<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: How (in)secure is your Second Life password?</title>
	<link>http://www.vintfalken.com/may-i-change-your-second-life-password/</link>
	<description>Exporting an SL photographer's Second Life</description>
	<pubDate>Fri, 25 Jul 2008 17:29:37 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: Vint Falken</title>
		<link>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-7456</link>
		<dc:creator>Vint Falken</dc:creator>
		<pubDate>Fri, 07 Sep 2007 17:01:37 +0000</pubDate>
		<guid>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-7456</guid>
		<description>Comment that late: It's more then ok. You have some information I did not know, so it's even highly appreciated. *smiles*

No, the corresponding email address was still working fine and not comprimized. 

I believe what you say about corresponding IP address and the timestamped UUID (didn't know it worked that way, thx!) making this more safe, but still... if there were no problems whatsoever, then why did LL just did not put the JIRA issue as solved, in stead of 'hide it'. Why did nobody ever reply, and why - this has nothing to do with the security issue, but all the more with Linden Lab policy - after TWO MONTHS, pingping zhaoying's account is STILL NOT REINSTATED? And now - after filing another ticket, he got a phone number that's not reachable from belgium. Hmmm... 

(sorry for the caps, I really can't understand how they can treath their residents that way.)

As the IP system is foolproof: why do I then never got the four questions page, even when trying from the PC I use daily for SL and with my own account name? (IP is fixed until reboot of the PC, I think, maybe even longer.)</description>
		<content:encoded><![CDATA[<p>Comment that late: It&#8217;s more then ok. You have some information I did not know, so it&#8217;s even highly appreciated. *smiles*</p>
<p>No, the corresponding email address was still working fine and not comprimized. </p>
<p>I believe what you say about corresponding IP address and the timestamped UUID (didn&#8217;t know it worked that way, thx!) making this more safe, but still&#8230; if there were no problems whatsoever, then why did LL just did not put the JIRA issue as solved, in stead of &#8216;hide it&#8217;. Why did nobody ever reply, and why - this has nothing to do with the security issue, but all the more with Linden Lab policy - after TWO MONTHS, pingping zhaoying&#8217;s account is STILL NOT REINSTATED? And now - after filing another ticket, he got a phone number that&#8217;s not reachable from belgium. Hmmm&#8230; </p>
<p>(sorry for the caps, I really can&#8217;t understand how they can treath their residents that way.)</p>
<p>As the IP system is foolproof: why do I then never got the four questions page, even when trying from the PC I use daily for SL and with my own account name? (IP is fixed until reboot of the PC, I think, maybe even longer.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aspen Normandy</title>
		<link>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-7454</link>
		<dc:creator>Aspen Normandy</dc:creator>
		<pubDate>Fri, 07 Sep 2007 16:52:22 +0000</pubDate>
		<guid>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-7454</guid>
		<description>I hate to come into this thread so late, but I do want to say that after some experimentation, I don't believe that their change password system is 'grossly' insecure.

Here's a breakdown of it:
  User clicks 'Forgot password'
  User enters SL name
  An email is sent to the registered email address with a URL in it.
  User clicks 'Email no longer valid'
  At this point, the process splits based on a condition.

  If that user has ever successfully logged into secondlife.com or into SL from the current machine's IP address using the reported name, they go to the aforementioned '4 question' screen.
  If the user has never logged in under that name, they go to a screen with a phone number on it.

The email link sends the user to the '4 question' screen.  These questions are very easy to answer, but it is assuming that your email address is secure.
Fabricating one of these numbers would be rather difficult.  It is a timestamped UUID, so the person would have to know the millisecond that SL.com generated the UUID as well as guess at a ridiculously large random number.

I'm not saying this system is 'perfect', just putting out my two cents on it.  I don't really believe that it's as big a problem as made out to be here.
Is it perhaps possible that the account in question had its corresponding email address hijacked?</description>
		<content:encoded><![CDATA[<p>I hate to come into this thread so late, but I do want to say that after some experimentation, I don&#8217;t believe that their change password system is &#8216;grossly&#8217; insecure.</p>
<p>Here&#8217;s a breakdown of it:<br />
  User clicks &#8216;Forgot password&#8217;<br />
  User enters SL name<br />
  An email is sent to the registered email address with a URL in it.<br />
  User clicks &#8216;Email no longer valid&#8217;<br />
  At this point, the process splits based on a condition.</p>
<p>  If that user has ever successfully logged into secondlife.com or into SL from the current machine&#8217;s IP address using the reported name, they go to the aforementioned &#8216;4 question&#8217; screen.<br />
  If the user has never logged in under that name, they go to a screen with a phone number on it.</p>
<p>The email link sends the user to the &#8216;4 question&#8217; screen.  These questions are very easy to answer, but it is assuming that your email address is secure.<br />
Fabricating one of these numbers would be rather difficult.  It is a timestamped UUID, so the person would have to know the millisecond that SL.com generated the UUID as well as guess at a ridiculously large random number.</p>
<p>I&#8217;m not saying this system is &#8216;perfect&#8217;, just putting out my two cents on it.  I don&#8217;t really believe that it&#8217;s as big a problem as made out to be here.<br />
Is it perhaps possible that the account in question had its corresponding email address hijacked?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Checking up on password security: an operation which I am not permitted to perform &#124; VintFalken.com</title>
		<link>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-4047</link>
		<dc:creator>Checking up on password security: an operation which I am not permitted to perform &#124; VintFalken.com</dc:creator>
		<pubDate>Mon, 09 Jul 2007 23:36:09 +0000</pubDate>
		<guid>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-4047</guid>
		<description>[...] the (in)security of our Second Life passwords, I said I&#8217;d be happy if the Lindens would say &#8216;No problems whatsoever&#8217; or [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] the (in)security of our Second Life passwords, I said I&#8217;d be happy if the Lindens would say &#8216;No problems whatsoever&#8217; or [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Smiley Barry</title>
		<link>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-3507</link>
		<dc:creator>Smiley Barry</dc:creator>
		<pubDate>Sat, 30 Jun 2007 11:55:47 +0000</pubDate>
		<guid>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-3507</guid>
		<description>Nope. That's a DB bug, i'm certain. I know Linden, but i'll email Torley just in case.</description>
		<content:encoded><![CDATA[<p>Nope. That&#8217;s a DB bug, i&#8217;m certain. I know Linden, but i&#8217;ll email Torley just in case.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Smiley Barry</title>
		<link>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-3506</link>
		<dc:creator>Smiley Barry</dc:creator>
		<pubDate>Sat, 30 Jun 2007 11:54:01 +0000</pubDate>
		<guid>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-3506</guid>
		<description>Done. Go here for more info and a link to the JIRA proposal:
http://www.tslwiki.vintfalken.com/wiki/index.php?title=The_How_%28in%29secure_is_your_password_campaign</description>
		<content:encoded><![CDATA[<p>Done. Go here for more info and a link to the JIRA proposal:<br />
<a href="http://www.tslwiki.vintfalken.com/wiki/index.php?title=The_How_%28in%29secure_is_your_password_campaign" rel="nofollow">http://www.tslwiki.vintfalken.com/wiki/index.php?title=The_How_%28in%29secure_is_your_password_campaign</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vint Falken</title>
		<link>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-3505</link>
		<dc:creator>Vint Falken</dc:creator>
		<pubDate>Sat, 30 Jun 2007 11:37:43 +0000</pubDate>
		<guid>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-3505</guid>
		<description>Barry, it seems they are already working towards that: 

Nock said: &lt;em&gt;Seems the fix has going on now. Some people got “Call Us” dialog after clicking “Email no longer active?”. Correction should be done in soon.&lt;/e&gt;</description>
		<content:encoded><![CDATA[<p>Barry, it seems they are already working towards that: </p>
<p>Nock said: <em>Seems the fix has going on now. Some people got “Call Us” dialog after clicking “Email no longer active?”. Correction should be done in soon.</em></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Smiley Barry</title>
		<link>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-3504</link>
		<dc:creator>Smiley Barry</dc:creator>
		<pubDate>Sat, 30 Jun 2007 11:30:19 +0000</pubDate>
		<guid>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-3504</guid>
		<description>AAHH! This is even MORE insecure to us Teen Grid members! Most members have their homes either in XXXXXXXXXXX, welcome areas, or their public homes. GAH!.

Luckily I don't have a home (build) in SL (hehe), just XXXXXXXXX.

I suggest they give the options only after email verification, and that the "Email no longer active?" option should be phone ONLY.

I'm gonna suggest it on JIRA.</description>
		<content:encoded><![CDATA[<p>AAHH! This is even MORE insecure to us Teen Grid members! Most members have their homes either in XXXXXXXXXXX, welcome areas, or their public homes. GAH!.</p>
<p>Luckily I don&#8217;t have a home (build) in SL (hehe), just XXXXXXXXX.</p>
<p>I suggest they give the options only after email verification, and that the &#8220;Email no longer active?&#8221; option should be phone ONLY.</p>
<p>I&#8217;m gonna suggest it on JIRA.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vint Falken</title>
		<link>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-3499</link>
		<dc:creator>Vint Falken</dc:creator>
		<pubDate>Sat, 30 Jun 2007 10:38:39 +0000</pubDate>
		<guid>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-3499</guid>
		<description>Stop updating faster than I can create in-world crosses! ;)

Glad to hear that you will be back!</description>
		<content:encoded><![CDATA[<p>Stop updating faster than I can create in-world crosses! ;)</p>
<p>Glad to hear that you will be back!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pingping</title>
		<link>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-3497</link>
		<dc:creator>Pingping</dc:creator>
		<pubDate>Sat, 30 Jun 2007 10:15:25 +0000</pubDate>
		<guid>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-3497</guid>
		<description>Guy,

I have issued a refund of the charges that were fraudulently placed on your account. We'll have the account returned to you, asap. We are responding to attacks like this as quickly as possible. Sorry for the trouble.

JP
ontvangen vandaag zaterdag 30-07 9 dagen na neerleggen klacht en enige reactie (dit is violledige mail)</description>
		<content:encoded><![CDATA[<p>Guy,</p>
<p>I have issued a refund of the charges that were fraudulently placed on your account. We&#8217;ll have the account returned to you, asap. We are responding to attacks like this as quickly as possible. Sorry for the trouble.</p>
<p>JP<br />
ontvangen vandaag zaterdag 30-07 9 dagen na neerleggen klacht en enige reactie (dit is violledige mail)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PingPing, murdered for a crime he did not commit &#124; VintFalken.com</title>
		<link>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-3498</link>
		<dc:creator>PingPing, murdered for a crime he did not commit &#124; VintFalken.com</dc:creator>
		<pubDate>Sat, 30 Jun 2007 10:10:49 +0000</pubDate>
		<guid>http://www.vintfalken.com/may-i-change-your-second-life-password/#comment-3498</guid>
		<description>[...] 9 days later, and without any sign of LL my account was shut down, no more logging in possible, the rest of my [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] 9 days later, and without any sign of LL my account was shut down, no more logging in possible, the rest of my [&#8230;]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
