Welcome to the Second Life Forums Archive

These forums are CLOSED. Please visit the new forums HERE

How do I get my UUId?

Gordon Wendt
404 - User not found
Join date: 10 May 2006
Posts: 1,024
05-25-2009 13:18
From: Tali Rosca
Your UUID is absolutely no secret. Any script which does anything at all for you needs it. Sending inventory, paying you, animating you, you name it.

It is completely harmless. It is true that *if* you could fake a different UUID, you could circumvent a lot of built-in security, but it's tracked on the server and manipulating it would likely require a security breach of the servers of a magnitude where impersonating a single avatar would be pretty insignificant, comparatively. It is certainly not something you can do from a script.

There has been some security vulnerabilities/breaches related to the account (login/password) and to theoretically impersonating a *sim*, but there has, to my knowledge, never been a security exploit in any way related to the avatar UUID. -Though in fairness, *if* there was, it would likely be kept rather tightly under wrap.


There was always the last mandatory update security issue that was packet sniffing/injection allowing someone with a user's IP to spoof packets and inject them into the stream to nefarious ends but that required a user's IP (easy to get from media streams) linked to a specific user (harder to correlate but still possible) and was patched up fairly quickly with a mandatory update.
_____________________
Twitter: http://www.twitter.com/GWendt
Plurk: http://www.plurk.com/GordonWendt

GW Designs: XStreetSL

Tali Rosca
Plywood Whisperer
Join date: 6 Feb 2007
Posts: 767
05-25-2009 13:22
From: Gordon Wendt
There was always the last mandatory update security issue that was packet sniffing/injection allowing someone with a user's IP to spoof packets and inject them into the stream to nefarious ends but that required a user's IP (easy to get from media streams) linked to a specific user (harder to correlate but still possible) and was patched up fairly quickly with a mandatory update.

That was actually the sim impersonation, IIRC. It could potentially trick you into revealing sensitive information to a 3rd party server, though it was rather theoretical.

ETA: I remembered it as requiring a fairly low-level TCP/IP hack as well (hence me calling it theoretical), but I have been corrected that that was not the case, and that it actually allowed you to do a full session hijack of a logged-in avatar.
-That's still not based on the UUID, though, but on another, non-permanent internal ID sent between the client and the servers.
Rhaorth Antonelli
Registered User
Join date: 15 Apr 2006
Posts: 7,425
05-25-2009 13:50
From: Cerise Sorbet
You can copy the link for the ones without pages to get the key, right?


oh never checked that part DOH!
*looks*

nope... just tested my alt who doesn't have an html page and without the html page there is no key in the page url
_____________________
From: someone
Morpheus Linden: But then I change avs pretty often too, so often, I look nothing like my avatar. :)


They are taking away the forums... it could be worse, they could be taking away the forums AND Second Life...
Cerise Sorbet
Registered User
Join date: 8 Jun 2008
Posts: 254
05-25-2009 14:29
I go to http://search.secondlife.com/search.php and put in my npiof alt's name. There is a link 'Resident profile: Xxx Yyyyyyy' and I right click on that and copy link location. I paste the link and it looks like secondlife:///app/agent/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/about and the xxxxxxxxx part is the same as my alt's key.

Is there a different kind of link for some of them?
1 2