Okay, so this is really ridiculous. If you saw my last post, it might have been clear that I was investigating a potential security breach, but I thought it was an isolated occurrence.
Consider the following, and then read on:
1. Google is single sign on. Web History, Gmail, Blogger, Groups, all use the same account for verification
2. You can't just force all of your sessions to log out. The individual session stay logged in seemingly as long as needed, depending on browser setting. This means that when you sign out once, it doesn't sign you out everywhere.
3. Changing your password does not force existing sessions to log out.
Turns out, there have already been
several reports of the issue that I had. I was using Google Groups on the 29th, and all of a sudden, my email address swapped to someone elses. I can't remember the name exactly, khalamas or something like that.
I had to log out, and by the time I logged back in, I was told that my invitation to "Patriots For Conservative Values" had been accepted. I was added to the group as 'Redhawk', instead of Gregory Brown. I did not sign up for this group, and it wasn't the same email notification as when you are added directly by a group manager.
After several rounds of confusing conversation, the group there seemed to not know what the hell I was talking about, saying that they just thought that I was some well known person that goes under that handle from gop.com
They were fairly helpful all in all, but I didn't know what to believe seeing as this seemed incredulous to me.
I've gone and changed a ton of passwords, made full backups of my email, offshored many of my services to a different email address, and done as much damage control as I could.
Le sigh. What is worse, is that google doesn't log you out of all systems when you log out. This is usually a feature of sorts, but means that if a session is highjacked, who knows how long it will stay alive. :-/
If it's not clear automatically, the fact that google is single sign on means that depending on how long this lasted, email, web search, and all of that other stuff may have been compromised. That's really what I'm worried about, and will post details if I find out more.
UPDATE: A
blog entry from a user with a similar experience, who got in touch with Google. They said they recently made some changes to fix the issue, but no more details are there.
UPDATE2: Looks like we have
even more reports of this issue happening that I overlooked. Sighs.
UPDATE3: I've received word from Google employees that this was a known Google Groups issue, and has since been reverted. I've asked a few additional questions for risk assessment, such as how long the sessions were live, but haven't heard back yet. At the very least, it doesn't appear to have been an attack.