Welcome to the Second Life Forums Archive

These forums are CLOSED. Please visit the new forums HERE

URGENT! LL security exploit

0mega Pixel
Registered User
Join date: 28 Jan 2006
Posts: 47
09-08-2006 10:31
now i'm locked out of my own account, thanks ll
Dnel DaSilva
Master Xessorizer
Join date: 22 May 2005
Posts: 781
09-08-2006 10:31
WAY TO FUCKING GO LINDEN LABS!

I purposefully do not give out my personal information in SL , now I find out they have been hacked and information like my ADDRESS is out there UNENCRYPTED!! In my country (Canada) we have strict laws protecting personal information kept electronically (PIPEDA), I will be contacting my lawyer regarding this although I doubt if there is a way to persure an American company.

I am seriously FUCKIN PISSED OFF about this, and to add insult to it, I change my password on the website AND I STILL CAN'T GET IN!

(I'm sure its just a delay since everyone is probably doing the same as me, but it sure doesn't help my mood right now).

Maybe if you gave direction to the people working there and TOLD them to do stuff, LIKE patch your servers or actively look for exploits, this would never have happened.
Yiffy Yaffle
Purple SpiritWolf Mystic
Join date: 22 Oct 2004
Posts: 2,802
09-08-2006 10:32
Well... Anybody know how to verify the password of several accounts which used a false email address? >.>
_____________________
Joshua Nightshade
Registered dragon
Join date: 12 Oct 2004
Posts: 1,337
09-08-2006 10:33
From: Tuach Noh
I would like to know why they were storing cleartext passwords in the first place, as opposed to hashed passwords. There is simply no good reason to do that.

Of course it may be that the passwords *are* hashed and they just want to prevent a dictionary attack against all the morons who used "password" as their password.

I word further like to know why the passwords are somehow less secure than the (presumably) cleartext answer to the security question, which might also be inferrable from the person's personal information.

In other words: After you finish changing your password, change your security question and answer too, just to be on the safe side.


yeah, I agree. wtf, they stored the passwords in unencrypted form?
_____________________


Visit in-world:
http://tinyurl.com/2zy63d

http://shop.onrez.com/Joshua_Nightshade
http://joshuameadows.com/
Tuach Noh
Ignorant Knowlessman
Join date: 2 Aug 2006
Posts: 79
09-08-2006 10:34
Wait, how do you change your security question and answer?

You can change them... can't you?
Very Keynes
LSL is a Virus
Join date: 6 May 2006
Posts: 484
09-08-2006 10:34
well now I'm pissed,

I cant get in with my primary accout or any of my alts and I still havent recived the email.
if i get debited this month for my $9.95 i'll screem.

This may be the last straw for me.
Skye McArdle
Resident Dragon
Join date: 26 May 2006
Posts: 132
09-08-2006 10:34
Oh great. I get the email back and it sends me to a page that says..

" Security Question
Please contact Linden Lab customer support, we do not have a security question on file for your account."

so now I'm waiting for email, when I was happily in the middle of a build before I logged :/.
Corona Lime
Lunatico
Join date: 14 Aug 2006
Posts: 171
09-08-2006 10:35
I will say this is one instance I am very happy about the Linden Blog. I don't visit here often enough to be up on all the news. However, the forum I run has direct Linden Blog RSS Feeds so a topic was created as soon as Linden Posted it. Worked well and allowed some of our members to hear about it quicker than they would have without the Blog.
_____________________
RCE Universe - bridging virtual worlds...
Adam Zaius
Deus
Join date: 9 Jan 2004
Posts: 1,483
09-08-2006 10:35
From: Joshua Nightshade
yeah, I agree. wtf, they stored the passwords in unencrypted form?


Nah,

The passwords are hashed and salted - so a dictionary attack is just about impossible (read: extremely impractical, but not mathematically impossible.)

I think LL is doing this just as a precaution, which is probably the right thing to do, even given that they are still likely secure.
_____________________
Co-Founder / Lead Developer
GigasSecondServer
Burke Prefect
Cafe Owner, Superhero
Join date: 29 Oct 2004
Posts: 2,785
09-08-2006 10:36
From: Jillian Callahan
Just a warning: Due to more brilliant programming, the change password page will allow you to choose a password that is longer than the login page will accept.

I didn't count, but it looks like it's 16 characters max, or so.


I noticed that too. I was gonna be clever and use one from http://www.grc.com/password (meant for networks and wifi keys). It allowed me to SET that, but...
_____________________
0mega Pixel
Registered User
Join date: 28 Jan 2006
Posts: 47
:(
09-08-2006 10:36
What I would really love to know is how can you reset your password if you dont remember your security hint.
Jillian Callahan
Rotary-winged Neko Girl
Join date: 24 Jun 2004
Posts: 3,766
09-08-2006 10:39
From: 0mega Pixel
What I would really love to know is how can you reset your password if you dont remember your security hint.
You'll have to give them a call.
This is gonna be a bad, bad day for thier support lines.

I get the feeling we're going to lose quite a few residents to this.
_____________________
Lewis Nerd
Nerd by name and nature!
Join date: 9 Oct 2005
Posts: 3,431
09-08-2006 10:41
Way to go Linden Lab... it's posted as the login message of the day.

How are you going to read that message if you can't actually log in?

Lewis
_____________________
Second Life Stratics - your new premier resource for all things Second Life. Free to join, sign up today!

Pocket Protector Projects - Rosieri 90,234,84 - building and landscaping services
0mega Pixel
Registered User
Join date: 28 Jan 2006
Posts: 47
09-08-2006 10:41
what a great day to close the forums, how ironic
Margaret Mfume
I.C.
Join date: 30 Dec 2004
Posts: 2,492
09-08-2006 10:41
From: Jillian Callahan
I didn't count, but it looks like it's 16 characters max, or so.

Yours is still good, Josh. :D
_____________________
hush
Aces Spade
Raise you One♠
Join date: 22 Sep 2003
Posts: 2,774
I can't remember
09-08-2006 10:41
I can't remember my security answer and i cant call LL this sucks
_____________________
From: someone
Posted by ZsuZsanna Raven
So where is the "i don't give a shit'' option?
Kimberly Casanova
Meh.
Join date: 24 May 2004
Posts: 787
09-08-2006 10:41
From: 0mega Pixel
What I would really love to know is how can you reset your password if you dont remember your security hint.


You're probably gonna have to get with LL on that, the security question is there for an important reason, I don't believe you can change it.
_____________________
Kimmers


http://www.kimberly-casanova.blogspot.com/
Fenrir Reitveld
Crazy? Don't mind if I do
Join date: 20 Apr 2005
Posts: 459
09-08-2006 10:44
L33t H4X W0rld, Pwnt Im4g1ntn
_____________________
----
----
----
Soleil Mirabeau
eh?
Join date: 6 Oct 2005
Posts: 995
09-08-2006 10:45
Goodbye alts.

I love you.
_____________________
0mega Pixel
Registered User
Join date: 28 Jan 2006
Posts: 47
09-08-2006 10:45
From: Jillian Callahan
You'll have to give them a call.
This is gonna be a bad, bad day for thier support lines.

I get the feeling we're going to lose quite a few residents to this.


i just gave them a call and got a nice recorded message saying you cant change your password over the phone FUCK!
Joshua Nightshade
Registered dragon
Join date: 12 Oct 2004
Posts: 1,337
09-08-2006 10:45
From: Margaret Mfume
Yours is still good, Josh. :D


to be honest my password was originally

cutoruncut ?

but now I have to think up something else. :(
_____________________


Visit in-world:
http://tinyurl.com/2zy63d

http://shop.onrez.com/Joshua_Nightshade
http://joshuameadows.com/
Albert Wake
Registered User
Join date: 5 Jan 2006
Posts: 25
09-08-2006 10:46
From: Lewis Nerd
Way to go Linden Lab... it's posted as the login message of the day.

How are you going to read that message if you can't actually log in?

Lewis


Flawless logic LL, I <3 LL
Jillian Callahan
Rotary-winged Neko Girl
Join date: 24 Jun 2004
Posts: 3,766
09-08-2006 10:47
From: 0mega Pixel
i just gave them a call and got a nice recorded message saying you cant change your password over the phone FUCK!
The feeling I had about losing residents? Just bumped up to a certainty.
_____________________
Taco Rubio
also quite creepy
Join date: 15 Feb 2004
Posts: 3,349
09-08-2006 10:48
From: Lewis Nerd
Way to go Linden Lab... it's posted as the login message of the day.

How are you going to read that message if you can't actually log in?

Lewis



lewis, this honestly made me laugh out loud thank you
_____________________
From: Torley Linden
We can't be clear enough, ever, in our communication.
Xplorer Cannoli
Cache Cleaner
Join date: 18 Sep 2005
Posts: 1,131
09-08-2006 10:49
From: Lewis Nerd
Way to go Linden Lab... it's posted as the login message of the day.

How are you going to read that message if you can't actually log in?

Lewis


now THATS comedy man. ROFLMAO
1 2 3 4 5 6 7 8 9