Skip to content

Comment on How Primedice was exploited for $1M in Bitcoinparent

Comments

That doesn't make much sense.

If they have a legit exploit, then kicking them will just make them create a new account. Or perhaps distribute the +EV betting over a bunch of accounts so that it was much harder to detect.

If they don't have an exploit, then you want them to keep betting and lose. And if you have no real basis for kicking them, then, what, your casino just doesn't pay out people that win big?

The casino's only real option here was to discover the exploit.

No, pay him out, but just don't let anyone bets that way continue betting. Betting that rapidly has to be a huge flag for even the dimmest of sys admins.

What is "bets that way"? It seems like initially all they knew was that some accounts were unusually active (betting every second, for hours) and implausibly lucky. They saw the flags, they just didn't know any useful way to react (which is also incompetence, but IMO different than what you said.) (I'm assuming a dumb rate-limiting solution would be off the table, as it would be ineffective at stopping the attack, and/or lose money as other players stop betting when they hit a limit.)

What is "bets that way"?

I dunno, maybe anyone who is clearly automated (ie, betting every second for hours) and probably cheating (ie, implausibly lucky)?

It seems like initially all they knew was that some accounts were unusually active (betting every second, for hours) and implausibly lucky.

Exactly.

They saw the flags, they just didn't know any useful way to react

The useful way to react would be to not let them continue betting.

But how do you reliably identify one anonymous entity? Like I said, putting a rate limit is going to turn away legitimate bettors (if too strict) and not make much of a dent in the attacker's profits (if not strict enough). Doing an "implausibly lucky" check is going to piss off legitimately lucky winners who might have given you more money (if the limit is too conservative), and/or not hurt the attacker much. Any per-account limits can be circumvented by the attacker making more.

Maybe they took some measures like this that they didn't tell us about. With that much money at stake, maybe "do something, anything" does make sense -- my point was there's no way for them to ultimately prevail until they understood/addressed the root issue, and knee-jerk responses could backfire.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.