5 ms·
Saved you a click: the internal state of some slot machines' PRNG can be predicted after observing a few of its outputs.
by CapacitorSet 10y ago
Saved you a click: the internal state of some slot machines' PRNG can be predicted after observing a few of its outputs.
- artursapek 10y agoI know I have read stories about this technique being used before. Doesn't it require special hardware and impeccable timing on your person to take advantage of it?
- matheweis 10y agoArticle indicates that an iphone is the special hardware. It also handles the timing, even preemptively signals the player when to go based on his/her reaction time. Timing doesn't have to be perfect - only enough to offset the house edge.
- macintux 10y agoWell, iPhone is the viewing mechanism for engineers on the other side of the world to do the real work.
- netsharc 10y agoInteresting how they're doing it, I guess making an app with image recognition takes too much effort, and having all the logic in an app makes it easier for your fellow thief to go independent and not give you your cut. I guess an app that requires login would be possible.
- macintux 10y agoIIRC the iPhone processing power is inadequate.
- bourbonfiber 10y agoWhat are you remembering, exactly?
- macintux 10y agoI made that assumption based on this text: > So even if they understand how a machine’s PRNG functions, hackers would also have to analyze the machine’s gameplay to discern its pattern. That requires both time and substantial computing power I would have guessed that the CPU requirements to process the video and map it against the PRNG characteristics would be a bit much for a smartphone, but given how powerful they are these days, that may well be flawed assumption.
- matheweis 10y agoI can't speak to the video processing (although with modern neural networks it seems it would be more than doable), but speaking from experience, brute forcing a 32-bit PRNG takes substantially less compute power than you might think...
- uremog 10y agoYeah, it'd be too much of a risk to let the "secret sauce" go anywhere out of their control.
- nbohra 10y agoIt only works for OLDER machines and the casinos and/or machine makers are not sufficiently financially motivated to upgrade the the logic
- acqq 10y agoThey obviously lose so little that it's not worth the cost of upgrading the software.
- jdcarter 10y agoNot just software; from the article it sounded like this was pretty old hardware, with a CPU only capable of running a basic PRNG. Doing a hardware upgrade on the zillions of old machines out there (I have no idea of the scale) must not be worth losing a couple thousand dollars here and there to sophisticated scammers.
- tromobne8vb 10y agoI found it interesting that part of the vulnerability is that the PRNG takes the time the machine 'spins' as a parameter, thus introducing an attack vector.
- lolc 10y agoI don't know whether it's mandated, but I think that a lot of gamblers would want it that way. They want to be able to influence the game. The outome will still be completely random if the other sources of randomness are good, but the outcome still depended on the gambler's timing.
- cxseven 10y agoThere has to be something that advances the PRNG to the next output. What's the alternative, advancing a single step each time a random number is actually needed? That also has (potentially much easier to exploit) vulnerabilities.
- dghughes 10y agoThe slot in question an Aristocrat MAV500 mark VI is 32-bit and is no longer in production. It's as random as much it can be made so in that range of 2,147,483,647? I'm not a programmer I'm not sure how a stop symbol or blank is chosen when programming a slot theme. Newer slots are 64-bit and have larger virtual reels. Some slots now even use a product called quantum randomness supposedly true randomness. https://comscire.com/ https://comscire.com/
- Strom 10y agoThe CPU architecture bit size (32-bit) has no impact on the random range. You can implement an arbitrary length RNG on any machine. Based on the article it seems that the flaw is that the machine uses the timing of human interaction as a significant seed source. This works well enough for unaware people, but as evidenced here is super easy to exploit once the knowledge is out there. Using time (e.g. the time the program started) as the PRNG seed is a very common security flaw. Otherwise experienced engineers keep making this mistake even in 2017.
- jcoffland 10y agoI don't think that is what the article said. Where do you read that the machine uses the user's timing to seed the PRNG? It talks about timing the button presses but my understanding was that that was only used after the PRNG was cracked. The PRNG is cracked by measuring the timings of on screen cues. These cues are essentially outputs from the PRNG. There is nothing that indicates the user's timing is used as a seed as far as I can tell.
- Strom 10y agoI assume you understood that by timing I didn't mean seconds from 1970. Beyond that this seems to be getting into semantics territory on how we define 'seed'. To be clear, I agree with what you're saying about the PRNG flaw. We can probably agree that PRNG is a function that takes an input and produces an output. I guess you take issue with me calling this input the seed. My use is probably a simplification indeed, but I thought one that doesn't change any principles. Because the user's interaction timing is crucial, it seems pretty clear to me that the exploit is about influencing the input of the PRNG. We can call this input something else, e.g. internal state. Or we can call it the seed.
- Scuds 10y agoThat bit about the attacker holding his finger over the spin button and then suddenly hitting it is a dead giveaway. Speed runners manipulate RNG all the time, except, of course, for a little 8 or 16 bit processor, not anything elaborate. Interesting how the core of an article gets explained with a few sentences given a small amount of background.
- IshKebab 10y agoAnd casinos have no fix!!! cough sure whatever
- anotheryou 10y agoAny simple enviroment sensor would have done the trick, no? (with any new input permutating some old value, so you can't fool the sensors unless you have acess to them all the time)