Google Account Security Issue?

I had an odd thing happen to me the other day. I was using my Google account in Firefox. I have multiple Google accounts - one for personal, one for business. I had first been logged into my business account, then logged out and logged in to my personal account. All was well, except when I clicked on a report in my Analytics list, I was taken to the ‘Analytics’ tab in my business account. So, I was able to see site reports for the account that I was no longer logged into.  I took some screenshots, because it was odd, and e-mailed Google to let them know they may have a security issue. This happened back on January 29th, and after giving Google ample time to reply / fix the issue, I’m now posting it.

Take a look at these screen shots - you can click on them to view the full-size screen shot.

On the screen shot below, note the two site names listed in the report listing.

Now, on this next screenshot, take a look at the name of the site that I am viewing report data for. It’s not one of the two reports listed.

I’m a huge fan of Google - I think they do a great job and provide great tools. However, their customer support completely failed to understand what was going on here, even with screen shots.
Below is the e-mail correspondence with Google. The original message from me was submitted through their support form.

From: xxx@creativeanvil.com

Subject: Security Issue with Adwords / Analytics

Date: Tue, 29 Jan 2008 15:24:01 -0800

I have two different google accounts - one for work and one for 

personal. When logged into my personal account, clicking on Analytics 

took me to the right spot, but clicking on a report took me to my work 

account — actually, into my work AdWords account, with the Analytics 

tab selected. I have used the same browser for both, but I specifically 

logged out of the work account, then logged into the personal account. 

I know it was logged in properly because I saw the right content in my 

google home page, my webmaster tools, but not my analytics. I have 

screen shots that I can e-mail of the different screens and what I got 

when I clicked different links. I’d be glad to send them so that you 

can verify this.

AdsUserLocale: en_US

Language: en

Name: Joe Koenig

Source: cuf

topic: Other

———- NEXT MESSAGE ———

Hello Joe,

Thank you for your email. I understand you are concerned as while you

try

to view the reports in one account, you are able to access the reports

of

some other account. To help us troubleshoot further it would be

advisable

if you could send a direct response to this email with the relevant

screenshots and the login email addresses you are trying to access your

account with. It would be better if you could include your work login

email address and your personal login email address. 

If you have additional questions, please visit our Help Center at

https://adwords.google.com/support to find answers to many frequently

asked questions. Or, try our Learning Center at

http://www.google.com/adwords/learningcenter/ for self-paced lessons

that

cover the scope of AdWords.

We look forward to providing you with the most effective advertising

available. 

Sincerely,

Suchi Kumar

The Google AdWords Team

—————-

To access your AdWords account, please log in at:

https://adwords.google.com

——- NEXT MESSAGE ——–

From: Joseph Koenig

Subject: Re: [#237202376] Security Issue with Adwords / Analytics

Date: Wed, 30 Jan 2008 08:49:11 -0600

Thanks for the response. Attached are screen shots. Picture 7.png shows 

the link in the status bar of the browser that I got when hovering over 

the report link. I wasn’t sure if anything in the parameters being 

passed in would be helpful. Other than that, the pictures just show the 

progression of screens from my account home page, to the analytics 

report. I was logged in as “xxxx@koenigland.com”, but I was seeing 

analytics reports for “xxxx@creativeanvil.com”. This was on Firefox 

2.0.11 on Mac OS 10.5.

*Joe Koenig*

*Creative Anvil, Inc.*

*Phone: *314.692.0338

1346 Baur Blvd.

Olivette, MO 63132

xxxx@creativeanvil.com

http://www.creativeanvil.com

—— NEXT MESSAGE ——

Hello Joseph,

Thank you for sending us this information. I’ll be happy to assist you in

this situation. I see that you’re having trouble while toggling between

two login email address for two different Analytics accounts. I have

escalated this issue to our Analytics team. They’re currently

investigating the situation, and we’ll contact you as soon as we’ve found

a resolution. 

In the meantime, I encourage you to log in to your accounts from two

different browsers. 

Thank you for your patience and apologize for any inconvenience.

Sincerely,

Seva

The Google AdWords Team

—————-

To access your AdWords account, please log in at:

https://adwords.google.com

OK, at this point, I’m thinking ‘What?!??! Trouble toggling between accounts!?!?! Clearly, they don’t get it….’ So, I wait a bit and this is the response I then get from the Adwords team…

Hello Joseph,

Thank you for your patience while we researched this issue. I understand

you’re concerned about your Analytics reports for the website

‘http://www.koenigland.com’ showing in your Analytics account with the

login email address ‘xxxx@koenigland.com’ which you expected would show in

the account with the login ‘xxxx@creativeanvil.com.’ I would like to

explain that in the site ‘http://www.koenigland.com,’ you’ve installed the

tracking code for the Analytics account ID ‘UA-2618736-2′ which is

associated with the email address ‘xxxx@koenigland.com.’ This is the reason

why your Analytics reports for this site is showing in an account

different from the one you intended. 

If you would like to receive data for this site in your account with the

login email address 

‘xxxx@creativeanvil.com,’ you’ll need to place the appropriate code on the

site. 

To view your personalized Google Analytics tracking code, please follow

the steps in the following Help Center article:

http://www.google.com/support/googleanalytics/bin/answer.py?answer=55603&utm_id=cr

I hope this helps clarify your concern. 

As always, we look forward to providing you with the most effective

advertising available. 

Sincerely,

Seva

The Google AdWords Team

At what point did I say I expected them to both show up the same account!?!?! I said I was seeing them from the wrong account! There’s a security problem somewhere here, and their low-level techs don’t even have the ability to recognize that and pass it on to the appropriate team. I gave up at this point. As I said, this was back in January. In fact, the last email was 2/4/08. If they haven’t had a chance to fix it yet, not my fault. If anyone can explain how this happens, or how to reliably duplicate the security breach, I’d love to hear it. I’ve tried it again, but only once or twice and couldn’t duplicate. I figured someone with some more time may want to give this a try and see what they come up with. All I know is that I did NOT quit firefox in between switching from accounts and had been logged into my adwords account before logging out and going back into analytics. Any ideas anyone?


Joe Koenig

Creative Anvil

Web Design and Development, St. Louis

Share/Save/Bookmark

Leave a Reply