Encryption issues with Cake Poker

Posted by Poker Videos on August 11th, 2010

For those interested in playing online poker, issues of security have typically been over insecure network connections and identity theft. Recently, however, glitches and bugs in sites such as Ultimate Bet and Absolute Poker (both part of the Cereus network) and now Cake Poker have players questioning whether their rolls are safe on any online site. Others have begun to re-raise the question of whether a government or other outside entity should be charged with regulating online gambling.1
In early May of 2010, the Cereus sites were widely outed online by Poker Table Ratings (PTR), a website that found weak security code allowed for players’ hole cards (and possibly their personal information) to be spied on by hackers. The PTR revelation led to swift action by Cereus executives and the problem was fixed within a relatively short time. Among online players, it was widely assumed that all online poker sites would learn from the troubles faced by Cerebus and check over all their own code and encryption. Apparently this assumption was also made at Cake Poker.
On Monday, July 26, 2010, PTR revealed that nearly the same problem with weak, in house made security code existed at Cake Poker (and thusly, at all skins under the site umbrella of Cake, which include Doyle’s Room and Bruce Poker among others). The response was not so swift by Cake, the problem remaining active on their site until August 4 when the SLL was repaired for the original version of Cake’s software. The beta version was corrected on August 5 and additional skins were left possibly the same as before, with the burden on individual players left to check for a .dll file.
Response to this issue has been heated in online poker forums, especially at 2+2 where players repeatedly questioned whether this issue was actually a software problem or could have been insider hacking by Cake’s own programmers. Despite differences of opinion on the how and why, many on the forum stated intent never to play on Cake sites again, likening them to the wounded Cereus sites Ultimate Bet and Absolute Poker. Meanwhile, the majority of posters indicated that they feel confident only in top tier sites like Full Tilt Poker and Poker Stars. Cake’s spokesman, poker professional Lee Jones has taken a lot of heat on the boards and even snapped at PTR on 2+2 claiming that they should have brought the issue to Cake’s attention in private. This suggestion by Jones sparked further outrage that Cake players were never notified about the problem by anyone at Cake. Furthermore, many posters questioned why Cake did not freeze its site while the problem was investigated and fixed (as it had done in February following a pot-shifting problem).2
The pot-shifting bug should have set off alarms at Cake, since their issue was very similar to one at Ultimate Bet,3 which would seem to indicate that the two companies were employing similar buggy software.
Of specific issue were statements on Cake’s website that the fully protective SLL encryption had always been in use on Cake, which has been revealed was not the case, Cake was in fact using their own encoding, an XOL. In his statement after the incident and its fix, Cake spokesman Lee Jones stated:
“One of our programmers, under a schedule crunch, replaced the TwoFish implementation with the XOR encoding. Obviously, that was a bad idea. There was some technical discussion about this change, but unfortunately we didn’t go back and redeploy the TwoFish (or an SSL) encryption in the code. Equally badly, nobody thought to update the website to reflect the fact that the TwoFish implementation had been removed. That was a classic lack of communication between the technical people and the people who maintain the website. Again, no excuses; we dropped the ball.”
Posters on the 2+2 and other forums pointed to this as lying or at least reckless misrepresentation. PTR’s initial report on the issue indeed raises the question as to whether this misrepresentation was in fact malicious.
By checking Pokerscout.com, it is easy to see that Cake Poker is sliding. Poker Scout Stats Though it remains the fourth largest U.S. provider, its numbers have dipped significantly and have continued to suffer during the last six months. Although representatives of Cake Poker, including the aforementioned Lee Jones, have discussed the issue on various poker forums, the Cake Poker security page makes no mention of the problem, which means that new users to the site will have to have done their research in order to know anything about the issue.4
Regardless, online players want to be able to play poker safely, with confidence that the software which deals their cards is free of bugs, glitches, and cheating. These are not unreasonable demands. In fact, they are the very same expectations that players would bring to playing live poker. In the meantime, many posters to online forums have been encouraging online poker regulation and others have been saying that there will never be safe online play- that the only solution is to play your cards in person.

Thread on Two Plus Two
Lee Jones Answer to issues
History

* When the Cake software was first written five years ago, it included an implementation of the TwoFish encryption algorithm in the server-client communication.
* Approximately 18 months ago, the TwoFish code stopped working because of a change in an unrelated part of the client. One of our programmers, under a schedule crunch, replaced the TwoFish implementation with the XOR encoding. Obviously, that was a bad idea. There was some technical discussion about this change, but unfortunately we didn’t go back and redeploy the TwoFish (or an SSL) encryption in the code. Equally badly, nobody thought to update the website to reflect the fact that the TwoFish implementation had been removed. That was a classic lack of communication between the technical people and the people who maintain the website. Again, no excuses; we dropped the ball.
* When the Cereus issue came to light in May, I asked our VP of Software Development (who’d only joined the company five months prior) if our implementation was more secure than that. He asked the programming team and was told that we were more secure than Cereus; that is what he reported back to me. We are still trying to understand exactly what he was told and why. As you might imagine, for the last week, we’ve been much more interested in actually solving the problem than trying to figure out how we got here. We have now started the post-mortem process to completely understand what happened in the first place. We will, I promise, get to the bottom of what happened.
* Once the vulnerability was publicly published, we dropped everything and turned to fixing it. All discussion of the events leading up to the problem was put on hold. As somebody who’s been through that sort of thing before, I completely stand by that decision. Spending time pointing fingers when there’s work to be done achieves nothing.

Current situation

* As I said before, once we became aware of the specific problem, a team of our top people went to work on the problem. They worked exceedingly long hours under the highest pressure imaginable. Not only did they implement the SSL layer in all server-client communications, they also added peer verification to ensure that nobody could mount a man-in-the-middle (MITM) attack. That release was completed Thursday, August 5th.
* We also instituted a full security audit of all aspects of our software. It is still ongoing, but we want to be sure that we have no issues remaining. So far, we’ve not found any other problems.
* While we believe that nobody has lost any money to an exploitation of this vulnerability, we are taking no chances. We are doing a full audit of the top winners since July 26th (when the vulnerability was first reported) and also the largest pots that were played. Once we have completed that audit, we are going to expand the search and investigate back to the time that the TwoFish implementation was removed. Again, I don’t believe we’re going to find any player losses, but we have a responsibility to do the audit. Serge Ravitch (adanthar) is heading up that audit. You may recall that he’s one of the people who uncovered the PotRipper problem; he’s an expert at these things.
* As we complete each phase of the audit, we will turn the hand histories over to Jeff (Yellowsub) Williams, who many of you know. Jeff will have access to whatever data we used for the audit plus whatever else he requests. We will pay him some appropriate amount for his time, but we feel that his stature in the poker community is such that he won’t risk his integrity for the amount of money involved. Jeff will report his findings to the community whenever and however he sees fit.

The Future

Obviously, we don’t want to repeat anything like this. Our VP of Software Development has instituted new procedures and protocols that will ensure a single person can’t go in and change the design of any code without review, oversight, and approval. He is relatively new on the job but I am impressed with his understanding of software design methodology and his commitment to running a tight ship. I believe his new methods will make us a better software company and thus a better poker site.

Questions

Q: Why did you leave the site running once the vulnerability had been disclosed?

A: After discussion with our technical experts, we felt that the actual practical risk was low, taking into account the thorough processes our player security team has in place. Furthermore, we are on heightened security alert. We go over every cash-out carefully anyway (spending many man-hours each day reviewing them), but since we became aware of this situation, we’ve put an extra magnifying glass on the whole process. We intend to make sure that nobody cashes out illicit funds (if there are any). In short, we felt we could adequately manage what risk there was. In retrospect, I believe we were right; we have no reason to believe that anybody was cheated either before or after the vulnerability was made public.

Q: What has happened (or will happen) to the programmer(s) who originally did this and misrepresented the situation to you and others?

A: We believe that’s a personnel matter that should stay within the confines of Cake Poker.

Q: Why did it take you so long for you to provide this information to the public?

A: Two reasons:

1. As I said above, we had our hands full assessing and fixing the technical problem. It was made more complex because we had to release it across all of Cake’s partners as well.
2. There are many stakeholders in this company. The Cake Network has approximately 50 partner sites, many of whom had an opinion on what we should or shouldn’t say. Pursuant to my relationship with Cake, it is not my place to just say whatever I want whenever I want; that’s not how it works. So those decisions – what to say and when – had to be hammered out across many emails, IMs, and phone calls.

Lessons

All of us at Cake have been humbled by this whole experience. It was disturbing not only on a technical and organizational level, but because of the strain it put on our relationship with our customers and the poker community at large. Personally speaking, I have learned some important lessons too and they’ll go forward with me in my career in this business.

We are sorry for the trouble and concern this has caused and hope we can go back to simply running a site which gives people a great place to play poker.

Best regards,
Lee Jones

Cake Poker Cardroom Manager

Carbon Poker
Play Online Poker
Poker Blog Copyright 2008 - 2012 Pokerbloggs.com

Subscribe to PokerBloggs.com

Ultimate Bet Scandal 2

Posted by Poker Videos on May 6th, 2010

Cereus Poker Network security flaw

Pokertableratings.com demonstrates how easy it is to see opponents hole cards or even hijack users accounts. Apparently Cereus is not using SSL or a similar encryption algorithm. Members of the online community Twoplustwo.com are having a field day right now about UB Scandal 2.

SenatorKevin posts:
They were probably curious more than anything. I analyzed Full Tilt’s network traffic a few years ago for such a vulnerability and was pleased to see they had fully encrypted traffic which made me feel more comfortable playing there. I never looked at UB, cause I didn’t play there at the time.

phils08 posts
The problem is that the Cereus Poker network does not use SSL to encrypt their communications; they use a custom form of encryption which is XOR-based. This form of encryption is known to be extremely weak, and in fact their particular implementation makes it particularly simple to decrypt network data due to an easily discoverable key.

In fact, the encryption that the Cereus Network employs isn’t so much encryption as it is encoding. To see how simple it is to decode this data, simply open up your windows calculator and set it on scientific mode. All that is really necessary to decode the data stream is the XOR button .

The requirement for this vulnerability to be exploited is network access. This means that if you are playing on an open wireless network, a cracked wireless network (something which is increasingly simple to do), or on a physical network which has been compromised – an attacker could dump the network traffic and exploit this vulnerability maliciously.

Surely the Cereus Network’s board is meeting right now on how to address this issue. Pokertableratings is again showings it’s value by instigating these matters. I will post as more information comes to light.

Carbon Poker
Play Online Poker

Subscribe to PokerBloggs.com

Haley Hintze exposes Scott Tom of Absolute poker Scandal

Posted by Poker Videos on April 28th, 2010

Disclaimer: The following does not reflect the opinions of PokerBloggs.com.

Haley Hintze, former Editor-in-Chief of PokerNews.com, has been running a series of blogs related to the UltimateBet (now UB.com) cheating scandal. Saturday, she decided to shift her focus away from the UltimateBet scandal and provided her user with what she called evidence that Scott Tom, former head of Absolute Poker, was indeed the person responsible for the cheating scandal involving PotRipper.

She starts off the blog rehashing the whole Absolute Cheating scandal and stating that she has been among the many entities that Scott Tom has threatened with libel suits due to speaking out against him and AP. She has obtained what she considers evidence that proves that Scott Tom may indeed be the force behind the AP scandal and the other involved players may have been pawns in his game.

Scott Tom PotChopper Info

She starts by providing information from the anti-fraud software “ieSnare” that AP purchased from UltimateBet. She shows the information for account PotChopper that clearly points to Scott Tom as the owner.

Potchopper Login Info

Next, she explains how that the software assigns an ID to each new computer that logged onto AP. Tom’s primary computer was assigned “11451887.” Using this ID, the software can show where the account was logged on at. It showed that two unique machines logged onto the site from various location, but always the same two computers.

Potripper Login Info

Next, she stated that his pc’s ID was linked to several of the known cheating accounts, including PotRipper, the account that brought the cheating scandal to the forefront. If you look at the image following, you will see that the device and NUID sets match those for logins from PotChopper.

Graycat Login Info

Double Drag Login Info

Next, she produced an image of what she said was the “Graycat” account that was also involved in the cheating scandal. As you can see from the image, the ID and NUID again matches other accounts. She also provided the same information for the “Doubledrag” account.

Scott Tom transaction info

Hintze then goes on to claim that Scott Tom was indeed behind the computer and using these accounts and not being “hacked” as he had claimed. She then produced evidence of several large deposits and a substantial withdrawal from Scott Tom’s account. Notice that he received a transfer for $70,000 from Double Drag and the account was immediately black listed. However, the account was then cleared within less than two hours and according to Hintze, this was based on directives from upper management which she stated was Scott Tom and others.

After winning a huge tourney on September 13th, 2007, Hintze indicated that Tom chip dumped a large portion of his “winnings” to other cheater accounts. After making the $70,000 withdrawal, she claims he then blacklisted the account. She states that the same was done to other accounts so that the majority of money was taken off the site.

Potripper Customer Service

Hintze then points out that the cheating accounts were flagged so that customer service would not close the account. She provided an image that shows the PotRipper account with the comment “Please do not close this account for any reason. Issues please consult with Brent, Adrian or Nolan.” Most of the pertinent information has been removed but she believes that the information was a “college buddy” he was using to launder money.

The allegations made by Hintze have not been proven by any other source as of the time of the writing of this article. Hintze did not reveal her sources. Should this prove to be true, it would raise a new set of questions and confirm the beliefs of many conspiracy theorists that, like Hintze, believed that Scott Tom was the head of the AP cheating scandal all along. Hintze says that she has more to publish on this matter at a future date so this isn’t the last that we will hear on this story.

- James Guill

Carbon Poker
Play Online Poker

Subscribe to PokerBloggs.com

Jason Ho Scam

Posted by Poker Videos on January 31st, 2010

The poker coaching world just had a big shake up, and the story is going crazy in all the major forums and poker blogs. Jason Ho was a poker coach at the popular training site Stox Poker, and recent stories came to light that he was a professional scammer. Although he was somewhat knowledgeable about poker, apparently he was a losing players, and did not win $1 million or “solve plo cap limit Omaha”. It seems Jason Ho had a professional ponzi scheme in effect, and was using his credentials at Stox to pull it off.

Jason Ho is an eccentric individual to say the least, even for the poker scene. He is an expert at self promotion, whether he looks like an idiot or not. His scam netted him over 100k for the poker economy, so some people were obviously fooled. He would post pics of weird photo shoots with make up on and a hot Asian model named “Jade”. Unsuspecting poker players would join his “camp Macao” and pay up to 1k per hour in some cases.

Jason played under these accounts :
zenconcept
zen888
jadebling
babiekwai
lilbebi

Jason was so cocky about his scamming abilities he would brag about it on Oriental Community forums:
jason ho forum post

Not only would losing players seek his coaching, but winning players would too. They would go from winning 100k a year to losing months later. He would also get them to send him money to clear bonuses. Jason would also multi account by playing under their screen names. He failed to show up for 50% of the days of these “Macao” session, and when he was there he would berate his students. When they would lose, he would blame it on variance and or that they did not follow his advice.

A user who was looking up his websites, had a trojan virus infect their computer within minutes:
jade website
So be very cautious when visiting his blogspots.

Jason Ho Photo shoots:
jason ho 4

Jason Ho photo 3
Jade

Jason Ho photo 2
Jason Ho and Jade

Jason Ho photo 1
Some threads paid for by the poker community

Jason Ho also has several liens put on him in UK from some other scam.

His Camp Macao being mocked on Poker Tube:

Jim Varmin of Stox Poker took immediate action to remedy the situation. He staktes on Two Plus Two:

Conclusion

We believe that StoxPoker has a responsibility to reimburse coaching fees for those that were introduced to Jason through StoxPoker and had a bad experience using him as a private coach.

I have been forthright in saying that:
• Jason was not vetted as other StoxPoker coaches have been. I let down the StoxPoker community and our other coaches in that regard. Coaches since Q4 of 2008 have all been subject to our formal QA process previously described before their first video is posted.

• StoxPoker could have acted as a 3rd party escrow agent for all funds involving coaching arrangements. That is already being implemented.
For the reasons previously mentioned in this statement, members that were introduced to Jason through StoxPoker and had a bad experience with private coaching from him will be reimbursed. However, there is shared accountability for those that continued to make payments to Jason for coaching. Therefore, we have taken this into consideration in policy.

We will reimburse for 100% of the first two payments for any coaching services with Jason and 50% of a 3rd. We will not reimburse for any payments after the 3rd.
Jason Ho Two Plus Two thread

So it looks like Stox cam back big, and is reimbursing people for coaching fees paid to them. Jason is still defending himself in Two Plus Two under the name : code7654321 .

Carbon Poker
Play Online Poker

Subscribe to PokerBloggs.com


Copyright © 2007 Poker Blog. All rights reserved.