Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

wow, that's some legit cool poo poo. like some kind of movie hacker ring actually happening in real life.

Adbot
ADBOT LOVES YOU

wyoak
Feb 14, 2005

a glass case of emotion

Fallen Rib

Truga posted:

either that or it has something to do with

if you have full debug access to your cpu, hahahaha drm? lol nope.
as if software cracks weren't shady enough, let me plug in this usb key and give the russians debug to my cpu so i save $60 on a game I probably won't like anyway
opsec wins again

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

owns

stealing from casinos is not a crime

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug
they really made some huge opsec mistakes, they only made see-through mesh pockets after one of their guys got popped?

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

pseudorandom name posted:

how do you think they "heavily integrate" it, if not the "cryptographic virtual machine"

I mean the online features in every aspect of the game that do nothing to improve it but somehow justify a constant connection to a central server.

cinci zoo sniper
Mar 15, 2013




https://www.cyberscoop.com/dark-net-markets-bug-bounty-programs/

quote:

Hansa Marketplace, a large anonymous black market which brought in an estimated $3 million in business in the last year, launched a bug bounty program this week with rewards ranging upwards of $10,000 (10 bitcoins) for people who find critical vulnerabilities.

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

this is really smart for pretty much the same reason bug bounties are smart for regular companies

surprised it didn't happen sooner

cinci zoo sniper
Mar 15, 2013




pr0zac posted:

this is really smart for pretty much the same reason bug bounties are smart for regular companies

surprised it didn't happen sooner
just slightly amusing to see a "darknet hacker enterprise" doing something mundane

Midjack
Dec 24, 2007




a similar attack happened in vegas years ago. the attackers bought a slot machine, determined the prng, then had to cruise for a machine in one of a few known states before they could start calling the patterns in. it took a bunch of trips to the pay phone with a synchronized watch and a partner to keep people off the machine while they conditioned it and the window to press the button was like 150 milliseconds. they got away with it for a while and quit before the heat came down on them. i'll look for the references when I get home tonight.

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

cinci zoo sniper posted:

just slightly amusing to see a "darknet hacker enterprise" doing something mundane

"i'm sorry boris, we're gonna have to let you go because our HR department has detected that you've been etching swastikas into your ecstasy shipments and, well, there's just no room for that type of behavior in our organization."

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



ugh some dumbass kid keeps setting up game accounts with my email

im changing their passwords

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Powaqoatse posted:

ugh some dumbass kid keeps setting up game accounts with my email

im changing their passwords

lol i've had the same bozo trying to sign up a 2k sports account with one of my gmails for weeks now

i already killed someone's hollister club cali account for the same crime

cinci zoo sniper
Mar 15, 2013




Powaqoatse posted:

ugh some dumbass kid keeps setting up game accounts with my email

im changing their passwords
:laffo:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Powaqoatse posted:

ugh some dumbass kid keeps setting up game accounts with my email

im changing their passwords

someone signed up my e-mail account for their at&t wireless service

cinci zoo sniper
Mar 15, 2013




http://www.gosugamers.net/dota2/news/43198-heavy-ddos-attacks-gets-virtus-pro-eliminated-from-dac-qualifiers (no technical details)

looks like someone did ddos aimed at knocking a russian dota 2 team out of a tournament qualifiers did grab along a district of a major city down with them

Shame Boy
Mar 2, 2010

cinci zoo sniper posted:

http://www.gosugamers.net/dota2/news/43198-heavy-ddos-attacks-gets-virtus-pro-eliminated-from-dac-qualifiers (no technical details)

looks like someone did ddos aimed at knocking a russian dota 2 team out of a tournament qualifiers did grab along a district of a major city down with them

wasn't there some eve online guy who was like, a russian mobster, and had the power grid cut to a neighboring faction's leader's home town during a big fight or something

cinci zoo sniper
Mar 15, 2013




ate all the Oreos posted:

wasn't there some eve online guy who was like, a russian mobster, and had the power grid cut to a neighboring faction's leader's home town during a big fight or something
yeah. the powergrid was probably just a hosed up transformation box (say, just "corks" stolen from it), since these stories tend to grow legs real quickly. besides that, russian eve has plenty of "real business" poo poo going on - one of my former alliances did quite literally get a headhunter of sorts to track down irl and harass an alliance fleet commander who stole some assets as he left. the most yossec one was another russian alliance, called "white noise". at their peak involvement, they were not shy of ddosing enemy voip servers/jabber/other comms, or just in general trying to hack other alliances websites and poo poo, since as you might imagine - the half of it still is running on 10 year old pirate versions of various forums cms

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Cocoa Crispies posted:

lol i've had the same bozo trying to sign up a 2k sports account with one of my gmails for weeks now

i already killed someone's hollister club cali account for the same crime

its weird how many people apparently dont know their own email address

cinci zoo sniper
Mar 15, 2013




also looks like holidayinn parent group did indeed get hacked - they had spoopy poo poo running on their credit card processing system's servers.

https://threatpost.com/intercontinental-hotels-confirms-credit-card-breach/123575/

vOv
Feb 8, 2014


i'm a bit surprised their PRNG is bad enough you can read the state off from a few dozen spins. wonder if they're using a Mersenne twister.

cinci zoo sniper
Mar 15, 2013




https://arstechnica.com/tech-policy/2017/02/vizio-smart-tvs-tracked-viewers-around-the-clock-without-consent/

quote:

Vizio, one of the world's biggest makers of Smart TVs, is paying $2.2 million to settle charges it collected viewing habits from 11 million devices without the knowledge or consent of the people watching them.

According to a complaint filed Monday by the US Federal Trade Commission, Internet-connected TVs from Vizio contained ACR—short for automated content recognition—software. Without asking for permission, the ACR code captured second-by-second information about the video the TVs displayed. The software then collected other personal information and transmitted it, along with the viewing data, to servers controlled by the manufacturer. Vizio then sold the data to unnamed third-parties for purposes of audience measurement, analysis, and tracking.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Powaqoatse posted:

its weird how many people apparently dont know their own email address

it's more hosed up that services don't do double opt-in

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

vOv posted:

i'm a bit surprised their PRNG is bad enough you can read the state off from a few dozen spins. wonder if they're using a Mersenne twister.

i mean, most slots players pretty much just robotically jab the spin button until they run out of credits or decide the machine is cold so as long as they can achieve the desired payout ratio the RNG probably doesn't need a ton of entropy assuming you can monitor the floor and catch people doing obviously shifty crap.

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.




2.2M? lol did they also make them pinky swear they wouldn't do it again?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://hackerone.com/youporn

:quagmire:

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

vOv
Feb 8, 2014

LeftistMuslimObama posted:

i mean, most slots players pretty much just robotically jab the spin button until they run out of credits or decide the machine is cold so as long as they can achieve the desired payout ratio the RNG probably doesn't need a ton of entropy assuming you can monitor the floor and catch people doing obviously shifty crap.

yeah that's true, it could be seeded from like time plus PID plus one or two other things

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

vOv posted:

yeah that's true, it could be seeded from like time plus PID plus one or two other things

yeah. this is also the reason most bars that have a couple slot machines will only pay you out in credit. they're not equipped to catch cheaters but the incentive to cheat is less if your only prize is 6,000 beers that must be drunk in the bar.

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
why are slot machines using PRNGs at all - just have a microphone, a temperature sensor or some optical sensor - the lower bits should provide entropy enough for the system, it's not like it needs more than a few byts of RNG for every spin anyway

if you're really paranoid, just throw the RNG module into a centralized server or something, the slot machines are probably networked anyway

I'm shocked any gambling commission would ever authorize a slot machine that uses any form of PRNG

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

ymgve posted:

why are slot machines using PRNGs at all - just have a microphone, a temperature sensor or some optical sensor - the lower bits should provide entropy enough for the system, it's not like it needs more than a few byts of RNG for every spin anyway

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

ymgve posted:

why are slot machines using PRNGs at all - just have a microphone, a temperature sensor or some optical sensor - the lower bits should provide entropy enough for the system, it's not like it needs more than a few byts of RNG for every spin anyway

if you're really paranoid, just throw the RNG module into a centralized server or something, the slot machines are probably networked anyway

I'm shocked any gambling commission would ever authorize a slot machine that uses any form of PRNG

i'm like 75% sure that most of the time, outside sources of entropy like that are still run into a PRNG and that's used for whatever random numbers the system needs.

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

ymgve posted:

why are slot machines using PRNGs at all - just have a microphone, a temperature sensor or some optical sensor - the lower bits should provide entropy enough for the system, it's not like it needs more than a few byts of RNG for every spin anyway

if you're really paranoid, just throw the RNG module into a centralized server or something, the slot machines are probably networked anyway

I'm shocked any gambling commission would ever authorize a slot machine that uses any form of PRNG

lol

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer

Good.

gently caress slot machines. They're a loving plague.

(source: I'm from a country that, at least at one point, had more slot machines than any other country in the world)

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

ymgve posted:

why are slot machines using PRNGs at all - just have a microphone, a temperature sensor or some optical sensor - the lower bits should provide entropy enough for the system, it's not like it needs more than a few byts of RNG for every spin anyway

yes. a slot machine that uses sensors that are easily manipulated by its user for random number generation is a safer idea

i like building rngs for fun but this is a terrible idea

https://www.youtube.com/watch?v=7n8LNxGbZbs

may as well use this then

Shaggar
Apr 26, 2006

that's so cool.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
did intel ever ship that actual rng instruction in chips you can buy

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
(all my work for the last year has had reproducibility as a primary goal)

spankmeister
Jun 15, 2008






I built an TRNG based on nuclear decay and the thing with natural sources of entropy is that they're either very slow, or it's fast but the quality of randomness isn't very good. Both things are solvable with seeding a CSPRNG with the output of a TRNG. This is how most of these devices are implemented.

Adbot
ADBOT LOVES YOU

vodkat
Jun 30, 2012



cannot legally be sold as vodka

so in America you can go to jail for pressing a button to accurately :rip:



if they hadn't have taken a plea bargain would that have held up in court? I mean they really didn't do anything other than play the game a little too well.

  • Locked thread