Heads Up: 2nd Life database hack!

General discussion about other games, links to reviews, demos, etc - let us know about whats up and coming

Moderators: Funkmasterr, noel

Post Reply
User avatar
Midgen
Gets Around
Gets Around
Posts: 115
Joined: December 4, 2002, 4:34 am
Gender: Male
XBL Gamertag: MidgenPlays
Location: Bothell, WA

Heads Up: 2nd Life database hack!

Post by Midgen »

Article here
Reuters wrote:NEW YORK (Reuters) - Second Life, the fast-growing online site where hundreds of thousands of people play out fantasy lives online, has suffered a computer security breach that exposed the real-world personal data of its users.

Linden Lab, the San Francisco-based company behind the Second Life site, said in a letter to its 650,000 users this weekend that its customer database, including names, addresses, passwords and some credit card data, had been compromised.

All users -- or residents in Second Life parlance -- are being required to request a new password. Some 286,000 residents have used the site in the past 60 days, according to a count on the home page at http://www.secondlife.com/.
Reuters wrote:The database breach potentially exposed customer data including the unencrypted names and addresses, and the encrypted passwords and encrypted payment information of all Second Life users, Linden Lab said in the message to users. Unencrypted credit card information, which is stored on a separate database, was not compromised, it said.

The breach was discovered on September 6. The company launched an investigation that revealed an intruder was able to access the Second Life databases utilizing a "Zero-Day Exploit" through commercial software used on Second Life servers.

"Due to the nature of the attack, the company cannot determine which individual data were exposed," Linden Lab's statement said. A technical probe is ongoing, it said.

The company said it will announced additional security plans on its blog at http://blog.secondlife.com/?tag=security/.
YIKES !
Hesten
Way too much time!
Way too much time!
Posts: 2620
Joined: April 29, 2003, 3:50 pm

Post by Hesten »

Yep, nasty one.
They handled it VERY well imo though, when they found out, ALL users were required to do a MANDATORY password change, could not even log in on the old one. You could request a new password from their database, and i sure hope that everyone remembered to give a usefull "secret question" question and answer, or they are pretty screwed, at least till LL would take mail or phone calls.

I dont think i even heard of any other company requiring password changes for everyone after being hacked.
"Terrorism is the war of the poor, and war is the terrorism of the rich"
User avatar
Winnow
Super Poster!
Super Poster!
Posts: 27747
Joined: July 5, 2002, 1:56 pm
Location: A Special Place in Hell

Post by Winnow »

Hesten wrote:Yep, nasty one.
They handled it VERY well imo though, when they found out, ALL users were required to do a MANDATORY password change, could not even log in on the old one. You could request a new password from their database, and i sure hope that everyone remembered to give a usefull "secret question" question and answer, or they are pretty screwed, at least till LL would take mail or phone calls.

I dont think i even heard of any other company requiring password changes for everyone after being hacked.
I remembered my seekrit question!

All is not entirely well though. On Sept 6th, I had a Linden/U.S. dollar transaction which has vanished. So far, customer service hasn't responded (understandable with the security thing going on) but that needs to be resolved before I give SL the thumbs up for them handling the hack.
User avatar
Winnow
Super Poster!
Super Poster!
Posts: 27747
Joined: July 5, 2002, 1:56 pm
Location: A Special Place in Hell

Post by Winnow »

All is well again. The transaction processed yesterday.

Another nice avatar.

Image

Image
User avatar
kyoukan
Super Poster!
Super Poster!
Posts: 8548
Joined: July 5, 2002, 3:33 am
Location: Vancouver

Post by kyoukan »

thank god. all the emo nerds can go back to cybering and pretending to be cool.
User avatar
Boogahz
Super Poster!
Super Poster!
Posts: 9438
Joined: July 6, 2002, 2:00 pm
Gender: Male
XBL Gamertag: corin12
PSN ID: boog144
Location: Austin, TX
Contact:

Post by Boogahz »

Maybe that means that one day YOU can be happy too! :D
User avatar
Winnow
Super Poster!
Super Poster!
Posts: 27747
Joined: July 5, 2002, 1:56 pm
Location: A Special Place in Hell

Post by Winnow »

Second Life kicks ass for what it is. I'm not playing much atm with lots of other things taking my time but will always head into SL here and there.

It's going to face a lot of growing pains in the next year as it's user base is climbing fast. The nice thing about SL is when they want to, they can take down the world sim by sim for updates instead of take down the entire world. I read somewhere that Linden Labs is rewriting the engine and will be able to switch over it eventually with just a patch.

Linden Labs needs to work on sim capacity if it plans to make it viable for large scale commercial events like concerts, etc. While Second Life can handle 100,000 people online, right now, individual sims top out around 60 which would barely be enough to hold a CT guild meeting.

They might want to add voice chat eventually. Streaming audio has made DJing in SL routine.

You can send an IM offline using email to someone in the game but it doesn't always work (depends on how long ago the last message was sent). SL needs an EQChat type addition to allow communication between offline and online people. A lot of merchants provide support/customer service and it would help a great deal to not have to log into the game sometimes.

If Second Life was publicly traded, now would be a good time to buy stock, especially after the hacker intrusion would have caused a dip.
User avatar
masteen
Super Poster!
Super Poster!
Posts: 8197
Joined: July 3, 2002, 12:40 pm
Gender: Mangina
Location: Florida
Contact:

Post by masteen »

Winnow wrote:... right now, individual sims top out around 60 which would barely be enough to hold a CT guild meeting.
If that meeting was held the day after the guild was formed maybe. A CT guild meet in their heyday would have choked a WoW cluster. :twisted:

Sorry, I couldn't resist.

p.s. SPAWN MORE OVERLORDS!
"There is at least as much need to curb the cruel greed and arrogance of part of the world of capital, to curb the cruel greed and violence of part of the world of labor, as to check a cruel and unhealthy militarism in international relationships." -Theodore Roosevelt
Hesten
Way too much time!
Way too much time!
Posts: 2620
Joined: April 29, 2003, 3:50 pm

Post by Hesten »

Hehe, i seen 74 people in one sim, ONCE. when the club i dance in had its 1 year anniversary.
Crashed 2 or 3 times that night, but we did see those 74 on without any crashes :)

But yeah, they REALLY need to work on getting more people in 1 sim. Those live concerts and stuff really need more than 60+ people :)
"Terrorism is the war of the poor, and war is the terrorism of the rich"
User avatar
kyoukan
Super Poster!
Super Poster!
Posts: 8548
Joined: July 5, 2002, 3:33 am
Location: Vancouver

Post by kyoukan »

Boogahz wrote:Maybe that means that one day YOU can be happy too! :D
lol dude you totally took what I said and directed it at me. they must have called you the zing master in college.
User avatar
Winnow
Super Poster!
Super Poster!
Posts: 27747
Joined: July 5, 2002, 1:56 pm
Location: A Special Place in Hell

Post by Winnow »

This could be better than Deadwood or the Sopranos! :twisted:
HBO documentary wants to speak with couples and expats in NYC area

Two requests:

1. Are you part of a Second Life couple in the NYC area? Did you meet in-world and get together in real life or are you just part of an in-world relationship?

2. Did you come to Second Life after leaving another virtual world or game to form your own community in SL?

This is for a documentary about MMORPGs for HBO and the production company is specifically looking for NYC area subjects. The producers will call you for a preliminary interview and if you are chosen to participate, you'll be required to do an on-camera interview.

Let me know if you're interested and provide your RL name, number, how long you've been in SL and how you'd like to participate. Contact me at

catherine@lindenlab.com

Thanks!
Catherine
Post Reply