Skip to content
  • Home
  • SL
    • News & Opinion
      • SL News
      • SL In the Press
      • Opinion
        • Communications and LL
        • OpenSpace
        • Promoting SL
        • RedZone
        • SL Tier
        • Virtual Privacy and Identity
    • Art in Second Life
    • Events
      • Bay City
      • BURN2
      • Dance Performances
      • Education
        • General Education
        • VWBPE
      • One Billion Rising
      • Relay For Life
        • Fantasy Faire
        • MSABC
        • RelayStock
        • SL SF Con + Expo
        • SL Living
      • Seanchai Library
      • SL Birthday
      • Misc Events
        • SLCC
        • Stand Up 2 Cancer
        • Virtual Ability
    • Region Visits
    • Reviews
      • Games in SL
        • Get the Freight Out (GTFO)
        • GTFO: Getting Started
        • MadPea Games
        • SL Winter Games
      • SL Annual Reviews
      • SL Product Reviews
      • SL Tools
      • Misc Reviews
        • The Drax Files
    • SL User Group Meetings
      • Combat User Group
      • Concierge & Land
      • Content Creation User Group
      • Governance User Group
      • Mobile User Group
      • Project Zero User Group
      • Puppetry
      • Simulator User Group
      • TPVD / Open Source User Group
      • Web User Group
    • Subscription Plans
      • Plus
      • Premium
      • Premium Plus
      • Linden Homes
    • Viewers
      • Current Viewer Releases Page
      • Viewer Release Summaries
      • Project Zero
      • V7 Style
        • Alchemy
        • Black Dragon Viewer
        • Catznip
        • Firestorm
        • Kirsten’s Viewer
        • Kokua Viewer
        • Project Zero
        • Restrained Love Viewer
        • SL Viewer
      • V1 Style Viewer
        • Cool VL
        • Singularity Viewer
      • Android & iOS
        • Speedlight
        • SL Mobile
      • Other Viewers & Clients
        • Group Tools
        • Radegast
        • Speedlight
      • Outdated and Discontinued
      • Third Party Viewer Policy
  • Tutorials
    • Tutorials Index
    • Reporting, Authentication & Web forms
      • Abuse Reports
      • Group Bans
      • Multi-Factor Authentication verification
      • Verifying your process credit information
      • Verifying your SL e-mail address
      • Using Names Changes
      • Second Life Place Pages
    • Viewer Tools and Options
      • 360 Snapshot viewer
      • Bakes on Mesh Primer
      • Camera Presets
      • Debug Settings
      • Graphics Presets
      • Viewer Release Process
    • SL Environment & Photography
      • Creating a simple (prim) mirror in Second Life
      • EEP – a primer
      • EEP In-Depth Tutorial
      • Stevie Davros’ EEP sets
      • Using EEP for reflective floors
      • Lighting projectors
      • Projectors as mirrors in Second Life
    • SL University videos list
  • LL
    • CEO and Board
      • LL Board
      • LL CEO
    • LL News
    • Meeting Transcripts/Summaries
      • Lab Gab and Lab Chat
      • Lindens at VWBPE
      • SLB Meet the Lindens
      • Town Hall Meetings
    • Tax
    • Terms of Service
    • Tilia
      • Tilia News
      • Tilia and SL
    • Discontinued Products
      • Blocksworld
      • Creatorverse
      • Desura
      • Dio
      • Patterns
      • Versu
  • Other Worlds & Tech
    • AR and VR
      • Augmented Reality
      • Virtual Reality
    • Astronomy and Space
    • Sansar
      • News & Announcements
      • Exploring Sansar
        • Art in Sansar
        • Sansar Experiences
      • Technical Updates
      • Sansar Help
      • Sansar Personal
    • Other Virtual Worlds Archive
      • Blue Mars
      • Cloud Party
      • High Fidelity
      • OpenSim
      • OpenSim Grids
        • Avination
        • Inworldz
        • Kitely
        • MOSES
        • OSGrid
        • SpotON3D
      • Sine Wave
      • SunAeon
      • The Blu
      • Versu
    • General Tech News
  • Blog Bits & Contact
    • CONTACT ME
    • About Me
      • Who I Am
      • Blogging and Me
      • My SL
      • My Videos Index
      • Fallingwater
      • D/s Essays Index
    • Blog Guidelines
    • Blog Navigation
    • My Review Systems and Settings
    • Privacy Statement
  • Guest posts
    • Beq Janus
    • Caledonia Skytower
    • Marianne McCann
    • NeoBokrug Elytis
    • R.

Inara Pey: Living in a Modemworld

Second Life, virtual worlds and virtual realities

Tag: Account Security

Linden Lab: keeping your Second Life account safe

Posted on May 23, 2025July 25, 2025 by Inara Pey
via Linden Lab
One of the things that we’re trying to do is making the Second Life financial transactions easier for creators and buyers.  We’re doing more and more things to streamline systems, to give real-time payments … The bad news is that when you start to do these really good things for folks, you become a target, and bad people try really hard to take over other people’s accounts.

– Linden Lab Executive Chairman, Brad Oberwager, May 22nd, 2025.

These words formed comments by Linden Lab Executive Chairman Brad Oberwager during a Zoom call to bloggers and operators of large in-world Groups held on May 22nd, 2025. The call was held ahead of an official blog post on the matter of account security in the face of growing attempts by bad actors to try to take over people’s Second Life accounts and which has coincided with efforts to make it easier for users to process credit (cash-out) from SL (see: Your Account, Your World: Keep It Safe, published on May 23rd, 2025).

Whilst the official blog post should be read in and of itself, in keeping with the Lab’s request:

  • This article repeats the guidance given there, hopefully adding some additional context as provided / suggested during the Zoom call.
  • Offers a very brief summary / insight of some of the additional steps Linden Lab is taking in order to try to reduce the risks of accounts being compromised / taken over, and people losing money, beyond those mentioned in he official blog post.

Basic Account Security

  • Remember: your account name is public information. It is only your password that is protecting your account.
  • Never give out your password to anyone in SL, no matter how well you think you know them, or how helpful they appear to be; confidence tricking is part and parcel of the phisher’s social engineering toolset.
  • Do not use the same password across multiple accounts – including third-party sites you associate with your Second Life account (e.g. e-mail, Discord, etc.).
    • Phishers may not be “just” interested in your Second Life account; they many potentially have as much interest in where the account might lead – your e-mail contacts, other accounts you use, etc., – as they are in taking your L$.
  • Use a strong, unique password – at least 12 characters long, mixing upper and lower case, numbers and symbols.
  • Consider using a passphrase rather than a password: these can be harder to glean or guess.
  • Use LL’s Multi-Factor Authentication (MFA): yes, it’s not as perfect as it could be, and not everyone can use it. But if you can, please enable it. The added security far outweighs inconvenience of finding your account has been compromised and you are locked out of SL as a result while LL investigate.

Links and Downloads

  • Don’t click on links appearing in group chats, IMs, local chat, third-party sites used in association with SL (e.g. Discord, Flickr or similar) or which arrive unsolicited, and/or which offer you the chance to download a viewer, or go to a website for “special deals”, etc.
    • Similarly, be wary of ill-defined links within avatar profiles and check those that provide a URL (e.g. does a link apparently for the Marketplace actually give the correct URL, or does it have odd letters – “mmarketplace” instead of “marketplace”, for example).
    • Do not enter your account details on any website a link has directed you to, no matter how “official” looking. Remember, SL uses single sign-on, so you should not be asked for credentials if already logged-on.
  • Only download viewers from either the SL official viewer download page (e.g. by clicking the option on the right of your Account Dashboard), or by navigating yourself to the viewer’s website using the links within the Third-Party Viewer Directory. Never download a viewer via any other link (no matter how apparently trustworthy the source of the link).

Money

  • Never try to obtain Linden anywhere other than the LindeX or through the Buy L$ button in the viewer.
  • Don’t fall for offers of “discount” L$ purchased via external services such as Venmo or PayPal; these are scam activities and can result in you both losing money and access to your SL account.

Staying Alert and Taking Action

Staying Alert:

  • All of the above can happen at any time, so treat all offers of L$, unsolicited download suggestions / links, “promotional” offers for L$, etc., as suspicious, no matter who / where they come from.
  • Friends and acquaintances can have their account compromised just like anyone else – so just because you “know” the account sending you a link / offering to log-in to your account to “help” you with something, doesn’t what is being sent / suggested is safe.
  • As the old truism goes: if something sounds too good to be true (and involves anything to do with account access, money, etc.) – it probably is.

If your account is comprised:

  • Change your password, if you can still access your account, and if you have not done so (and can), enable MFA.
  • Report the situation to Linden Lab.
  • Accept the fact that the safest way to secure your information is for the Lab to lock your account for a time, and you may have to provide proof of identity before you regain control of it.
  • Do not revert any password set for your account by LL back to a previously used password. Remember, any previously-compromised password remains compromised even after your account has been reset.
I’ll give you an example of how trusting people are: someone gets their account taken over. We stop their account. They come back. We verify it’s them. We change their password to something complicated – because their password was “Potato1”. What do they do? The next day, they change it back to “Potato1”. And then they get their account taken over again.

– Linden Lab Executive Chairman, Brad Oberwager, May 22nd, 2025

What the Lab Is and Will be Doing

Linden Lab has been moving to address problems of account take-overs in a number of ways, some of which will are already in place or will be coming into use soon, as per the official blog post. In addition, further changes to help protect accounts are either in active development or are being considered. These include the following.

Additional Protections  / Requirements When Processing Credit (Cashing Out)

  • Enforced MFA when processing credit (cashing-out) from Second Life. If you are a creator or similar, wanting to convert L$ to fiat currency and take it out of Second Life as real-time payments, you will be required to use MFA.
    • The same may be required for those buying “large sums” of L$.
  • Re-introducing delays in processing credit if:
    • The cashing-out account has seen a password change ahead of the process credit request.
    • The external receiving account has been changed or the pay-out method updated.
    • There has been an IP address change for the account logging-in (not clear on how dynamic IPs will be handed with this).
  • Investigating specific options for account safety and verification where cashing-out very large sums are concerned (the example was in terms of tens of thousands of dollars).

MFA and Secure Log-in Enhancements

Linden Lab is additionally looking to:

  • Enhancing the multi-factor authentication (MFA) toolset to make it easier for more people to use.
  • Possibly adding passkey support to MFA.
  • Implementing log-in from trusted services (e.g. Google).

However, it was noted that some of this work will take time to complete.

Additional Improvements

These are options LL is either engaged in implementing, or considering (note: this list is not exhaustive in terms of the Zoom discussion, but reflects those things indicated as being pursued / investigated):

  • URL Links in Group chats, IMs, etc.:
    • Currently being scoped for inclusion in the viewer: adding a pop-up warning highlighting the risks when a user clicks on a link in an IM, Group chat, etc. This is being done in preference to disabling all such links, as it has been recognised there are legitimate use-cases for providing URL links.
    • Under investigation: providing the means for Group owners (/officers?) to be able to remove links from their Group chats.
  • Log-in warning: possibly add a log-in warning to remind people not to give their passwords out, share their account etc., with a required action to remove it. However, this is not currently viewed as optimal, due to the level of irritation / upset it would cause.
  • Updating interactions with Tilia to ensure greater account security. More to come on this from the Lab / in this blog in the near future.

Conclusion

Account take-over is a real threat within Second Life. While LL is attempting to minimise the risk of user accounts being compromised and money being taken, we all have a responsibility to ensure we keep our credentials as secure as possible, and that we all take a common sense approach to minimising the risks of having our accounts compromised. As such, if you are not already doing so, please do take the recommendations in the first part of this article – and in the Lab’s own blog post – seriously, and act on them.

Related Links

  • Your Account, Your World: Keep It Safe – Linden Lab 
  • Second Life Multi-Factor Authentication: the what and how – this blog
  • Protecting Your Account: Recognizing and Avoiding Phishing Attempts – Firestorm viewer

Share this:

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Facebook (Opens in new window) Facebook
  • More
  • Click to email a link to a friend (Opens in new window) Email
  • Click to print (Opens in new window) Print
Like Loading...
Tagged Account Security, SL News, Zoom2 Comments

Second Life: Android client “IM to SecondLife” blocked with security advisory for users

Posted on October 6, 2018May 29, 2020 by Inara Pey

Oz Linden, Technical Director for the Second Life platform at Linden Lab, has issued a blog post indicating the  Android client “IM To SecondLife” has been blocked from accessing Second Life.

While no specifics have obviously been given, the blog post notes the reason for the blocking is due to the committing “serious violations of the Policy on Third Party Viewers relating to user account security and user privacy.”

The blog post goes on to provide direct security advice for users who may have downloaded and made use of “IM to SecondLife”:

If you have ever used that viewer, Linden Lab strongly suggests that you secure your Second Life account, beginning with updating your password on the Second Life account page:
https://accounts.secondlife.com/change_password/

We may need to temporarily hold some accounts in connection with this incident. Please ensure that your contact information is up to date and verify your email address: https://accounts.secondlife.com/change_email/

Oz Linden, Technical Director for Second Life
concerning the “IM to SecondLife” Android client

Within the notice, Oz goes on to remind Second Life users:

As a reminder, although you may connect to Second Life using software released by a third-party developer,  as explained in our Privacy Policy and Terms and Conditions, you do so at your own risk. Linden Lab provides a Policy on Third-Party Viewers to promote a positive and predictable experience for all Second Life Residents. Extra caution must be taken with third-party viewers that are not in the Viewer Directory: they have either declined to self-certify their compliance with Linden Lab policies or have been refused for non-compliance with the policies.

(Above emphasis my own.)

According to Google Play, “IM to SecondLife” was released in September 2015, and since then has seen more than 10,000 downloads. If you have at any time used “IM to SecondLife”, or know someone who has, please ensure you read the blog post from the Lab and take the recommended action, or direct those you believe to be using it to read the post.

Share this:

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Facebook (Opens in new window) Facebook
  • More
  • Click to email a link to a friend (Opens in new window) Email
  • Click to print (Opens in new window) Print
Like Loading...
Tagged Account Security, SL News3 Comments
December 2025
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
293031  
« Nov    

Find out more about me by reading my interview with Strawberry Linden:

Second Life Spotlight - Inara Pey

Search this Site

Find me on Google by typing site:modemworld.me. Or use the search options below.

Categories

Archives

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

  • RSS - Posts
  • RSS - Comments

My Social Media

On Primfeed
On BlueSky
On Twitter
My photos on Flickr
My videos on YouTube

Most Recent Posts

  • Naughty Panda’s Return of the Light in Second Life
  • Eira’s charming wintertime setting in Second Life
  • Kitten’s Asphalt World at Nitroglobus in Second Life
  • 2025 SL viewer release summaries week #50
  • Alpha’s Quollidays in Second Life

Recent Comments

Inara Pey's avatarInara Pey on Kitten’s Asphalt World at Nitr…
Inara Pey's avatarInara Pey on Eira’s charming winterti…
Inara Pey's avatarInara Pey on Kitten’s Asphalt World at Nitr…
Joanna Kitten's avatarJoanna Kitten on Kitten’s Asphalt World at Nitr…
yoon-sl's avatarninetyninedots on Eira’s charming winterti…

Top Posts

  • Eira's charming wintertime setting in Second Life
  • Kitten’s Asphalt World at Nitroglobus in Second Life
  • The caring submissive
  • The "Ten Rules" of D/s
  • Naughty Panda's Return of the Light in Second Life
  • SSC and RACK

My Viewer Review Systems Specs

Blogroll

Anthea Courtois
Austin Tate's Informatics
Beq Janus
Bine Rodenberger
Calas Galadhon
Emily Short
Gwyneth Llewelyn
Hugh Toussaint
Kultivate Magazine
Loki Eliot
Owl Dragonash
R. Dismantled
Seanchai Library (SL)
Tatiana Dokuchic
UWA in SL
Virtual Ability
Virtual Community Radio
Wurfi's Second Life(SL)

SLBN RSS Feeds

Second Life Bloggers - news, reviews, updates
Destination Bloggers - learn about places to visit in-world
Home and Décor - what to buy for house and home

Second Life Resources

Feedback Portal
LSL Portal
Second Life University Tutorials
Server + Viewer Release Notes
SL Arts Wiki
SL Wiki
User Group Meetings
SL on You Tube

Viewers and Clients

Viewers
Alchemy
Aperture
Black Dragon
Catznip
Cool VL Viewer
Firestorm
Genesis
Kirsten's Viewer
Kokua
LL Alternate Viewers (RC and Project)
Lovense Viewer
Megapahit
Restrained Love
Singularity

Clients
Mobile Grid Client (Android)
Radegast (Win/Mac/Linux)
SL Mobile (iOS/Android)
Speedlight (iOS/Android / Browser)

RSS Second Life Grid Status

  • Phone and Live Chat Support Maintenance
  • Voice Server Maintenance for WebRTC
  • Rolling Restarts for Second Life RC Channels
  • Voice Server Maintenance
  • Rolling Restarts for Second Life Main Channel
  • Voice Server Maintenance for WebRTC
  • Rolling Restarts for Second Life RC Channels
  • Unscheduled Billing Maintenance
  • Community Forum Maintenance
  • Community Forum Maintenance

Virtual Community Radio

Virtual Community Radio

Flickr Photos

Naughty Panda - December 2025Naughty Panda - December 2025Naughty Panda - December 2025Naughty Panda - December 2025Naughty Panda - December 2025
More Photos

©, Disclaimers & Acknowledgements

All written material with articles in this blog, unless otherwise stated via citation and / or reference, is © Inara Pey.

All other trademarks found within this blog are properties of their respective owners, and are duly acknowledged; no attempt to infringe on any such copyright or trademark is intended.

Unless expressly stated otherwise, no affiliation with, or sponsorship by, any platform or entity mentioned in these pages should be assumed.

Comments submitted to these pages represent the views and opinions of those authoring them, and do not constitute any endorsement on the part of the author of this blog.

Links to other web / internet locations are offered as a convenience only. No warranty, express or implied, nor any legal liability is assumed for the accuracy, completeness, or usefulness of any information, product, or service offered at or through such linked sites, or for any consequences arising from the use of such links.

This blog is Creative Commons - Attribution - NonCommercial - Share Alike. original material within it may be shared / reposted / quoted in part or in whole in electronic and/or printed format, providing:

  • Full and correct attribution to this blog and author are given.
  • Any sharing/reproduction/other use is not for commercial purposes.
  • If you alter, transform, or build upon any content in this blog, the resultant work will only be distributed under the same or similar licence.
Website Powered by WordPress.com.
Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.
To find out more, including how to control cookies, see here: Cookie Policy
  • Subscribe Subscribed
    • Inara Pey: Living in a Modemworld
    • Join 2,248 other subscribers
    • Already have a WordPress.com account? Log in now.
    • Inara Pey: Living in a Modemworld
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar
 

Loading Comments...
 

    %d