9 ms·
Use a Software Bug to Win Video Poker? That’s a Federal Hacking Case
- jacoblyles 13y agoThat's impossible. Gambling software is carefully regulated and approved by state gaming control boards, so there cannot be bugs.
- derleth 13y agoYes, because the only solution to state regulation failing to meet every single one of its goals is to end all regulation of everything, everywhere.
- pyre 13y agoI think the point is "there cannot be bugs, so obviously he hacked it!"
- jacoblyles 13y agoThe goal of regulation is regulation. Therefore it meets its goals always, every time. (On a side note, wouldn't it be awesome if every regulatory agency posted a list of quantitative goals and produced audited quarterly and annual reports on how it is doing? What a different world that would be!)
- derleth 13y ago> The goal of regulation is regulation. If you believe that, go breathe the air in Beijing.
- jacoblyles 13y agoDid the Beijing air regulators get fired? If not, it sounds like they're doing their job since their bosses must be pleased with their performance. The real goals and the stated goals of government are not always the same. To find out the real goals watch how they act instead of what they say.
- fennecfoxen 13y agoThe goal isn't always regulation - sometimes it is, sometimes not. When the goal is regulation, however, the excuse is always consumer protection, regardless of whether the actual form that the regulations take is a good approximation of a minimal, lowest-impact way to achieve those protections. And higher regulatory compliance costs make a very good barriers to entry, so lots of entrenched interests will lobby for regulation, because the benefits are concentrated among a few players with lots of resources. By contrast, the beneficiaries of lower-regulation regimes are typically consumers and upstart firms with fewer resources. Guess which group is going to be lobbying politicians? Guess which side makes a better story for politicians to tell their constituents? Guess which side brings the actual regulatory agency heads bigger budgets, more power, and general career advancement? It's an intrinsically unbalanced game, and what the economists call "rent-seeking" is a continually ongoing problem for most economic and political systems. Now, how about an actual debate on how to structure an actual regulatory regime specifically, instead of painting "Regulation!!!!" with a broad brush one way or the other? Both of you sides, goodness.
- dugmartin 13y agoHe didn't use the bug to win but rather change the payout. If it was a logic bug causing him to win against the machine I would say he was fine, however this bug allowed him to change the payout amount, which is fraud. It is really no different than if the machine printed out the amount on a ticket and he forged a different amount on it before he turned it in.
- fatjokes 13y agoBottom line: he was beating the house. There is no way that would've been "fine" to the casinos. On the bright side for him, at least it's not the "old days" when casinos were run by the mob. From that perspective, he should be grateful to be thrown in front of a judge.
- LanceH 13y agoFlip the scenario: I bet on the Giants -3.5. Oh, the casino has taken advantage of my misunderstanding of -3.5. They have escalated access to my money based upon my mistake. Have they committed fraud? Do I get my money back? Do I get to change my bet after the fact? Of course not. They put out a machine which was giving away money. The guy did nothing other than put money in the machine and push the buttons. If Vegas had to return all the money to the gamblers who made mistakes, it would just be a desert again.
- kbenson 13y agoMy understanding is that all the slot/video machines have highly regulated payouts. The law states they must pay within a certain range, and they are verified by state employees on a regular basis. If he is causing the machine to pay out at a level outside that allowed by the law, then he's breaking the law as much as the casino would be to make it pay out differently as well. Edit: To clarify, I don't think he should be tried for hacking. I think he should be tried for circumventing state gaming laws, if applicable, or released. If they don't cover this, they it should be legislated if it is deemed important enough. Going after someone through some loosely affiliated law because you want them to go to jail even though what they did wasn't strictly illegal in wrong, IMHO.
- tzs 13y ago> But the casino had been suspicious, and Kane didn’t collect the last win Bad move! This reminds me of Louis Colavecchio. He made quite a lot of money off Atlantic City casinos using counterfeit slot machine tokens. The casinos KNEW they were being ripped off by a counterfeiter, because their token counts at the end of the day were coming in consistently high, but they were stymied because they could not tell which tokens were counterfeit. That made it hard to even get started tracking their origin. Even the token manufacturers were not able to determine which of a set of tokens were authentic and which were counterfeit. [1] Colavecchio's downfall came one day when he was playing a machine, and it jammed, eating his token. He simply moved to the next machine, and continued playing. That caught the attention of the guard watching that row of machines on the security camera. These machines were something like $10 or $25 per play machines. When a legitimate gambler has a token of that value eaten by a machine, they don't just let it go and move on to another machine. They report it and make a fuss until they get their money back. The guard realized that one person who would just move on would be the counterfeiter--he would not want to draw attention to himself by making a fuss, and psychologically would think of his tokens as only worth a few cents and so would not be upset at losing one. With that lead, they were able to watch Colavecchio and get enough evidence to nail him. [1] Years after Colavecchio was caught and convicted, his counterfeit tokens remained in circulation in Atlantic City casinos, because they never did figure out a way to tell which were real and which were Colavecchio's.
- vinhboy 13y agogreat story.
- harryh 13y agoSuper cool story. Though, that wasn't my reading of "Kane didn’t collect the last win." I read it as "the casino didn't pay him for the win because they suspected him of hacking/cheating." It could be either one though. Now I'm not really sure.
- reustle 13y agoCool story. For the curious, "Sentenced to seven years, Colavecchio was released in 2006. He was re-arrested by the FBI only a few months later having resumed his activities, and release on a $25,000 surety bond" http://en.wikipedia.org/wiki/Louis_Colavecchio http://en.wikipedia.org/wiki/Louis_Colavecchio
- eykanal 13y agoThis is going to be tough to argue from a hacking standpoint. IANAL, but a quick perusal of some of the hacking-related legislation shows that almost all federal definitions of "hacking" involve "without or exceeding authorization "(See sections (1)(a), (1)(b), and (1)(c) in the Computer Fraud & Abuse Act (CFAA) [1]). A definition of that phrase is provided at length in this pamphlet [2] put out by the Department of Justice Cybercrime division. Specifically, from the first document (section (e)(6)): > the term "exceeds authorized access" means to access a computer with authorization and to use such access to obtain or alter information in the computer that the accesser is not entitled so to obtain or alter and from the second (section A.2): > The term “without authorization” is not defined by the CFAA. The term “exceeds authorized access” means “to access a computer with authorization and to use such access to obtain or alter information in the computer that the accesser is not entitled so to obtain or alter.” Later in the same section, it states: > Prosecutors rarely argue that a defendant accessed a computer “without authorization” when the defendant had some authority to access that computer. However, several civil cases have held that defendants lost their authorization to access computers when they breached a duty of loyalty to the authorizing parties, even if the authorizing parties were unaware of the breach. [...] Some of these cases further suggest that such a breach can occur when the user decides to access the computer for a purpose that is contrary to the interests of the authorizing party. See, e.g., Citrin, 440 F.3d at 420 (defendant’s authorization to access computer terminated when he resolved to destroy employer’s files); ViChip Corp. v. Lee, 438 F. Supp. 2d 1087, 1100 (N.D. Cal. 2006) (same); NCMIC Finance Corp. v. Artino, 638 F. Supp. 2d 1042, 1057 (S.D. Iowa 2009) (“[T]he determinative question is whether Artino breached his duty of loyalty to NCMIC when Artino obtained information from NCMIC’s computers.”). Not sure what to make of that, as again, IANAL. Still, this is definitely not hacking in the traditional legal sense. [1]: http://energy.gov/sites/prod/files/cioprod/documents/ComputerFraud-AbuseAct.pdf http://energy.gov/sites/prod/files/cioprod/documents/Compute... [2]: http://www.justice.gov/criminal/cybercrime/docs/ccmanual.pdf http://www.justice.gov/criminal/cybercrime/docs/ccmanual.pdf
- ChuckMcM 13y agoUnderstand that the Justice department pamphlet is how they would like it to be interpreted but how it is actually interpreted is based on case law. And they provide the case law that supports their interpretation. It will be interesting if that language gets stricken from the CFAA because it will significantly blunt this particular tool in the governments toolbox. That said, I expect that this case will find for the defendant on the grounds that the Casinos put those machines in, they agreed to pay out any winnings. That there was a bug was IGT's issue. So the casinos will then have their losses covered by IGT's errors and omissions insurance.
- thehigherlife 13y agoHere is an interesting anecdote. From the author of the article's wikipedia page. His best-appreciated hack was a takeover of all of the telephone lines for Los Angeles radio station KIIS-FM, guaranteeing that he would be the 102nd caller and win the prize of a Porsche 944 S2. When the Federal Bureau of Investigation started pursuing Poulsen, he went underground as a fugitive. When he was featured on NBC's Unsolved Mysteries, the show's 1-800 telephone lines mysteriously crashed http://en.wikipedia.org/wiki/Kevin_Poulsen http://en.wikipedia.org/wiki/Kevin_Poulsen
- apawloski 13y agoFor future reference, footnote-style notation [1] can significantly improve the clarity of your comments on sites that don't use markdown. [1] http://www.google.com http://www.google.com
- thehigherlife 13y agoI updated the post to strip some of the unnecessary links, thanks for the heads up.
- jedberg 13y agoThe reddit office was just next to Kevin's desk. Kevin is a cool guy. He's crazy smart and makes an excellent security journalist. He married his defense attorney and they have a super cute kid. And I talked to him once about the radio contest thing, because I was a teenager at the time and remember trying to win that contest.
- vinhboy 13y agoMy goodness. This is such baloney. How are you going to get charged with hacking for something like this. If anything, you can blame the guy for not being moral and telling the casino about their mistake, but he is definitely not required to. It's the casino's fault, or the game creator, for putting out a buggy game. They should be happy to have discovered the problem and just fix it. Should I be allowed to sue vending machine owners every time my candy doesn't drop?
- spinlock 13y agore: the morality of the situation. this guy lost a million dollars in one year playing video poker. That's an addiction and it is certainly amoral to allow someone with a gambling addiction to play in your casino. In my opinion, any moral obligation goes away when the other side is taking advantage of your addiction.
- danielweber 13y agoAlthough I do think that this guy crossed a legal line, there's no doubt that the casino would love to have him right up against that line as hard as possible.
- ssharp 13y agoI'd expect that there would be some some central database of these machines that track their incoming and outgoing money that all the casinos feed their data into. It would seem crazy that this type of activity would go undetected to the tune of several hundred thousand. Even if payouts were tracked locally, it should have been a huge red flag. Unless the tracking that is sent over (or compared locally against baselines) is based off of in-play data and the amount exploited in the bug was never properly reported.
- reillyse 13y agoThis case would be laughable if not for the fact that we all know the gambling associations are going to use their wealth & power to make his life hell.
- DanBC 13y ago> Much of the cheating the Technology Division deals with comes from professionals, who will buy a used game machine, put it in their garage and plumb it for vulnerabilities. > “They are looking to explore how they can exploit the machine from a mechanical standpoint,” says Jim Barbee, chief of the division. That means physical hacks aimed at the coin hopper or the bill reader. Software vulnerabilities like Kane’s are nearly unheard of. Someone should sell them a fuzzing suite.
- deleted 13y ago[deleted]
- hughw 13y agoIf you discover a reproducible flaw in a blackjack game -- the card shuffler at a certain table isn't random -- is there a penalty for that? Because just having a computer in the mix doesn't seem like it really changes the moral equation.
- format 13y agoBlackjack already has a reproducible flaw, it is called card counting. It is not illegal, but casinos frown upon it and often ban people who are suspected of card counting. I would argue that noticing and exploiting a flaw in the blackjack card shuffler falls along the same lines. You are using meta-knowledge to reduce the house edge. But this is not what Kane did, he didn't alter his chances of winning, he altered the payout. The real argument is not if pushing the buttons in the right order is cheating, but is it hacking? That issue seems to come down to whether or not there was an escalation of access. Did those button presses give him unauthorized access to data? He exploited a flaw to alter the payout of the game, and that is at the very least fraud. If we are using your blackjack analogy this is like he somehow Jedi mind tricked the dealer to change the payout for a 21. If I used a software exploit to get a bank computer to double my money I have no doubt that would be seen as hacking. So how is the gambling machine different?
- spinlock 13y agoFYI - gaming regulators in different states deal with card counters in different ways. In NV, the casino is allowed to ask you to leave and ban you from the casino. But, not in NJ. in NJ you cannot be barred from a casino for counting cards. The casino can shuffle the deck after every hand to make the game fair again (or unfair in the right way).
- 9999 13y agoThis reads like fraud to me. From the article: "Now when Kane returned to Triple Double Bonus Poker, he’d find his previous $820 win was still showing. He could press the cash-out button from this screen, and the machine would re-award the jackpot. Better yet, it would re-calculate the win at the new denomination level, giving him a hand-payout of $8,200." To me it seems analogous to placing a $1 bet on a table game, then swapping the $1 bet for a $10 bet if your wager paid out. That kind of cheating/fraud is fairly commonplace (and dealers are trained to prevent it).
- klodolph 13y ago> “These guys kind of kept it a secret,” says Leavitt. “If this had got out… this would have been a bad thing for the casinos.” I'm sure they would have pulled all the games pretty quickly if it had gotten out. Casinos take analytics seriously.
- danielweber 13y agoI have this feeling that the other shoe is about to drop, and we're going to find out something big is missing from the reporting, they they had a friend working at the company. Also, this logic: “All these guys did is simply push a sequence of buttons that they were legally entitled to push.” is very annoying. You can describe any illegal action as innocuous. I'm not saying this case deserves to be hacking (IMHO if you learn, say, that the sequence of cards resets every 256th turn through, more power to you), but this is a weak argument.
- sneak 13y agoThe issue is that we as a society expect the user to guess at the intent of the programmer (even when it seems obvious) instead of going by their code's behavior, which is fundamentally flawed. In the weev/ATT thing, they were even leveraging this insane duality for profit - the publishing of the email addresses by ATT was an explicit design decision for user convenience, and they relied only on obscurity and the law to protect the data. Weev and Gawker made sure that the obscurity argument was a non-starter, and we'll see about the legal one in the next few years. I think that the casinos should have the liability, because they are the ones who deployed automatic money dispensers with poorly-designed software running on them. I don't see criminal behavior, here. If you program (or load software) onto your robot, you are responsible for when it carries out those instructions, even if you did not fully envision the consequences in advance. Same goes for replying to packets on the internet. It's impossible to rob a server of information at gunpoint. This is DWIM carried through the machine and legally imposed onto the end-user, and that's a load of crap.
- danielweber 13y agoFortunately we don't live in the wild west. If the bank forgets to lock its vault it's not free money season. He didn't just find some way to, say, outsmart the random number generator. (And I think that would be fine: casinos encourage people to think they have founds ways to beat the system, because they keep on trying them, putting more money in the casinos' pockets. If someone manages to somehow actually beat the system, good for him.) He found a bug in the payout calculator. If you figure out a way to press buttons on an ATM that makes your withdrawal credited as a deposit, it's neither legal or right to repeatedly exploit that. There is no "gee, I really thought it meant to do that."
- spinlock 13y agoso, if it is considered "hacking" to do this, what about the first time he found the exploit? He didn't intend to do that he just jumped the gun to get back to playing. Was that mistake a crime?
- lifeformed 13y agoThis is like watching game speedrunners exploit glitches in the game to get a better time, and then hearing laypeople complain about it not being a "real" run. If it's all done within the context of the system, then it's fair. In game speedruns, the context is: "Beat this game as fast as possible with the following restrictions (no cheats, 100% completion not necessary, etc) using the provided input system." If I go to a casino, the context of playing a slot machine is: "Put real money into this machine and press buttons on it until you run out of money or leave." There aren't any implicit rules like, "some combination of button presses are not allowed". Let the player have his money, patch the bug and move on.
- sliverstorm 13y agoFor speedruns, there's a philosophical divide- some people consider exploits to be cheating, thus it falls under the "no cheating" rule.
- lifeformed 13y agoI don't know any serious speedrunners who consider most exploits to be cheating. Something as simple as bunnyhopping is an exploit, yet you'd be laughed at if you tried to run Quake without doing so. True, there are some exploits which are truly degenerate, but they are specifically handled. Exploits in general are highly encouraged. Speedruns are listed in terms of the restrictions given: a specific difficulty, 100% vs any%, rules governing the timing, etc.
- format 13y agoSkiing in Tribes was originally a bug, and it became an essential feature and set the franchise apart from other shooters. Exploits in speedrunning aren't often easy to do, and finding new applications for them are part of the challenge and can set one speedrunner ahead of another.
- pyre 13y agoI remember seeing a speedrun of Half-Life where the player went through a wall (that you weren't supposed to go through), kept going (past all of the weird clipping visual nonesense), and finally came out in a different level (which IIRC wasn't even populated with enemies), and kept going through the game. That seems like cheating to me. Little glitches in the game mechanics are a little bit different.
- habosa 13y agoThat's crazy. Am I "hacking" a vending machine if it gives me two candy bars instead of one? What if he had just closed his eyes and slammed the buttons and this happened? Would he be the world's foremost blind hacker? Both sides are engaged in taking as much of the other's money as possible within a set of rules, and he won.
- twoodfin 13y agoWhat if he had just closed his eyes and slammed the buttons and this happened? Would he be the world's foremost blind hacker? That's not a very good argument. Intent matters. This guy obviously knew he had uncovered a bug, and repeatedly exploited it while attempting to hide the fact that he was doing so. I can't speak to whether the CFAA actually will or should be interpreted to treat his actions as a crime, but it would not be an unreasonable law that did.
- snarfy 13y agoIt's not obvious it's a bug, not at all, and it's a slippery slope to say otherwise. Intent matters on both sides. Did the programmer intent for this bug to happen?
- twoodfin 13y agoHuh? Through a specially designed switch back and forth between games, he manages to multiply a preexisting payout by a factor of 10. It is absurdly obvious that this was a bug.
- jmharvey 13y agoIANAL, but I have thought a lot about what constitutes cheating at gambling, as opposed to legal advantage play, and I think this is cheating. The key distinction, for me, is that the machine is not a game in and of itself, but an interface for offering multiple games. (For those who didn't read the article, the scheme basically involves playing game A at the minimum wager until you get a big win, then switching to game B at a higher wager until the game B reaches a certain state, and then switching back to game A, at which point the machine would re-calculate your earlier win in game A based on your (higher) wager in game B.) The nearest analog I can think of is switching roulette table chips between tables of different denominations. When you buy roulette chips, the croupier notes the value of a stack of 20 chips, usually $20, $100, or $500 a stack, by placing a token near the wheel. Looking at a single chip, it's impossible to tell whether the chip is worth $1, $5, or $25. And a given color chip at one table may be worth $1, while at a neighboring table it's worth $25. Table chips are marked with a letter on their face indicating which table they belong to, but croupiers don't always examine the letters, so if you slip chips between tables, you might be able to wager a low-denomination chip and be paid off in high-denomination chips. That's definitely cheating, even if the casino doesn't immediately stop you from slipping chips between games. My general rule of thumb is that anything that happens within a game is fair play. If the exploit had been that a particular sequence of wagers would cause the random number generator to behave in a predictable way, then I'd be fine with it. But I wouldn't consider the game-selection interface to be part of the game.
- adamio 13y agoThere are signs on these machines that read malfunction voids pay. This ultimately is a malfunction, and is the casino's responsibility is to verify before payout. Exploiting a malfunction to increase payout on an already negotiated win might be fraud, but hacking?
- mrb 13y agoFascinating. This reminds of the true story of a group of friends who won nearly a million dollars by reverse-engineering video poker machines and finding flaws in the pseudo-random number generators used to select random cards. These people have given anonymous interviews and an entire description of their adventure to Kevin Mitnick for his book The Art of Intrusion. They also claim to have never been caught, thanks in part to the fact they stopped exploiting it after they won "enough" money! http://www.amazon.com/Art-Intrusion-Exploits-Intruders-Deceivers/dp/0471782661 http://www.amazon.com/Art-Intrusion-Exploits-Intruders-Decei...
- jjjeffrey 13y agoI really don't like trying to judge this case with analogies to non-electronic gambling. It's not a terrible way to start thinking about the issue, but taken too far it allows someone to come up with almost arbitrary conclusions. Rather, I think it's best to judge this by what a certain outcome would do to the greater picture. (And now to argue for my own interpretation, which happens to use the above argument.) I was in the middle of writing what I thought was a pretty interesting argument, when I realized... Why the hell is the federal government even getting involved in this? I mean, I know why, but it has nothing to do with them. This is (or should be) a case about what constitutes fair play at a casino. Jumping into this and flexing the CFAA just seems beyond ridiculous.
- 205guy 13y agoI like this argument. When looking at the other analogies (ATM giving you too much cash, cashier giving you wrong change, etc), the missing detail is that a casino is sort of a morality-free zone for money when you think about it. The casino is given a license by the state to offer losing odds to customers, thus guaranteeing the casino a (statistical) advantage (and the gov't a cut of the profits). In other words, the casino is allowed to exploit people's greed and credulity that they can beat the odds. And so, if there is no money-morality at a casino, I don't see why casino patrons shouldn't be allowed any exploit of whatever games the casino offers (card counting, bug exploits, etc)--barring of course any threats or injury to people. If the dealer doesn't shuffle the cards or the game has a bug, up to the gambler to take advantage of it until the casion fixes it. So by this reasoning, creating counterfit tokens at a casino would be considered fair-play. I actually don't see that as a problem--it does not affect legal money supplies so why should the feds or states prosecute it. Up to the casino to protect itself and develop secure tokens. I don't see why the feds were involved in that case either (of course, I understand under the current laws). In my hypothetical world, he only thing the government should be regulating are the taxes (on winnings by both sides) and the non-money aspects of casinos, such as ensuring personal safety. It's not allowed for the patron or the casino to threaten or hurt anyone based on any money transactions. Casinos can exclude patrons by refusing to allow them to play, but they can't physically interfere with them.
- mixmastamyk 13y ago> In June, Nestor returned to Pennsylvania, and began working the exploit with a crew. I was rooting for the guy until that sentence. Book'em Danno.
- caf 13y agoIt's fun to speculate how this bug might have come about. My suspicions are that each sub-game maintains separate state about the last game played, but that the wager amount and "has the win been paid" flag variables are global, shared between all games. When the double-or-nothing option is disabled, wins are paid immediately; but when it's enabled, that flag doesn't get set until the user either declines to double up or the result of doubling-up is determined. This leaves a window for the user to switch games, changing the wager in the process, and have the payout recalculated because the win has not been paid yet.
- sehugg 13y agoIf you apply this same logic to coin-operated arcade games, you are breaking the law if you use the Tetris PRNG hack mentioned today (https://news.ycombinator.com/item?id=5640893 https://news.ycombinator.com/item?id=5640893) or even Pac-Man patterns (http://www.math.montana.edu/~hyde/pacman/ http://www.math.montana.edu/~hyde/pacman/) to "exceed your legal access" and extend your play time, thus stealing valuable quarters that would otherwise be spent by non-exploiting players. You might even be able to apply this to games with IAP. Better not get too good at playing Super Monster Candy Time 2, buddy!
- BHSPitMonkey 13y agoThis is obviously (at least it should be obvious) a business matter between the casino and the game vendor, not the user. The way this should have played out is 1) the casino notices the pattern, 2) the casino pulls the machine and scolds the vendor for shipping a bug that hurt their business, and 3) the vendor loses future contracts or resolves the issue in a way that satisfies the casino.
- nathantotten 13y agoI wonder what would happen if the situation were reversed. What if a machine was found to have been paying out less money on winnings than the stated rules. My guess is this would be a non-issue or at worse the casino would face a small fine.
- gcb0 13y agoI don't read wired (tired of their lengthy narratives that always culminate with the subject cast in a holier than thou light) so i will assume this is about someone exploiting a bug left by the cassino on their own systems. Anyone who understand law care to explain how this is different than sitting at a black jack table and the croupier just dealing up all the cards face up?
- sivanmz 13y agoThe entire casino business model relies on bugs in the human mind.
- yoster 13y agoI guess it's OK to steal billions of dollars from tourists, but when the tables are turned, it becomes a crime.
- zupa-hu 13y agoThis is a feature, not a bug. Certainly, the Casino didn't know about it. Imagine you sign a legal document you don't 100% understand (you miss sg). Who cares? You are bound to it. The Casino didn't fully understand the "contract of the machine". Who cares?
- AliAdams 13y agoIf I am a cashier and occasionally accidentally give out more change than I should, surely that is wholly my own problem (a fault of my own process) and not that of the person who takes the money I gave them.
- likeclockwork 13y agoShared mutable state strikes again.
- AjithAntony 13y ago> It takes a lot of video poker play to stumble upon a bug like > that. And Kane, according to his lawyer, played a lot of video > poker. “He’s played more than anyone else in the United > States,” claims Leavitt. “I’m not exaggerating or embellishing. > … In one year he played 12 million dollars worth of video > poker” and lost about a million, he says. “It’s an addiction.” You gotta admire this guy's commitment to quality assurance!