Welcome to the Second Life Forums Archive

These forums are CLOSED. Please visit the new forums HERE

Security Update????

Craig Weiland
Registered User
Join date: 16 Jul 2006
Posts: 3
09-08-2006 17:15
From: someone
Linden Lab, please answer these questions ASAP:

What type of data was compromised in the exploit? Please enumerate the exact fields of info that was stolen, such as physical address, name, email, etc.

What form of encryption is used for the billing information? How thoroughly was it encrypted? (What sort of encryption method, how many bits used for key length, etc.?)

The blog originally stated "encrypted passwords" were stolen, but was later updated to reflect "encrypted payment information."

What kind of information was kept in this? Transaction history? Credit card numbers and billing address?

Will these questions be answered in your blog post? I think we have a right to know exactly what was compromised so we can take the right precautionary measures. And when do you expect this information to be available to us?
Robin Linden
Linden Lifer
Join date: 25 Nov 2002
Posts: 1,224
09-08-2006 21:21
Craig, we have no evidence that anything was stolen; only that the possibility existed.

*If* the attacker accessed information, it would have included your email, real name and contact information (if you included it), and an encrypted (hashed) password and CC number.

If we discover as we continue to investigate the intrusion, that specific information was accessed, we will let you know (or the account holders affected if it was limited to a smaller group).
_____________________