Tuesday 27 March 2007

Google Account Security

I think that everyone who makes heavy use of Google services would agree that losing control of their Google account would constitute a serious breach of privacy. I came within a click of losing my account to an opportunist.

Recently another gmail user with a similar name attempted (and failed) to reset the password of my gmail account. He then attempted to add my email address as a secondary address for his account. At this point Google sent me an email in Dutch prompting me to click a link which would have given this other user complete access to my email and Google account. I don't speak Dutch so I used an online translator to check the message from Google. If I had been feeling tired or lazy, I might have clicked some of the links in the message to try and work out what it was about.

Surely, correspondence from Google to its users should be in the language of the account holder, not the language of the account hijacker!