy may or may not be successful, when part of affinity / differential testing. When you test blog access, you're going to see varying reliability - based on a number of browser and reader details.

There are multiple ways to test blog access, of owner vs readers.

Any experienced testing technician knows that the most reliable testing, in affinity / differential analysis, will use identical browsers, on identical and separate computers.

Very few blog owners will have use of a bank of identical computers, for testing. There are alternate possibilities, when identical computers can't be used.

  • This browser, in the primary session - after "clear cache, cookies, and sessions".
  • This browser, in a secondary session - aka "Incognito" / "Private" browsing.
  • A different browser, on the same computer.
  • The same branded browser, on a different computer.
  • Any browser, on a different computer.

All of these details will be relevant, sometimes - though not always. The differences between "always" and "sometimes" will lead to some testers using incomplete testing techniques - and cause inconsistent results.

This browser, in the primary session - after "clear cache, cookies, and sessions".

The best way to avoid environment based inaccuracy is to re use the environment, sequentially. This approach requires more time - plus development of a testing script, to keep testing procedures consistent.

It is, however, the best way to avoid confusion from inevitable testing variations.

Using the same browser, in the same browser session, one can try using a different identity. This technique starts with the apocryphal instructions to "clear cache, cookies, and sessions".

This browser, in a secondary session - aka "Incognito" / "Private" browsing.

Some browsers support multiple sessions. In Chrome, a secondary session is provided as "Incognito" mode - and in Firefox, a similar (not identical) option is called "Private" browsing. The differences between the "Incognito" and "Private" features are significant - and can cause different testing results.


This blog, displayed in "Incognito" mode.



A different browser, on the same computer.

Each different browser will have differences in the browser itself. Plus, different add-ons and settings, on the different browsers, will produce differing results.

Having both browsers on the same computer will eliminate computer setup differences, present when multiple computers are involved.

The same branded browser, on a different computer.

If the branded browser, on the two computers, is maintained identically, there is a chance for consistent results. Having two different computers involved, however, may offset the consistency gained by using identical browsers.

Any browser, on a different computer.

This is the most inaccurate testing procedure, of the choices listed. Any difference between the browsers, or computers, can lead to inaccuracy.

The differences, in testing, involve multiple details.

  • Login identity in use.
  • Cookie filters, that block identity.
  • Script filters, that block identity access.
  • Browser add-ons, that may or may not be present.
  • Browser brand and design differences.

Login identity in use.

This is the one difference that you intentionally need, to test the reader experience. In the primary session, you are logged in as the owner. You require at least one secondary session - where you are not logged in as the owner, to test your blog as a reader.

The secondary session is where the need for sequential session reuse - or use of a different browser and / or computer - becomes necessary.

Cookie filters, that block identity.

Many Blogger features - involving both the dashboard, and access to the blog - use cookies to determine identity and permissions. Cookie filters, inappropriately managed, can cause havoc with Blogger. As an example, consider commenting ability, and third party cookies.

Different browsers may have different cookie filter settings. In some cases, identity is not relevant, for testing as a reader.

If you are testing access to a private blog, though, reader identity - which is cookie based - will be essential. A cookie filter involved, with a private blog being tested, will cause problems.

Similarly, testing Google+ comments requires known identity - for both the blog owner and readers. With Google+, identity is essential, to guarantee consistent display of comments.

Script filters, that block identity access.

Many Blogger features - involving both the dashboard, and content in the blog - are JavaScript based. Script filters can cause havoc with Blogger.

Different browsers may have different script filter settings - and different browser brands may have completely different script filters.

Browser add-ons, that may or may not be present.

The Firefox browser does not have native script filters, so many computer owners who use Firefox will add NoScript.

NoScript is a very intense add-on, with a lot of options, and opportunities for confusion. If you were to use Firefox on two different computers, you would need to carefully synchronise NoScript settings on both computers, for reliable testing.

Firefox with NoScript is the best known example - but it's not the only possibility for confusion. Every browser can have script filters, which will make browser to browser testing comparison a challenge.

With Chrome, one can select each individual add-on to be present in the secondary session ("Allow in incognito") - and this will create uncertainty. Some advice to "try using a Chrome incognito window" will be successful, with other advice being useless - and the absence or presence of the necessary add-on will be one of the issues.


AdBlock, optionally included in incognito mode, will produce uncertainty in testing - and is a well known script block.



Browser brand and design differences.

Every different browser produces differences in displayed content. Even a formatting discrepancy can lead to difference in test results.

The end results.

Interpreting test results, based on comparison of different browser displays, will be a challenge for anybody trying to produce reliable conclusions. The most reliable results will come from testing using the same browser session, sequentially. This will start with instructions to "clear cache, cookies, and sessions" - a painful but necessary process.



Many #Blogger problems need to be diagnosed using repetitive testing, and affinity / differential analysis. People who don't understand organised testing will sometimes recommend testing procedures, such as use of different browser sessions - which will produce inconclusive results.

Blogger Magic - Enabling Exceptions, In Chrome

Some blog owners and readers prefer to ignore recommendations in Chrome - and block cookies and / or scripts.

Blocking cookies can cause problems with many Blogger features - and blocking scripts will cause problems with both Blogger and with Google, and with various other websites.

If you want to use Blogger and Google effectively, you need to allow cookies to be installed, and to allow scripts to be run, on your computer.

If you cannot allow cookies and scripts for all websites, you can allow cookies and / or scripts on specific websites.

With Chrome, if you are willing to selectively allow specific websites to install cookies / run scripts, you should enable exceptions for those websites.

Start with the "Content settings" wizard.


Select "Block third-party cookies and site data", and / or "Do not allow any site to run JavaScript".



Add cookie exceptions, for specific websites.


Click on "Manage exceptions" under Cookies, to get the "Cookie and site data exceptions" wizard.




To add "google.com" as a cookie exception, paste / type "[*.]google.com", and select "Allow".




Click anywhere in the wizard window, to see the addition - then click "Done".



Add JavaScript exceptions, for specific websites.


Click on "Manage exceptions" under JavaScript, to get the "JavaScript exceptions" wizard.




To add "google.com" as a JavaScript exception, paste / type "[*.]google.com", and select "Allow".




Click anywhere in the wizard window, to see the addition - then click "Done".



Remember that cookie and script filter settings, in Chrome, may not be the only settings which you need to consider - and that many filters are subject to change, without your knowledge or approval.

For more detail about cookie and JavaScript exceptions, see Chrome Help: Manage exceptions. These are settings that you must determine and install - neither Blogger nor Google can make these changes for you.



Security conscious #Blogger blog owners may wish to ignore #Chrome recommendations, and block general permission for websites to install cookies and / or run scripts on their computers.

Some websites will not run properly, without cookies and scripts. If one is to use websites like Blogger and Google successfully, they need to be trusted - and Chrome must allow those websites to install cookies / run scripts.

Blogger Magic - Enabling Scripts, In Your Browser

Similar to the need to properly filter cookies in the browser, we have the need to properly filter scripts.

Cookies and scripts are completely different elements - but proper filtering of each is essential, to making many Blogger features operate properly.

If you have a problem with Blogger - either accessing / using the dashboard, or using / viewing a blog - one of the simplest things to check, complementing cookie filter settings, is the browser script filter settings.

The browser is the most important component, when setting up security - and scripts, like cookies, are a common challenge.

Script filters are adjusted differently, for each browser. Consider the multiple domains used by Blogger / Google - and layered security, on any computer, used by the owner and readers of any blog.

  • Chrome.
  • Firefox.
  • Edge / Internet Explorer.
  • Opera.
  • Safari.

Setting the script filters in Chrome.

With Chrome, you enable scripts, using Settings ("Customize and control Google Chrome") - aka the 3 bar toolbar icon.

In Settings, if necessary, click on "Show advanced settings" at the very bottom of the page.

Under Privacy, click on "Content settings", which gives you the "Content Settings" wizard. Here, you have selections for Cookies and Javascript - including "Manage exceptions" for each section. Select the recommendation.

  • JavaScript: Allow all sites to run JavaScript

Hit "Done" - and close the Settings tab.


From "Privacy", hit "Content settings".




Under "JavaScript", select "Allow all sites to run JavaScript (recommended)".



Alternately, you may select "Do not allow any site to run JavaScript" - then use "Manage exceptions", and allow all blog(s) that you publish, and the many Blogger and Google domains, to run JavaScript. Make your exceptions complete, for best results.

Setting the script filters in Firefox.

Firefox does not contain any native script filters. The most popular add-on for Firefox is NoScript - and this is how most Firefox users filter scripts.

You'll need to designate "blogger.com", "google.com", and any Google domain excepting "blogspot.com", as trusted - when you load any display for the domain in question. An untrusted domain will show a "NoScript Untrusted" icon in the status area at the bottom of the window. To enable each domain, you position the cursor over the NoScript icon and select "Allow (domain URL)" in the popup menu.

Setting the script filters in Edge / Internet Explorer.

With Internet Explorer, you enable security settings - both cookies and scripts - from the browser menu, using Tools - Internet Options. Optionally, you may access the "Internet Options" applet directly from the Windows Control Panel.

  • IE uses a zone defense setting, where you designate "blogger.com" and "google.com", in Security, as being in the Trusted zone. Please note that "blogspot.com", in general should not be in the Trusted zone - .
  • You will want the published URL of your blog(s) - including any country local domain URLs, in the Trusted zone.
  • Default settings for the Trusted zone will allow proper filtering of scripts.
  • Verify proper settings, with "Trusted sites" selected, and the Security level slider control set to "Medium". Hit "Custom level", and examine the Settings list.
  • Look for the "Scripting" section, 3/4 of the way to the bottom of the list.
  • You will observe 6 options under "Scripting". Default settings will have all options Enabled, except "Allow Programmatic clipboard access"; you may wish to Enable this to allow easy use of Post Editor.
  • Hit "OK", and "Yes" if necessary, then "OK" again.

Setting the script filters in Opera.

With Opera, you enable cookies and scripts from the Advanced tab, in the Preferences wizard. The Content menu contains selections for scripting.

Setting the script filters in Safari.

With Safari, you enable scripts, using the Preferences wizard. The Privacy wizard, in Preferences, contains selections for scripts ("Cookies and website data”).

Script filters cause problems with Stats "Don't track ..." and other Blogger features.

Many problems, reported in Blogger Help Forum: Get Help with an Issue, with various Blogger features - and the Blogger dashboard - involve script filters.

Stats and the "Don't track ..." option used to involve third party cookies, for many years. In March 2016, the "Don't track" wizard was rewritten to run under the URL of the blog, when being set - and now requires enabling scripts from the blog URL.

Consider how your blog is published.

If your blog is published to "blogspot.com", consider the non "blogspot.com" alias that may be relevant to your country. If your blog is published to a custom domain, consider the custom domain URL.

Many computers have other relevant settings, which block scripts.

Many blog owners and readers will have computers, and networks, with additional protection. Scripts, in the browser, may not be the only filter that needs to be checked - but this is a start, to learning how to control the script filters.

Having checked and corrected your script filters, continue by checking browser cookie filters - then check cookie and script filters, outside the browser. Also check settings on any ad blocker add-on - which may be an app, or a browser extension.

Be aware that many settings may not be obvious - and that both obvious and obscure settings may be updated, without your intention or knowledge.



Many #Blogger problems are cause by overly restrictive script filters. If you, a blog owner or reader, are going to use Blogger successfully, you need to configure your browser properly - for both cookies and scripts.

Blogger Magic - Enabling Cookies, In Your Browser

The Blogger dashboard, and blog displays, is less of a pair of websites - and more of an application with code that runs on our computers.

The Blogger code on our computers requires cookies and scripts, which are installed as we use the various Blogger dashboard pages. The cookies and scripts are susceptible to interference, from overly restrictive layered security.

If you have a problem with Blogger - either accessing / using the dashboard, or using / viewing a blog - one of the simplest things to check, complementing script filter settings, is the browser cookie filter settings.

The browser is the most important component, when setting up security - and cookies are a common challenge.

Cookie filters are adjusted differently, for each browser. Consider the multiple domains used by Blogger / Google - and layered security, on any computer, used by the owner and readers of any blog.

  • Chrome.
  • Firefox.
  • Edge / Internet Explorer.
  • Opera.
  • Safari.

Setting the cookie filters in Chrome.

With Chrome, you enable cookies, using Settings ("Customize and control Google Chrome") - aka the 3 bar toolbar icon.

In Settings, if necessary, click on "Show advanced settings" at the very bottom of the page. Under Privacy, click on "Content settings", which gives you the "Content Settings" wizard.

Here, you have selections for Cookies and Javascript - including "Manage exceptions" for each section. Select the recommendation.

  • Cookies: Allow local data to be set

Hit "Done" - and close the Settings tab.


From "Privacy", hit "Content settings".




Under "Cookies", select "Allow local data to be set".



If you want to enable cookies selectively, select "Block third-party cookies and site data". Then use "Manage exceptions", and add "blogger.com", "google.com", and any addresses which apply to your blog.

Setting the cookie filters in Firefox.

With Firefox, you enable cookies, from the browser menu - aka the 3 bar toolbar icon, using Preferences - Privacy.

  • Under History, select that "Firefox will:" is set to "Remember history" then "Use custom settings for history". That will give you an array of settings.
  • Check "Accept cookies from sites".
  • Close Preferences. Settings will be saved.
  • Note that any Firefox add-ons which filter cookies, and offer more detailed options, will have to be dealt with, separately.


Select "Remember history", then "Use custom settings for history".




Check "Accept cookies from sites".



If you want to enable cookies selectively, change "Always" to "Never". Then use "Exceptions", and add "blogger.com", "google.com", and any addresses which apply to your blog.

Setting the cookie filters in Edge / Internet Explorer.

With Edge / Internet Explorer, you enable cookies, using the browser menu, selecting Tools - Internet Options. Optionally, you may access the "Internet Options" applet directly from the Windows Control Panel.

  • Edge / IE uses a zone defense setting, where you designate "blogger.com" and "google.com", in Security, as being in the Trusted zone. Please note that "blogspot.com" should not be in the Trusted zone.
  • Default settings for the Trusted zone will allow proper filtering of scripts.
  • Verify proper settings, with "Trusted sites" selected, and the Security level slider control set to "Medium". Hit "Custom level", and examine the Settings list.
  • You enable Cookies under the "Privacy" tab.
  • Move the Privacy slider to the bottom, to allow all cookies.
  • Click "OK".

Setting the cookie filters in Opera.

With Opera, you enable cookies, using the Advanced tab, in the Preferences wizard. Select "Accept", to accept cookies from all sites.

Setting the cookie filters in Safari.

With Safari, you enable cookies, using the Preferences wizard. The Privacy wizard, in Preferences, contains selections for cookies ("Cookies and website data”). Select "Always allow", to enable third party cookie access.

Cookie filters cause half of the problems reported, with many Blogger features.

Maybe 50% of the problems, reported in Blogger Help Forum: Get Help with an Issue, with many Blogger features involve cookie filters.

  • Comments.
  • The Cookie Advice Banner.
  • Post/Page/Template Preview.
  • Reading List.
  • Template Designer.

Stats and the "Don't track ..." option used to involve third party cookies, for many years. In March 2016, "Don't track" was rewritten to run under the URL of the blog, when being set - and now requires enabling scripts from the blog URL.

Consider how your blog is published.

If your blog is published to "blogspot.com", consider the non "blogspot.com" alias that may be relevant to your country. If your blog is published to a custom domain, consider the custom domain URL.

Many computers have other relevant settings, which block cookies.

Many blog owners and readers will have computers, and networks, with additional protection. Cookies, in the browser, may not be the only filter that needs to be checked - but this is a start, to learning how to control the cookie filters.

Having checked and corrected your cookie filters, continue by checking browser script filters - then check cookie and script filters, outside the browser. Be aware that many settings may not be obvious - and that both obvious and obscure settings may be updated, without your intention or knowledge.

Learn more.




Many #Blogger problems are cause by overly restrictive cookie filters. If you, a blog owner or reader, are going to use Blogger successfully, you need to configure your browser properly.

Stats "Don't Track" - You Cannot Satisfy Everybody

Blogger recently redesigned the Stats "Don't track ..." option - and removed third party cookies from the picture.

The "Don't track ..." wizard is now accessed from the blog URL. The wizard still produces cookies - but they are ordinary first party cookies, which are much less feared than third party cookies.

But, every silver lining has a cloud.

In making the "Don't track" wizard accessed under the blog URL, Blogger created a new requirement - which is no more understood, by some blog owners, than "third party" cookies.

"Don't track" now runs scripts from the blog URL, instead of the Blogger dashboard.

In order for a blog to observe - and preserve - the "Don't track" setting, any computer that the owner uses has to permit first party cookies - and all scripts - from the blog, instead of from the Blogger dashboard.

Since "Don't track" is designed to be used by the blog owner, this new requirement should not be a problem. Every blog owner should be able to trust herself / himself, to not add dodgy code to his / her own blog.

Many security products block scripts from personally owned blogs.

Unfortunately, general security practice is to block scripts from "blogspot.com", "blogspot.xx" (for every "xx" for every country local domain"), and preferably for blogs published to custom domains.

You can trust scripts from "blogger.com", and the Blogger dashboard. You cannot trust the individual blogs, since you cannot trust every blog owner. Even if you could trust some people not to intentionally try to hack your computer, you cannot trust everybody to not stupidly install malicious software from a very convincing hacker, providing one more "gotta have this" blog accessory.

And since you cannot trust the individual blogs, you will have filters. And those filters have to be adjusted, to trust your own blogs - if you want to ignore your own pageviews.

Some blog owners add security software, and don't know how to maintain the filters.

There are too many Blogger blog owners who have installed protective software on their personal computers - without knowing how to adjust the filters, in the protective software. And some of those owners think that it is a Blogger responsibility, to provide them instructions, how to adjust the protective software on their own computers - when only they are capable of knowing what they installed.



The new version of the Stats "Don't track" option is an improvement, because it no longer requires third party cookies - and involves the associated security risk. Unfortunately, it now requires blog owners to permit scripts, from the blogs themselves.

This is not a security risk, in that only personally owned blogs need to be trusted - but the blog owners do need to know how to adjust the filters involved. And not everybody with a computer knows how to configure their security accessories.

The New Stats "Don't track" Option, And Script Filters

The new Stats "Don't track" option is an improvement, to many blog owners.

"Manage tracking your own pageviews", as before, starts from the Stats dashboard page. The wizard now runs from a sub directory of the blog managed by the dashboard - and uses a normal (first party) cookie.

Now, blog owners no longer must enable third party cookies, to make Stats ignore their page views. This is an improvement - but it can still present a challenge, for some blog owners.

Besides filtering "third party" cookies, not all blog owners and readers will permit complete control by content under the individual blogs.

If you want "Don't track" to work reliably, enable scripts for the blog URL.

If you want the "Don't track" option to work reliably for your blog, you now must enable scripts to run under the published URL.

We have to trust scripts run from "blogger.com" - that is the Blogger dashboard. The Blogger dashboard is produced by Blogger Engineers - and if we trust Blogger to host our blogs, we have to trust their code.

Scripts which run under the individual blogs - "blogspot.com", local country domains, and custom domains - can be added by the owner of each individual blog. Not all blog owners should be trusted.

People who mistrust third party cookies may also mistrust scripts which run under "blogspot" etc. Unfortunately, to make "Manage tracking your own pageviews" work, you (the blog owner) now have to open up any script filters, which block content run as part of your blog.

Start from the Stats dashboard page.

Click on "Manage tracking your own pageviews".



"Manage tracking your own pageviews" now runs under the blog published URL. This removes "third party" cookies from the problem.

With a custom domain published blog, you must use the wizard in "HTTP:" mode.

By default, the new wizard runs in SSL mode. This will be a problem, with blogs published to custom domains.


If the blog is published to a custom domain, you will need to change "https" to "http".




Check "Don't track my views for this blog." - then close the tab / window.



The new wizard, "Would you like to have your pageviews counted when you visit this blog?", now runs as "blogging.nitecruzr.net", for this blog.

http://blogging.nitecruzr.net/b/statsCookieManage

If you publish to a custom domain, and you can correct the URL, you will see the same, for your blog. If you publish to "blogspot", you can see the same also. This is a script - and is subject to security filters.

And yes, there is no "Save" button, or link. Just the box.

Don't track my views for this blog.

Click the box or don't. As soon as you click, it's set.

You should trust your blog - even though you do not trust other blogs, in general.

Generally, as the blog owner, you can safely trust content run under your blog. You probably should not trust "blogspot.com", and all blog publishers, however. This means that you will require multiple filter rules - for every browser and security add-on, that contains a script filter.

  • Block all "blogspot.*". (Please!).
  • Permit "yourblog.blogspot.com".

If you publish to "blogspot.com", and live in a country which has a local domain, such as the UK, you need a rule to permit the local domain alias.

  • Permit "yourblog.blogspot.co.uk".

If you have multiple blogs - and want to block pageviews from being counted, for each blog, you need permissive filter rules for each blog.

  • Permit "yourblog1.blogspot.*".
  • Permit "yourblog2.blogspot.*".
  • etc.

If you publish your blog to a custom domain, you need a rule to permit the domain URL. For this blog, I need

  • Permit "blogging.nitecruzr.net".

If you do not permit the proper URL(s) for your blog, you will find Stats counting your own pageviews. Possibly, this will happen even with "Don't track my views for this blog." checked. In some cases, the check mark will be cleared, when you close the window.




Owners of #Blogger blogs who don't want their activity tracked by Stats now see a new "Don't track" wizard. Using the "Don't track" option no longer requires enabling third party cookies - and worrying about the security issues.

Unfortunately, this now means that the "Don't track" wizard may now be vulnerable to filters which restrict scripts that run under blogspot, and any custom domains.

What Are The Mysterious Turning Gears?

This is a question, occasionally seen in Blogger Help Forum: Something Is Broken.
I cannot view some blogs - all that I see are gears, turning endlessly. What is going on, here?

The gears are animation, displayed by Blogger, while a dynamic template and blog content loads on the computer being used. Generally, the gears will play for a few seconds, then the blog will be seen. For an example, check out my Musings blog.

Sometimes, all that you will see are the gears, endlessly turning - waiting for the templates and blog content to download.

The dynamic templates, used by some Blogger blogs, represent an innovative approach to providing web content.

Normal web content, provided in Blogger blogs which use Classic, Designer, and Layout class templates, consists of comments, gadgets, posts, and templates, arranged together in pages (dynamic and static).

Blogs which use Classic (HTML only) templates arranges everything when the blog is maintained. Blogs which use Designer / Layout templates (HTML / XML) arrange the content when the blog is maintained - then build the individual pages when the blog is read by each viewer, dynamically. For all 3 classes of templates, the content is served from Blogger / Google servers, in individual display pages.

The Dynamic class of Blogger templates take the concept of dynamic publishing to another level. Dynamic class templates load a significant amount of script code (the template) directly to each client computer. Instead of reading the pages of blog content from a Blogger / Google blog server, a dynamic template script, running on the client computer, reads the published blog feeds from a newsfeed server - then turns the feed content into a display.

A Dynamic template is a specialised Newsfeed Reader, similar to the dashboard Reading List, or to Google Reader.

By offloading a large amount of the publishing process to the client computer, and by using the blog comments and posts feeds, Blogger provides blogs which can be viewed in a number of different ways - selectable by each individual viewer, and at the convenience of the viewer. This selectability is not without cost, unfortunately.
  • The templates require a significant amount of script code.
  • The templates require the blog comments and posts newsfeeds.

For most blogs using a dynamic template, and being viewed on most computers, the "turning gears" icon plays briefly, while the template code, and the blog comments and posts newsfeeds, are downloaded. As soon as downloaded, the content is assembled into a display, and the viewer can view the blog. This does not happen, in all cases.
If the client computer has a slow Internet connection, the viewer may watch the turning gears for more than a few seconds. If the computer filters scripts aggressively, or if the blog does not publish a full newsfeed, the gears play, endlessly, while the computer waits for the scripts and newsfeeds to finish downloading. In the latter case, the viewer can only find another blog to view.

If you encounter one or two Blogger blogs playing the turning gears, endlessly, then you are experiencing the reality of dynamic templates - some blog owners do not realise that they have broken their blogs. If you encounter a large number of Blogger blogs doing this, then you might want to check the filters, on your computer - including, but not only, the browser cookie and script filters.

>> Top

We Are At The Mercy Of Every Anti-Malware Protection Program Imaginable

We see reports, from time to time, in Blogger Help Forum: Something Is Broken, about blogs which people can't read, from their computers.
One of my readers claims that I have a virus on my blog. He provided the following information:
AVG anti-virus detected the following threat on the site:
File Name: www.mydomain.com/favicon.ico

Threatname: Exploit Black Hole Exploit Kit
How do I fix this?

Similar to the many reports that we process here, about spurious spam classification, the above report is frequently determined to be a false positive. An anti-virus alert, even if a false positive, is generally not as simple to resolve as a spurious Blogger spam classification, though.

One of the frustrating problems with false malware alerts is that they come from so many different anti-malware products.

I've contributed my opinion about computers, and the suggestion that no two privately owned computers are identical, many times. One way which many computers vary is the complement of security software, which is chosen by each different computer owner.

At any time, any different anti-malware product may decide that some component of your blog is unsafe.
  • Maybe, a single file mentioned in your blog code (as above, "favicon.ico") is suspect.
  • Maybe, content hosted by "blogspot.com" is unsafe.
  • The code may be an accessory that we added, intentionally.
  • The code may be content in another blog - hosted by your blog in a bloglist, a linklist, or maybe in the Reading List on your dashboard.
In either case, you (or your reader) won't be allowed to view the blog - or may be allowed to view the blog, but given a stern warning which very few chose to accept.

Like many problems with layered security, any malware detection can come from
  • A native browser filter.
  • A filter in a browser add-on.
  • A filter installed on the computer.
  • A filter in a network appliance.

Listen to your computer. some time. Your anti-virus protection may update, automatically - and may audibly announce the update. On a typical day, I hear the Avast client on my several computers announce an update, several times - and I am not (contrary to some misconceptions) seated in front of my computer on a 24 x 7 basis.

Avast (my personally and professionally recommended choice, to many people) is only one of dozens of various anti-malware products which receives automatic updates, when the host computer is online. Any one of these products may be updated, at any time -and somebody's access to your blog (or my blog) becomes blocked.

If you get a message from one of your would be readers
I can't view your blog!
this could be someone reporting that your blog just went offline, for one reason or another - or it can be someone just discovering that the anti-malware program, on his computer, has decided that BlogSpot hosted content, or Blogger code in general, is unsafe. In either case, there is not a lot that you can do, except wait it out - and concentrate on the readers who can access your blog.

>> Top

Would Be Blog Owners Report Inability To Create A Blog

We are currently seeing frustration, in Blogger Help Forum: Something Is Broken, about new blog creation.

Would be new blog owners have various concerns
I can't create a blog - the "Create" button is grey (inoperative)!
or
It keeps saying
Verifying availability
when I enter a blog name!!
or even
It said
This blog address is available.
until I hit "Create blog!" - then it changed to
Sorry, this blog address is not available.

Each of these problem reports - and others - may come from people who don't read the instructions, for using the wizard. Alternately, some folks may be complaining about yet one more case of over done layered security.

The most obvious problems, in the blog creation process, come from people who don't understand how to use the "Create a blog" wizard.

Not every would be blog owner understands that 3 things must be done, to make the "Create blog!" button operative - and all 4 must be done, before the blog is actually created.
  1. Enter a Title for the blog.
  2. Enter an acceptable and available Name for the blog.
  3. Select a Template for the blog.
  4. Hit "Create blog!", with "This blog address is available." displayed.

When you choose a Name (aka "address" or "URL"), enter your choice properly.
  • Only enter the "xxxxxxx" part of "xxxxxxx.blogspot.com".
  • Only use lower case alphabetic characters ("a" - "z"), numeric characters ("0" - "9"), and dashes ("-").
  • Do not use a trailing dash (You cannot publish "xxxxxxx- . blogspot . com").

Besides the syntax issues when entering a blog name (URL), there is the unfortunate issue of competition in the creation process. Blog owners who are anxiously creating a new blog, based upon a current event - maybe a popular movie star, or an important political campaign - will be dismayed to see
Sorry, this blog address is not available.

If you are competing in real time, with other would be blog owners, for the name of your choice - and you take too long between Steps #1 - #3, and Step #4 - you may still see
Sorry, this blog address is not available.

Many people want to setup a blog, based on that blog name. Some may see the bad news, repeatedly, leading to one frequently seen complaint.
All the good addresses are taken!
And sometimes, to a more imaginative suggestion.
How do I get Blogger to re issue me the dormant address?
The latter question is one of futility.

Finally, the anxious blog owner may see
Checking address availability
for some time - possibly forever - if an overly ambitious cookie / script filter, or an intrusive security add-on is installed in the browser. In this case, the magical advice to
Clear cache and cookies!
or
Try a different browser!!
will be effective - though absent any attempt to diagnose the problem, one may not ever know what actual underlying problem may have caused the plaintive cry
I can't create my blog!

Some Blog Owners Reporting The Template Designer Changes Do Not Update On Their Blogs

For several weeks, we're been seeing various reports in Blogger Help Forum: Something Is Broken, mentioning problems with template updates, being made using the Template Designer wizard.

The reports are not so widespread to indicate a complete malfunction - but neither can we dismiss the problem, as being unique to one browser, one template type, or one particular update pattern.

It's likely that we are looking at a number of problems, aggregated and compounded, into one common symptom.
I cannot Save changes in Template Designer.
With a problem report like this, some examining of the details may be appropriate.

The Template Designer wizard, which is a component in the Blogger Dashboard, is a complex and sophisticated collection of menus and utilities, which runs on the blog owners computers.

Like most Blogger code, the Template Designer is subject to the effects of other programs, and various security settings - which may be installed or set on each individual computer, with or without the understanding of the blog owner and / or computer owner. In some cases, the blog owner and computer owner may be different people.

If you are seeing a problem with the Template Designer, when trying to update the layout on your blog, there are several tests which you can make, which may help to isolate the problem.
  • Try making the same updates, using another computer.
  • Try making the same updates, using another browser on your current computer.
  • Try setting up a new blog, with the same template, and make the same updates to the new blog.
If you're able to make one or more of the above alternate updates, that will help to eliminate some, or many, alternate suspects, as the cause of your problem. If other people are reporting this problem, their results from the above tests may or may not correspond with yours - because their base problem may differ from yours.

Right now, we're seeing seven different causes of these problems.
  1. Changes made by Blogger Engineering, to support new browser versions and browser updates, and to provide new template features.
  2. Changes inherent in new browser versions, made by the browser vendors.
  3. Third party browser add-ons, installed by the owners of the various computers.
  4. Security settings, inherent in new browser versions and third party add-ons.
  5. The cumulative effects of various template tweaks, both made using "Edit HTML" and the Template Designer itself.
  6. Unrealistic expectations of blog owners, about effects of Template Designer settings, against all templates provided by Blogger.
  7. Unrealistic expectations of blog owners, about effects of Template Designer settings, against templates not provided by Blogger.
Of these possible causes, only #1 (and possibly #2 and #6) are the sole responsibility of Blogger Engineering. The blog owners (and computer owners) must assume some partial responsibility for #2 - and sole responsibility for #3, #4, and #5. The blog owner, and the developer of any custom, third party template, must jointly assume responsibility for #7.

Recently, Blogger Support acknowledged the problem, in part.
Some users have reported that the Apply to Blog button in the Template Designer is non-functional for some Dynamic View templates.
We also have a Rollup Discussion, in Blogger Help Forum: Something Is Broken, where individual details are being provided by various blog owners.

Right now, we're starting to suspect that some "problems" are actually caused by the blog owners, who are simply not aware that not all changes made, using the Template Designer (or the Layout or Template "Edit HTML" wizards), are designed to update all templates used in viewing our blogs.

Stats And The "Don't track your own pageviews" Option On Mobile Computers

As mobile computing becomes more popular, we're starting to see questions about use of the Blogger dashboard on mobile computers (iPhone / iPod, PDA, smart phone), in Blogger Help Forum: Something Is Broken. Most recently, we're seeing people trying to use Stats, and the "Don't track my own pageviews" option, with Blogger on mobile computers.

Problems with Stats and the "Don't track ..." option are not unknown, in the past. We've helped many blog owners with this setting, which is sensitive to cookie and script filtering in general - and to "third party cookies" in particular. "Third party cookies" may be filtered in any of several places, any which will interfere with "Don't track ...".

The "Don't track ..." option, when seen as a problem with "full size" computers (desktop, laptop / notebook), may involve any of various "layered security" settings. In general "full size" computers use a somewhat standard software infrastructure. While any of several operating systems (Apple / Macintosh, Chrome, Linux, Microsoft Windows), and various browsers (Chrome, Firefox, Internet Explorer, Opera, Safari) make use of Blogger an occasional challenge on "full size" computers, there is some common features between the various operating systems and browsers.

With the various "operating systems" and browsers on mobile computers, we're seeing more discrepancies in features offered. In particular, not all "mobile computers" have explicit settings to allow / disallow "third party cookies" - or even cookies and scripts, in general. If these settings are not present, it's likely that these computers do not support such details as "third party cookies".

Without the availability of "third party cookies", Blogger can't support the "Don't track ..." option. Here, I'll note that this option is specific to each individual browser, on each individual computer. One must set the option - and browse the specific Blogger blog - using the same browser, for the option to work. This is not an option that can be set on a per user basis, and apply to all browsers used by a specific user.

>> Top

Use A Well Protected Browser, To Block Redirecting From Misbehaving Code And Gadgets

Regularly, in Blogger Help Forum: Something Is Broken, we advise people about problem code or gadgets in their blogs.

Generally, this follows reports by blog owners, that their readers are being redirected to unexpected and unwanted blogs and websites, from their blogs. Sometimes, we get the reply
I can't remove the code. Every time I login to Blogger, I am redirected, just as my readers are being treated!

When we see the latter complaint, we recognise yet one more blog owner who does not know how to properly protect himself, from malicious code and websites. Most people, who know about Layered Security, know that proper browser security is an essential complement to a properly chosen and maintained anti malware filter.

Many people, who care about browser based security, use Firefox with NoScript.

This combination provides Unix level security, "deny by default, permit by exception". Simply install NoScript as an add-on, to Firefox, to get started. Alternately, you may use Chrome with ScriptSafe, or Opera with NotScripts.

When using your browser with a script filter, there will be specific Blogger / Google websites which you should trust, and others which you should not trust.

Every time you surf to a different website - and decide that the owners of the website, which you are now viewing, have your best interests in mind - configure NoScript to allow that website, to display properly on your computer. When you find that a trusted host website does not display properly, examine the NoScript taskbar and the list of websites used by the host website. Look at the NoScript Options menu, carefully. Allow specific websites which you trust, and Forbid all other websites which you do not trust.

Deciding which websites to trust, based on their presence in the NoScript Options menu, will be a learning experience for a while. For some host website pages, which use a large number of unfamiliar websites, you may have to carefully select to "Temporarily allow all this page" - or you can "Temporarily allow" each single website, one by one, until the host website page displays properly.

When you decide to (permanently) "Allow" any website, that website will be "Allowed" on all other host websites where you may surf. Conversely, any website which you never select to "Allow" - such as the problem website which is providing the misbehaving code - will never execute on your computer again. This will prevent redirection on your computer, allow you to safely use the Blogger dashboard, and edit or remove any dodgy code which may be part of your blog.

After removing any dodgy code from your blog, always clear cache and restart Firefox, to test the effects of your editing.

>> Top

Blogger Blogs Lack The Navbar, Though Not Removed By The Owner

Recently, a few Blogger blog owners are looking at their blogs and wondering
Where is my Navbar?
or
Why don't I have a "Sign In" ("Sign Out") link, at the top of the page?


When investigating further, they may discover that none of the blogs, that they view, shows the Navbar. And, they did not intentionally make any template changes, to their blog, to hide the navbar.

Many of these people, later investigating the problem in Blogger Help, learn that their browser, or another anti malware product, is blocking the navbar as suspicious code. This is another example of improperly configured layered security, planned to protect our computers.

If you are observing the lack of the navbar on your computer, and you request help in Blogger Help, please help us to help you better, and provide details.
  • What browser (name and version - and precision matters) are you using?
  • What add-ons are installed, in the browser (completeness matters)?
  • What anti malware product(s) do you use, on your computer (again, completeness matters)?
If we can get an idea of what components are involved in this problem, maybe we can isolate the problem, itself. Please, be complete - and be precise.

>> Top

Contact Us

24x7 online , we happy to answer you
tamilcypc@gmail.com

Disclaimer

This Blog and its TUT's are intended for educational purposes only, no-one involved in the creation of this TuT may be held responsible for any illegal acts brought about by this Blog or TuT.



Featured Post

Custom Domains And HTTPS Redirection Code