Digg it!
|
Aaron Levy
Medicated Lately?
Join date: 3 Jun 2004
Posts: 2,147
|
09-08-2006 15:43
|
Luciftias Neurocam
Ecosystem Design
Join date: 13 Oct 2005
Posts: 742
|
09-08-2006 15:45
|
Aaron Levy
Medicated Lately?
Join date: 3 Jun 2004
Posts: 2,147
|
09-08-2006 15:47
'Cause its news, and people should know when a company has a horrid security lapse that compromises the safety of its customers.
|
Uma Bauhaus
Renascene
Join date: 18 Aug 2004
Posts: 636
|
09-08-2006 15:48
Excellent! Thank you for doing this. Make sure Aimee is aware of this too. I imagine she'll be doing a blog entry soon and might provide a link. dugg.
_____________________
The prophecy is true! At the end of the forums, Prok shall be born again and take the believers up to a holy forum while the sinners are forced to post comments in Linden blogs!
|
Chronic Skronski
SL Live Musician
Join date: 23 Jun 2006
Posts: 997
|
09-08-2006 15:49
"Hackers gain private information on all 642,720+ Second Life users"
Is this confirmed now, then? The official word is that "some of the unencrypted customer information stored in the database was compromised, potentially including Second Life account names, real life names and contact information, along with encrypted account passwords and encrypted payment information."
Yes, this is news - but not Fox.
_____________________
A man without religion is like a fish without a bicycle.
|
Kamen Zeluco
Registered User
Join date: 12 Feb 2006
Posts: 6
|
09-08-2006 15:51
I really hope more news sites pick this up - MSNBC, CNN, BBC et all so people can actually see what a piss poor company LL is from the point of view of customer service.
What the fuck have they been doing for 2 days - just blows me away. I'm literally sitting here shaking my head from the way they have dealt with this. Reset all the accounts and then fuck off home for the weekend - fantastic!!
I really feel sorry for the support staff on Monday - they are going to get absolutely mauled by people when they call them.
|
Uma Bauhaus
Renascene
Join date: 18 Aug 2004
Posts: 636
|
09-08-2006 16:39
Boing.
_____________________
The prophecy is true! At the end of the forums, Prok shall be born again and take the believers up to a holy forum while the sinners are forced to post comments in Linden blogs!
|
Alex Fitzsimmons
Resu Deretsiger
Join date: 28 Dec 2004
Posts: 1,605
|
09-08-2006 16:48
Dugg.
_____________________
"Whatever the astronomers finally decide, I think Xena should be considered the enemy planet." - io Kukalcan
|
Aindreas McGee
Registered User
Join date: 11 Jun 2006
Posts: 29
|
09-08-2006 17:25
I mentioned in another thread how CSR's (customer service representatives) were actually the most feared enemy in The Matrix Online, not Agents, shortly after the Sony takeover. So LL is not the worst for cutomer service.
What were they doing for the past 2 days? I'd say they probably locked down the offending entryway, then patched it, did a decent amount of testing on it, and then announced to us (and the hackers) when they reset the passwords.
Maybe that should be a thread? What would cause you to leave? Maybe something like: "Darn, we though we fixed that bug that randomly repossessed land to Governor Linden without compensation"
I'm very far from happy and the news should get out though; I totally agree with that. But I'd also hate to see SL wink out. I think the Lindens can get back on the ball, and I hope they do.
|
Aaron Levy
Medicated Lately?
Join date: 3 Jun 2004
Posts: 2,147
|
09-08-2006 17:43
I don't see how two days of investigation and THEN telling everyone their passwords, and possibly their credit card and personal billing information may have been disclosed is good business practice.
Companies are expected to act on security breeches immediately. What damage was done while they were "investigating?" The hackers obviously acted covertly, so why would they do something stupid to reveal their tracks? They could have logged into well-known accounts when they were offline and stole code or sent full-perm copies of objects to a wide variety of alts. The things people could do with just our password are mind-boggling.
It highlights the stupidity of the current login system though. Your user name IS ALSO your login name? Who the hell thought that up? I like WoW, where you have a login name known only to you, and all of your accounts are stored under that login name.
|
paulie Femto
Into the dark
Join date: 13 Sep 2003
Posts: 1,098
|
dugg
09-08-2006 17:46
_____________________
REUTERS on SL: "Thirty-five thousand people wearing their psyches on the outside and all the attendant unfettered freakishness that brings."
|
Aindreas McGee
Registered User
Join date: 11 Jun 2006
Posts: 29
|
You're right, probably could have been done better
09-08-2006 17:54
Hmm, yea, you're swaying me to your side more, Aaron. 2 days is pretty slow. The more responsible action would have been to put a lockdown on everything until it was fixed rather than leave it open 2 days like that. Maybe would have caused more backlash, even though it is a safer course of action.
But they certainly couldn't have just reset the passwords then if the hole still existed. They would have alerted both the original and unaware hackers to the potential exploit.
I also agree that those two username systems are a good idea, where you have a secret username that only you know, and then a public name that everyone else sees in game on when you post to the forums. It makes it that much harder for hackers.
|
Worthstream Rote
Registered User
Join date: 4 Jun 2006
Posts: 10
|
09-08-2006 18:05
Made an account just to digg this story! And it is a fast registration, too... 20 secs and you'll be making LL feel the bad pr!
By the way: this story just made the home page!
|
Raudf Fox
(ra-ow-th)
Join date: 25 Feb 2005
Posts: 5,119
|
09-08-2006 18:07
During the two days they were investigating, they could have said, "We're sorry, but we believe your personal information might have been exposed via an exploit. At this time, we request that all players change their passwords, until we find out more. If necessary, we may have to invalidate all passwords to protect your information. Please be ready with the answer to your security question, if this does occur."
They could have avoided the drama and disruption by simply doing this and looked a lot better in everyone's eyes.
Also, I'm pretty sure they're dreading Monday... oh, yes.... that's going to bite them hard. They felt it was important enough to invalidate the passwords, but not important enough to supply the support needed for those who would have problems? *snort* I guess they're learning the hard way, huh?
_____________________
DiamonX Studios, the place of the Victorian Times series of gowns and dresses - Located at http://slurl.com/secondlife/Fushida/224/176
Want more attachment points for your avatar's wearing pleasure? Then please vote for
https://jira.secondlife.com/browse/VWR-1065?
|
paulie Femto
Into the dark
Join date: 13 Sep 2003
Posts: 1,098
|
submitted it to BOINGBOING
09-08-2006 18:11
_____________________
REUTERS on SL: "Thirty-five thousand people wearing their psyches on the outside and all the attendant unfettered freakishness that brings."
|
paulie Femto
Into the dark
Join date: 13 Sep 2003
Posts: 1,098
|
submitted to SLASHDOT
09-08-2006 18:24
...
_____________________
REUTERS on SL: "Thirty-five thousand people wearing their psyches on the outside and all the attendant unfettered freakishness that brings."
|
Jeffrey Gomez
Cubed™
Join date: 11 Jun 2004
Posts: 3,522
|
09-08-2006 18:27
Boinged. 
_____________________
---
|
Aaron Levy
Medicated Lately?
Join date: 3 Jun 2004
Posts: 2,147
|
09-08-2006 19:35
We made the Digg front page! 
|
Uma Bauhaus
Renascene
Join date: 18 Aug 2004
Posts: 636
|
09-08-2006 20:02
I was just going to post this! It made the front page. Not just the Security front page but the Technology front page which is the front page. Excellent job Aaron. 
_____________________
The prophecy is true! At the end of the forums, Prok shall be born again and take the believers up to a holy forum while the sinners are forced to post comments in Linden blogs!
|
Ryan00 Odets
just a stupid redneck!
Join date: 17 Dec 2005
Posts: 289
|
09-08-2006 21:25
Dugg...and Aaron edit in the email from LL admitting the breach so its more beliveable.
_____________________
~~~~~~~ryan00~~~~~~~~~~~~~ http://forums.secondcitizen.com/
|
Alex Fitzsimmons
Resu Deretsiger
Join date: 28 Dec 2004
Posts: 1,605
|
09-09-2006 11:19
834 Diggs and counting, and it just went up yesterday. Gee. I know this is going to sound crazy, but bear with me here: I'm going to go out on a limb and say ... are you ready? I'm going to go out on a limb and say that despite all of the babbling about, "Oh this is nothing! You people are overreacting! It's all your fault anyway! Shut up and love it!" ... that despite all of that, it might be possible, just maybe, just possibly, that a few people felt there was something to be concerned about after all. Just sayin'.
_____________________
"Whatever the astronomers finally decide, I think Xena should be considered the enemy planet." - io Kukalcan
|