Warning: Quicktime security leak !!

As Linden Lab announced on their official blog yesterday, a direct security leak has been discovered in the Quicktime video player. The Second Life viewers use Quicktime to play in-world video's. To date, Quicktime have not released an update on their software. Until that time, any software that uses Quicktime, like the SL viewer(s) that you have installed on your computer, is affected by this security leak.

Linden Lab found this important enough to confront everyone with an extra warning when you log in. This warning has taken the shape of a ToS (Terms of Service) change that you have to agree to. The ToS hasn't actually changed, but I guess it was a quick way for LL to implement such a warning sign.

What does this mean?

People with bad intentions can make videos that you can stream in SL that might take over or crash your viewer.

What can I do?

Until Quicktime releases an update of their software and until Linden Lab can include this in their viewer, it's better to switch off your video player in-world. Of course you can still use it, but beware that you only play video's from people or companies that you trust.

How do I do that?

In the login screen, you can click on the Preferences button. Or, when you're already in-world, go to the Edit menu, then go to Preferences (or simply press Ctrl-P). Once you have the Preferences panel open, go to the Audio & Video tab and you will see 2 tickboxes. One is for audio streams and the other one is for videostreams. Simply deactivate the 2nd one and you're good.


I use the ON-REZ viewer. Does this affect me too?

Yes. For now, any viewer that is capable of playing in-world video's and that's using Quicktime, is affected.

What happens next?

Nothing. It's a waiting game till Apple releases an update for the Quicktime software. Beware, this does not only affect Apple computers, but any computer that has Quicktime installed on it. So this warning is active until further notice. In the meantime LL is able to track malicious video streams and they will remove those upon signt to make your Second Life as safe as possible.