Security news September 8, 2006

On September 6 we discovered evidence that an intruder was able to access the Second Life database through the web servers. The exploit was shut down on the afternoon of September 6 when we discovered it.

Detailed investigation over the last two days confirmed that some of the unencrypted customer information stored in the database was compromised, potentially including Second Life account names, real life names and contact information, along with encrypted account passwords and encrypted payment information.

No unencrypted credit card information is stored on the database in question. Unencrypted credit card information has not been compromised.

As a precaution we have invalidated all Second Life account passwords. In order to log-in to Second Life you will have to create a new password. Please access the log-in page at https://secondlife.com/password, and click on the “Forgot Password” link. An email will be sent to the email address you have registered with us. (Don’t forget to check your spam filter!) Please click through the link in that email, answer the security question, and create a new password.

Passwords cannot be changed over the phone at this time. Phone support for password issues will be available starting Monday, September 11.

Related Articles:
  • Stolen VA laptop recovered; data appears untouched: A missing laptop and hard disk containing personal data on
  • Cisco kicks off annual analyst conference: Cisco Systems Inc. kicks off its 11th annual Worldwide Analyst
  • Browser users urged to patch up : Windows users are being warned about a bug that lets
  • MacIntel Switch: Part 1: Apple Makes a Switch of its own Part 1: The
  • SanDisk Launches TrustedSignins Authentication System: Online banking, shopping and other transactions will soon have added
  • Articles:

    Leave a Reply

    You must be logged in to post a comment.