So I’ve been happily been using my Nokia XpressMusic 5310 for some time now.  Though I didn’t take a data plan with T-mobile I can still check my Gmail using the phone. That was until I changed my Google password.

I blogged that my Gmail account was comprised recently so I’ve been changing passwords a little and decided on one that I could remember easily.  When I updated it on my phone though it couldn’t sign-in.  I gave it a day but still nothing.  Now here was the confusing thing.  If I changed one or two characters of the password on the phone it gave the standard ‘wrong password’ message.  Type the right password in and it just said “sign-in failed, try again”.

Saturday morning I spent over 40 minutes on the phone with T-mobile support.  They had had a problem with some G1 customers (pure coincidence) so they thought it might have been fallout from that, but no.  As I was on hold for the third time I tried changing one character in my password in Google and then tried logging in on the phone – BINGO!

Seems that whatever Nokia/T-mobile uses to pass your password to Google it doesn’t like ampersands.  Chatting with the support tech he said he’d never come across that before and would log it in the Nokia database (they can’t access Google).  It was odd that somewhere, something was recognizing that it had the right password, but just wouldn’t let it through.

So if you want to bolster your secure password add non-alphanumeric characters, as long as you don’t want to access them from a Nokia phone using T-mobile.

So, I woke this morning to find my Gmail account had been sending out spam to everyone in my contacts list while I slept!

First, apologies to anyone that got hit. Second, how do I combat this?

Changing my Google password (which I did this morning) is really like shutting the barn door after the horse has bolted. I don’t think its anything on my laptop as I run anti-virus software and regular Spybot scans. Also nothing was sent from Thunderbird which I use locally.

How did “it” get access to my Gmail account? How does it run when its there? Is it Google’s fault?

We’ll have to start dealing with this kind of stuff more and more as we move into the cloud.  Can you trust the servers that your info is on? Do they run the latest anti-virus software, etc.?

Hopefully when I find out more about my current Gmail problem I’ll post here.