Skip to content

Security: Thirdrez/Support

Security

SECURITY.md

Security

Found a security problem? Please don't open a public issue.

Email contact@thirdrez.com and we'll take it from there. We'd much rather hear about something early and awkwardly than late and politely.

What to send us

Whatever you've got. A rough description beats no report at all. If you can, include:

  • What the problem is, and what someone could actually do with it
  • How to reproduce it, or a proof of concept
  • Which product, and which version — for TRZ View™, the version is shown in Help
  • Your operating system

What happens next

We'll confirm we received it, tell you whether we could reproduce it, and let you know what we're doing about it. When it's fixed we'll tell you, and we're glad to credit you by name if you want that — or to leave you out of it entirely if you'd rather stay anonymous.

Please give us a reasonable window to ship a fix before publishing anything. We're not going to argue about disclosure timelines with someone who just did us a favor.

In scope

  • TRZ View™ — the viewer, its updater, and its built-in tools
  • Kinetiq Engine™ and thirdrez.com
  • MotionPrint™ signing and verification

Not in scope

  • Second Life® itself, and anything else operated by Linden Lab. Those go to Linden Lab, not to us.
  • Scanner output with no working exploit behind it.
  • Anything that requires attacking our users rather than our software — social engineering, physical access, stolen devices.

For Second Life residents

Impersonation is the attack you're most likely to actually meet, so here is exactly where we do and don't exist.

We will never ask you for your password

Not by email, not on Discord, not in-world, and not in a bug report. TRZ View sends your login straight to Linden Lab and nowhere else — it never passes through Thirdrez. Anyone who asks you for it is not us, no matter what they call themselves.

We have no in-world presence beyond one person

Thirdrez does not operate in-world support staff, a volunteer team, an official support group, or a network of administrators. None of that exists.

The only resident who represents TRZ View in-world is Green Cloud. The viewer shows that name together with its account identifier under Help → Independence & Safety, so you can verify it yourself before trusting anyone.

Nobody else speaks for us. Using the viewer, running a fan group, moderating a Discord, or making tutorials about it does not make someone part of Thirdrez.

Nothing we ship ever arrives in-world

Installers, updates and patches are never distributed through inventory offers, objects, notecards, group notices, or unsolicited instant messages. If it reached you in-world, it did not come from us.

  • Don't run a file offered by a resident claiming to be TRZ View support, staff, an administrator, or a developer.
  • Don't trust a "download", "update", "security fix", or "required patch" link delivered in-world.
  • Don't type your Second Life password into a site you reached from an unsolicited message.

Official builds come from thirdrez.com or the viewer's own updater. Nowhere else. When something feels off, close the message and type thirdrez.com into your browser yourself rather than clicking anything.

Our only official channels

Website thirdrez.com
Documentation doc.thirdrez.com
Code repositories and issues github.com/Thirdrez
Community Discord
Email contact@thirdrez.com
In-world The resident Green Cloud, and nobody else

Anything outside that list is not us. If someone claiming to be from Thirdrez asks for your password or hands you a file, tell us at contact@thirdrez.com and we'll warn everyone else.


Second Life and Linden Lab are trademarks or registered trademarks of Linden Research, Inc. TRZ View is not provided or supported by Linden Lab and is not affiliated with or sponsored by Linden Research, Inc. Thirdrez has requested consideration for Linden Lab's Third-Party Viewer Directory; a request is not an approval, an audit, a certification, or an endorsement.

There aren't any published security advisories