Welcome to the Second Life Forums Archive

These forums are CLOSED. Please visit the new forums HERE

Any advice on security?

Allegria Kanto
Trailing clouds of glory
Join date: 28 Nov 2007
Posts: 1,004
09-16-2008 15:45
Wow, my CC got used fraudulently! :( This has never happened to me before... It's the account I use for all my online stuff, and I don't carry the card, so it must have been hacked in some way. Scary stuff.

Doesn't paypal offer a service that gives you a one-time use CC number to use for on-line transactions? If anyone knows, reply or PM me, please.

I've been concerned about security here too, after a recent thread disclosing the forum security flaws. Before I went on vacation at the beginning of Sept., I deleted all my payment info, because I thought I'd probably have to use an insecure wireless connection, which I did. I plan to have my old main be the only account with payment info on file (different pwords, of course), and just transfer Lindens to me when I need them. Think that will work? So far I'm still accessing the Forum, even tho I no longer have payment info on file. Wonder if that will continue to be the case?

What do you guys think are reasonable security precautions?

PS. I don't think the security breach happened at LL. I had not re-entered my payment info until last night, and the fraud happened this last weekend.
_____________________
Let us pray that we ourselves cease to be the cause of suffering to each other. -- Thich Nhat Hahn
3Ring Binder
always smile
Join date: 8 Mar 2007
Posts: 15,028
09-16-2008 15:46
honestly Allegria, i claim my cc lost about every 3 months, and they send me a new acct # and cards.... which makes the old acct invalid.

sorry this happened. really sux. i hope it wasn't too much $$ and that you get it resolved before your credit is ruined.
Allegria Kanto
Trailing clouds of glory
Join date: 28 Nov 2007
Posts: 1,004
09-16-2008 15:53
I don't think my credit will be ruined, I caught it within 2 days and the card is now cancelled. I just don't want it to happen again.
_____________________
Let us pray that we ourselves cease to be the cause of suffering to each other. -- Thich Nhat Hahn
3Ring Binder
always smile
Join date: 8 Mar 2007
Posts: 15,028
09-16-2008 15:58
i haven't done this yet, but i'm going to.... someone suggested buying those gifty visa cards and putting money on them and using them for online stuffs.... that could be a way to handle it.

in the interim, now that you cancelled your card and are getting a new one, mark this date and do it again in 3 months... claiming it lost. that'll at least avoid a repeat of same.
Desmond Shang
Guvnah of Caledon
Join date: 14 Mar 2005
Posts: 5,250
09-16-2008 15:59
Lock down your email passwords - that's #1. It's more critical than your bank password or anything. Once that is breached, hackers pwn your password resets. Often *all* of them.

Also amazing is the number of people whose security question is "what's your dog's name" - and then they mention Pookie twice a week in their blog.
_____________________

Steampunk Victorian, Well-Mannered Caledon!
3Ring Binder
always smile
Join date: 8 Mar 2007
Posts: 15,028
09-16-2008 16:01
From: Desmond Shang
Lock down your email passwords

what does this mean? how do you lock them down?
Allegria Kanto
Trailing clouds of glory
Join date: 28 Nov 2007
Posts: 1,004
09-16-2008 16:11
From: 3Ring Binder
i haven't done this yet, but i'm going to.... someone suggested buying those gifty visa cards and putting money on them and using them for online stuffs.... that could be a way to handle it.

in the interim, now that you cancelled your card and are getting a new one, mark this date and do it again in 3 months... claiming it lost. that'll at least avoid a repeat of same.



The service charges on those cards are outrageous, 3ring. I'm going to investigate the virtual card that paypal and some banks offer. They expire after one or a few uses.

Cancelling your card periodically is a thought.
_____________________
Let us pray that we ourselves cease to be the cause of suffering to each other. -- Thich Nhat Hahn
Allegria Kanto
Trailing clouds of glory
Join date: 28 Nov 2007
Posts: 1,004
09-16-2008 16:18
From: Desmond Shang
Lock down your email passwords - that's #1. It's more critical than your bank password or anything. Once that is breached, hackers pwn your password resets. Often *all* of them.

Also amazing is the number of people whose security question is "what's your dog's name" - and then they mention Pookie twice a week in their blog.



Reset my email pwords... that's good advice, i used them on a wireless connection while on vacation, and didn't think to change them.
_____________________
Let us pray that we ourselves cease to be the cause of suffering to each other. -- Thich Nhat Hahn
Gabby Handrick
Registered User
Join date: 18 Feb 2007
Posts: 190
09-16-2008 16:28
From: 3Ring Binder
what does this mean? how do you lock them down?

It just means to make sure your passwords are protected. In general you should change them now and then, make them strong (numbers, letters and special characters, no common or easily guessed words and not too short) and make sure that NO ONE else has access to them.
LittleMe Jewell
...........
Join date: 8 Oct 2007
Posts: 11,319
09-16-2008 18:55
Allegria - log into your paypal acct (set one up if you don't have one yet). Then on the left side of the screen, click on "PayPal Plug-In". That will install a plugin to your browser that will let you generate a new cc for each online usage, with the cc number really being paid from your paypal acct, either via your checking account or a real cc.

Also, pay the little bit of money to get the additional security device sent to you. This is a little device that you use to give you a new random number each time you log in to paypal.

ETA: And never ever enter a password that is used for financial/protected/important stuff on a website that is just HTTP rather than HTTPS
_____________________
♥♥♥
-Lil

Why do you sit there looking like an envelope without any address on it?
~Mark Twain~

Optimism is denial, so face the facts and move on.
♥♥♥
Lil's Yard Sale / Inventory Cleanout: http://slurl.com/secondlife/Triggerfish/52/27/22
.
http://www.flickr.com/photos/littleme_jewell
TigroSpottystripes Katsu
Join date: 24 Jun 2006
Posts: 556
09-17-2008 03:14
by canceling your cc, or claiming it lost or somthing, with paypal, don't you risk having your SL account frozen for some time? 0.0
Vampaerus Wysznik
bad lurker
Join date: 12 Apr 2008
Posts: 1,011
09-17-2008 04:14
it's not good for much other than peace of mind, but check with the bank that issues the card which was hacked/charged. Ask them if the CCV or a zip was used? (prolly wasn't) With modern computer hardware it's quite feasible to try random combinations of 16 digits plus a 4 digit expiration. If you process enough of em fast enough, by probability some small percent just works. So your CC# could have been directly spoofed with no provocation whatsoever on your part. The bank can usually tell that by how the card was used. If you have a $0.99 charge followed by a $1.99 then $9.99 etc, that's another indicator that it's a blind attack. RL bots are a much bigger problem than any SL bots. :mad:
_____________________
Small scale web hosting for your SL or RL. Payable monthly in L$.
Allegria Kanto
Trailing clouds of glory
Join date: 28 Nov 2007
Posts: 1,004
09-17-2008 12:27
From: TigroSpottystripes Katsu
by canceling your cc, or claiming it lost or somthing, with paypal, don't you risk having your SL account frozen for some time? 0.0



I've removed the CC info from my SL accounts, and am still accessing everything just fine. I don't intend to put payment info back on file for Allegria, unless I find I can't access the forums one day.
_____________________
Let us pray that we ourselves cease to be the cause of suffering to each other. -- Thich Nhat Hahn
Allegria Kanto
Trailing clouds of glory
Join date: 28 Nov 2007
Posts: 1,004
09-17-2008 12:29
From: LittleMe Jewell
Allegria - log into your paypal acct (set one up if you don't have one yet). Then on the left side of the screen, click on "PayPal Plug-In". That will install a plugin to your browser that will let you generate a new cc for each online usage, with the cc number really being paid from your paypal acct, either via your checking account or a real cc.

Also, pay the little bit of money to get the additional security device sent to you. This is a little device that you use to give you a new random number each time you log in to paypal.

ETA: And never ever enter a password that is used for financial/protected/important stuff on a website that is just HTTP rather than HTTPS



Thanks lil, I didn't know payPal had the little security device. I use them for work accounts, and feel much more secure.
_____________________
Let us pray that we ourselves cease to be the cause of suffering to each other. -- Thich Nhat Hahn
Nika Talaj
now you see her ...
Join date: 2 Jan 2007
Posts: 5,449
09-17-2008 12:33
From: TigroSpottystripes Katsu
by canceling your cc, or claiming it lost or somthing, with paypal, don't you risk having your SL account frozen for some time? 0.0
Prolly not. But, more importantly, if you cancel your CC often, you risk your RL credit score, and suddenly every Tom, Dick and Harry wants to call your credit card company to verify your identity every time you buy a latte (>.<;)

Happened to me when my wallet got stolen/lost twice within six months.
.
Allegria Kanto
Trailing clouds of glory
Join date: 28 Nov 2007
Posts: 1,004
09-17-2008 16:25
From: Nika Talaj
Prolly not. But, more importantly, if you cancel your CC often, you risk your RL credit score, and suddenly every Tom, Dick and Harry wants to call your credit card company to verify your identity every time you buy a latte (>.<;)

Happened to me when my wallet got stolen/lost twice within six months.
.


I thought that might happen, but have not had the experience myself.
_____________________
Let us pray that we ourselves cease to be the cause of suffering to each other. -- Thich Nhat Hahn
LittleMe Jewell
...........
Join date: 8 Oct 2007
Posts: 11,319
09-17-2008 16:33
From: TigroSpottystripes Katsu
by canceling your cc, or claiming it lost or somthing, with paypal, don't you risk having your SL account frozen for some time? 0.0
Actually, if you are changing the cc number associated with your paypal account very often, you risk having your paypal account locked until you can fax them all sorts of documents to prove who you are. A few years back, Citibank had a 'virtual cc number' generation and I added and removed a few cc numbers on my paypal account. After roughly the 6th time or so of doing this, my account was frozen for possibly fraud and it took me two weeks of trying to talk to them and get them the correct documents to straighten things out. Here I thought I was being a good cautious consumer and ended up making myself look suspicious.
_____________________
♥♥♥
-Lil

Why do you sit there looking like an envelope without any address on it?
~Mark Twain~

Optimism is denial, so face the facts and move on.
♥♥♥
Lil's Yard Sale / Inventory Cleanout: http://slurl.com/secondlife/Triggerfish/52/27/22
.
http://www.flickr.com/photos/littleme_jewell
Kit Namanari
Let's pretend...
Join date: 14 Oct 2006
Posts: 126
09-18-2008 06:28
From: Allegria Kanto
Wow, my CC got used fraudulently! :( This has never happened to me before... It's the account I use for all my online stuff, and I don't carry the card, so it must have been hacked in some way. Scary stuff.


I just joined the club. My check card was also compromised. :( Luckily it was large amounts of money. It would have been sometime before I caught the little amounts. Grrrr!
_____________________
我 看见 我 忘记。我 听见 我 记住。我 做 我 了解。
Brenda Connolly
Un United Avatar
Join date: 10 Jan 2007
Posts: 25,000
09-18-2008 07:07
I stopped using credit cards a couple of years ago, I don't even have one anymore. I have a Visa Check Card tied to an account strictly for online shopping and keep only a small running balance, transferring funds to it as I need.
_____________________
Don't you ever try to look behind my eyes. You don't want to know what they have seen.

http://brenda-connolly.blogspot.com