Computerized Betting System Proves Vulnerable 310
count3r writes "A front page article in today's New York Times reports that an employee of Autotote has been fired for (allegedly) hacking the system responsible for 65% of all horseracing bets in North America. The caper, if it is indeed a caper, resulted in a series of six bets that paid a total of $3,000,000 in last Saturday's Breeders' Cup."
dumbass. (Score:5, Interesting)
Re:dumbass. (Score:2)
On a side note, their are so many Office Space jokes running through my head right now that they're getting stuck, like two fat guys trying to go through an open door at the same time.
Re:dumbass. (Score:2)
Re:dumbass. (Score:5, Insightful)
As a bit of background regarding this, these guys didn't transfer from one bank account to another, or some other thing that's caught "in the books": One purportedly made an electronic bet, and the other altered the electronic bet after the fact to match the winners. It really isn't that ridiculous of a scam as people do win every now and then. It isn't entirely inconceivable that someone one.
Having said that, it is the duty of responsibility of the operators to exercise due diligence, and truly not trust anyone: i.e. all databases have multiple layers including audit logs, in this case catching his transaction as it occurs for future analysis. In this case I presume that exactly that happened, as they obviously caught him.
"Wasn't that dumb"?? (Score:2)
Once you've done that, putting a flashing marquee on your front lawn that reads "cheating the OTB out of millions of dollars is my very smart, infallible plan" is officially redundant.
Re:"Wasn't that dumb"?? (Score:5, Informative)
It's still confusing no matter how many times I read it, but it sounds like he made six identical bets, when the point of the pick-six ticket is to place several different bets on one ticket. Anyone who can clarify this a bit more, please do.
Re:dumbass. (Score:5, Informative)
A lopsided payout will be noticed, not because someone one, people always win in a properly booked race/game/whatever, it is that the payout was disproportionate to the take.
If you make your book properly, you aren't making money off of people losing their bets, you make money off of the vig. Your payouts and take should roughly be equal if you did your books right.
A horse isn't a 100:1 long shot because the book maker thinks its a bad horse. The horse is a 100:1 long shot, because off all the betting dollars, only 1 out of every 100 dollars was bet on that horse.
The only way the house wins is to avoid making stupid bets. How does the house avoid making stupid bets? By nt betting. If I make sure that the other 99 dollars are going to cover your 1 dollar bet, and I collect the 10% vig from the losers, I make money, and don't have to worry about the long shot.
Legalized horse betting does the same thing, except since they can't charge a vig to the losers, they don't make a 100% payout. That way, no matter who wins, they have made sure they can cover the bets, and still make a profit. In this scenerio, the winner pays the vig in the shape of the odds aren't as high as they should have been, the winner didn't win as much as was proportionally alloted to him.
The reason why this was a dumb scheme, and the reason why they got caught is pure math. The track paid out more money then they took in, and immediately knew something was amiss. If the systems worked properly, that can't happen. Long shots hit all the time, even 100:1 long shots, but if your computer system adjusted the odds according to the bets made before post, you won't lose money.
The fact that they changed the bet afterward means that the odds were wrong. Of course most people don't realize these subtelties to book making, so probably thought it wasn't a dumb mistake.
Re:dumbass. (Score:2, Insightful)
Obviously you understand horse racing. Having said that, I question your claim that it's entirely pool driven. Most tracks offer multiple win wins that are many multiples the win for a single race. i.e. If this guy changed a single $1 bet for #7 in the 3rd to be a $10000000 bet, then that seems obvious. If, on the other hand, he changed a $1 bet (so $6) for #7 in the 1st, #2 in the 2nd, #4 in the 3rd, etc, for $6 races, and the track offers a mega win for six successive wins, the difference that his bets make in the win is miniscule.
Re:dumbass. (Score:3, Informative)
No, the win did not pay out more than the track earned. Each winning ticket paid $428,392 from a pool of $4,569,515, which means that there were probably 8 or 9 winning tickets in total, nationwide. The guy they are investigating had 6 of them.
Having 6 of only 9 winning tickets is obviously unusual. His betting strategy is even more unusual... making single selections for 4 races, then "wheeling" then entire field for the last 2, which means if the first four come in, he's guaranteed to win. Combined with the "flaw" in the system which doesn't report the ticket to the central database until after the fourth race, this is an obvious red flag. Finally, making the same bet 6 times is simply stupid. It's the same as buying 6 lottery tickets with all of the same numbers... the only justification is to increase your percentage of the winner's pool if you KNOW you are going to win.
Think of recent Powerball lottery wins... if they announce there were 6 winners, and one guy shows up with 4 of the winning tickets, it's going to raise eyebrows.
Had this guy never made these wagers, most likely there would have been 2 legit winners, each of whom would have won about $1.8 million (or maybe 3 winners each getting $1.2 mil). Instead, since there were a lot more winning tickets, the payout on each was reduced to only $428 thousand.
Again, the track didn't lose anything, and if they disqualify his tickets, the money will get paid to the legit winners. That's how pari-mutual wagering works... the total pool is calculated, the house percenatge is taken out, and everything left is split among the winning tickets. When there are 9 winning tickets, each one gets paid less than if there were 3 winning tickets. The racetrack is unaffected. The legitimate winners are the victims.
Re:dumbass. (Score:2)
Maybe because it's not a simple matter of hacking into the system to change a ticket, assuming he actually did that?
Re:dumbass. (Score:3, Interesting)
I'm sure a smaller amount would not have been as obvious and he may have been able to sustain it. Of course these horse cheats in the story could have started small years ago and have just now got caught.
What's really dumb is ... (Score:2)
Charge the company that programmed the betting system too, why don't you!
Re:From the horse's mouth (Score:3, Informative)
Pallidum would have solved this. (Score:5, Funny)
DRM will be our savior.....
Oh wait, he required that kind of access to do his job? So DRM wouldn't have helped. What do you mean that most hacks are inside jobs?
What happened to the old days (Score:5, Funny)
No registration (Score:4, Informative)
Re:No registration (Score:3, Insightful)
Re:No registration (Score:3, Insightful)
(Or perhaps you don't mean that, in which case I apologise. But I'm getting sick of seeing people here with the attitude, "We're all for 'Free'. And look, we can just take shit! Stick it to the man! Yeah!")
Re:No registration (Score:2)
they make tons of money off advertising - and requiring readers to register for their stories is rediculous.
I cant stand all the people who try to argue for the registration on a site that is just going to give you a story that is available from other sources without such restrictions.
Do you pay for a subscription to slashdot? i doubt it - and if it was required from the first day, i doubt you would even be here....
News is information that is meant to be free. If I want opinionated biased *stories* I will pay for it. If I want news about whats happening in the world around me - I will get it from traditional news sources with a very long history of subsidizing the cost of production through advertising. The model has been like that for a very long time - and by the amounts that most major news anchors make, I dont think they are hurting - or even would be hurting from our wanting of free access to the "news" they are offering.
Re:No registration (Score:2)
Re:No registration (Score:2)
Slashdot itself requires a free registration to post even off-topic comments like that one, so besides being needlessly elitist, it would be just a bit hypocritical.
Re:No registration (Score:2)
Go through the free registration. Is your time really that valuable? You're reading Slashdot, aren't you?
Tell them that you're a 90 year old high school dropout millionaire from Afganistan (which is usually the first country on the alphabatized list). Give your email address as Fake@AOL.com (might as well waste some of their CPU time while you're at it).
-B
Re:No registration (Score:2)
you can easily register as a 123-year-old
polynesian software engineer, earning 400,000
a year. (If you are one, pick another
example
Re:No registration (Score:5, Interesting)
Re:No registration (Score:5, Informative)
http://www.nytimes.com/2002/10/29/sports/others
Linked to Partner "Slashdot" [nytimes.com]
Re:No registration (Score:3, Interesting)
Another one (Score:2)
Well, they do want some registration stuff, but nothing identifiable to you.
Not too smart. (Score:3, Insightful)
I will never understand how people come up with good, well thought out crime plans, and then totally screw up the execution by rushing things or bring too much attention to the project. Just dumb.
Re:Not too smart. (Score:4, Funny)
Well, the brilliant plan to milk billions from the Federal Reserve Bank in Denver is still going strong, undiscovered.
Re:Not too smart. (Score:2)
So? (Score:4, Insightful)
Someone will always find a way to steal and no matter how good your security, when you have the human element on the inside, you are vulnerable. That's why auditing to detect theft is as important as securing against it.
This wouldn't have happened when the mob ran it! (Score:5, Funny)
Re:This wouldn't have happened when the mob ran it (Score:4, Funny)
Much stronger disincentive tho (Score:2)
Re:This wouldn't have happened when the mob ran it (Score:2)
No way! (Score:5, Funny)
Re:No way! (Score:2)
This isn't "online betting." Autotote is the electronic system used to place bets all across the country. You could be at an OTB (off-track-betting) center placing a bet on a race getting ready to run at Saratoga in a few seconds.
And it's not like people normally get screwed out of their winnings. This guy is getting put on hold because of suspicious circumstances. It has nothing to do with how he placed the bet or betting "online."
What they did... (Score:2)
Tor
I used to write betting software (Score:5, Interesting)
I never put any backdoor code into anything I submitted but it would have been very easy to do so. We had well over 300,000 lines of code and very little of it was audited. The only problem would have been getting the backdoor in without other programmers noticing as everyone was responsible for different areas. Still, I know it could have been done, I can picture exactly what it would have taken to do so.
Would it have been noticed? Possibly eventually, though I have my doubts. Apparently, there was a bug in our code for one of the complex bet types. It ended up _always_ overpaying a specific complex winning bet type by $1. That is, it always rounded up to the next dollar instead of down and this bug went undetected for YEARS.
All the code was written in VB and we worked crazy amounts of overtime ALL the time. Additionally, the 'business experts' could never get their act in gear and agree to how things should work. I ended up resigning my position.
Re:I used to write betting software (Score:5, Interesting)
I'm sure that had the company tried to screw over one of the bigger casinos that they'd have been caught. (And depending upon the casino probably taken care of independently from the police) However so long as regular people are getting screwed, they don't care.
Same thing with gas stations. Once again I remember a scheme that extra charged gas slightly using computers. Nothing but a few cents on every fillup. But it added up. Once again more the company themselves. But how hard would it have been for an employee to do it?
The only thing that keeps these schemes for working for individual employees is the cost/danger ratio. These schemes are only worth the risk if you make a fair amount of money. But to make a fair amount of money you have to get that check from the company which is then noticable by the company auditors. If the "checks" or "expense" is spread out over thousands of people, the auditors are far less likely to discover it. But by the same measure you are far less likely to be able to make use of the money.
Re:I used to write betting software (Score:4, Interesting)
I recall seeing a story about a programmer who reversed engineered the pseudo-random number generator used in Keno games. The impression I got was that it was a clean-room solution, and yet he was arrested for fraud anyway. Needless to say, I disagreed with the notion that his act was illegal (assuming it was clean room).
Re:I used to write betting software (Score:3, Informative)
Here's the story [ncl.ac.uk] from "The Risks Digest" ("Forum on Risks to the Public in Computers and Related Systems").
Basicly, they caught the guy, and then released him and even gave him the money back with interest.
The "source" of the problem? A missing clock that was supposed to seed the random number generator. Thus, upon rebooting (every morning I suppose), the same number sequence would be generated as the seed would be the same...
Greg
Re:I used to write betting software (Score:2)
Re:I used to write betting software (Score:2)
Re:I used to write betting software (Score:5, Interesting)
A long time ago I used to write software for computerized gambling games, such as draw poker. One of the features of the software was being able to dial in a certain payback percentage. The way it worked was that when it drew the final hand (after the cards were held), it would decide on a random basis to redraw the hand if it was a winner. If it was paying out too much, it would gradually redraw the hand more often until it was back to the right payback.
Anyway, one of the problems we had was that our payout amount field was only 4 digits for a maximum of 9999 coins. The problem was that you had the option to play up to 50 coins at a time, and the highest payout odds were 500 to 1. So management had me make the machine NEVER pay out the big winner if you bet 20 coins or more to avoid the problem.
The latter was probably illegal, but this company was pretty shady. I didn't work there for very long, and they went bankrupt not long after.
I still look at the machines in Vegas with suspicion, though. :)
Re:I used to write betting software (Score:2)
The government agencies these days also supply the random number generator to all manufacturers, and if the source code was displayed on the slot machines to every patron, and you had a BeoWolf cluster of G4's, it would take you 10^8 years to figure out the next RNG outcome, assuming you can hit the spin button with an accuracy of 250 micro seconds, which is when the RNG is reseeded.
Re:I used to write betting software (Score:2)
Re:I used to write betting software (Score:2)
the company i'm with now works exactly the same way. i should have resigned years ago, but stuck it out. now we've finally got an owner who knows what the hell is going on, so my stock options might be the last remaining ones out of the 20th century to be worth more than toilet paper.
In Other News... (Score:5, Funny)
I'm only going bet on something trustworthy: (Score:5, Funny)
Picking 4 Horses (Score:3, Interesting)
And, I wonder how often this bet hits? Technically, the bet was really picking the winner or 4 straight races, plus betting on every horse in next 2. I won a trifecta once that paid a cool grand. To think, if I'd only tried for one more......
If they're guilty, they're idiots.
This is not the way to go. (Score:4, Informative)
It may not get you $3M, but they won't have to work anymore, and they don't get put in FPMA prison.
Re:This is not the way to go. (Score:2)
Not really hacking; still a problem... (Score:5, Interesting)
In any case, I'm surprised that ANYONE has the access to modify bets. Shouldn't that info be encrypted or protected or something, kind of like how your Bank's customer service rep can't look up your pin, but can only reset it to a new pin?
Re:Not really hacking; still a problem... (Score:2)
Yeah, but then how would the employees be able to go in and create winning tickets after the fact?
I mean, that's a perk for working at autotote, like stock options.
Re: (Score:3, Interesting)
Re:Not really hacking; still a problem... (Score:2)
There are some ways in which it could help. For example, imagine a two machine setup where machine1 accepts bets and cryptographically signs them (including a timestamp) using a private key known only by machine1. Machine1 then passes the bet off to machine2 for a second timestap/signature and longer storage.
Under this system, an attacker would have to subvert both machines in order to place a retroactive bet. If the attacker only subverts machine1, then the machine2 timestamp won't be correct for a bet supposedly placed in the past. If the attacker only subverts machine2, then the stored machine1 signature will be wrong.
Of course to make the system viable, you have to implement policies to make it difficult for a single person to get access to both machines. If someone's responsible for uploading the final betting data to the track, for example, they'd only get access to machine2.
It's not a panacea, and it also doesn't help that they're holding the bets until 4 of the races are done, but it does increase the difficulty of subverting the system if it's properly implemented.
VLT Backdoors? (Score:5, Interesting)
Anybody ever heard of anything like this happening in real life? As an earlier poster said, if you kept your take down to a couple thousand a week, I think it would be pretty unlikely you'd get caught.
Re:VLT Backdoors? (Score:3, Interesting)
There have been a lot of very smart scams that were caught. It makes you wonder how many extremely smart scams were never caught. I remember watching a show about that stuff, and there was a security consultant with this quote: "A casino is the only place in the world where you can steal millions of dollars and if you do it right, no one ever notices that it's missing."
Re:VLT Backdoors? (Score:2, Funny)
Can't secure gambling, eh? (Score:2, Insightful)
Another computerized wagering event coming up: (Score:3, Funny)
Fortunately, all of those systems are closed, so I'm sure that security was motto number 1.
Of course, motto number 2 was "Ignore motto number 1".
Nitpick / Details (Score:2, Insightful)
Was was reading this yesterday, it's actually interesting. It wasn't six bets, it was one bet on six consecutive races (called a Pick 6, apparently). The ticket cost over a grand just to purchase.
Apparently, the winning ticket including the first 4 race winners, followed by picking every horse in the field for the 5th and 6th races. This was suspicious because the betting management company allows the bets to be submitted during simulcasting through the end of the 4th race to prevent system congestion, according to the article.
The theory is that the employee submitted a fixed bet at the end of the 4th race. The ticketholder himself, apparently unrelated to the employee who is under investigation for fraud, claims that he is innocent, and is telling the company to put up some evidence or give him his 3 mils.
I dunno about you, but I do detect a strong odor of fish. On the other hand, if the lottery hit for this guy and he is legit, more power to him.
Just wait... (Score:2, Insightful)
Fortunately, such a thing could never happen with electronic voting machines.
Right?
Things you don't do (Score:5, Funny)
Tug on Superman's cape.
Spit into the wind.
Rip off the NY mafia to the tune of $3,000,000.
Obligatory Karma Whoring...The NYT Article. (Score:2, Informative)
By JOE DRAPE
As the authorities investigated whether an exotic bet worth $3 million on last Saturday's Breeders' Cup horse races was rigged, the company that processed the wager said yesterday that it had fired a "rogue software engineer" who exploited a weakness in its system.
The company, Scientific Games Corporation of New York, said it had turned over the employee's name and evidence of potential wrongdoing to the state police and state wagering officials.
The employee attended Drexel University in Philadelphia with the winner of the bet, racing officials and a state investigator said.
The head of the company, Lorne Weil, said the worker had the access and know-how to breach the system run by the company's subsidiary Autotote, which processes 65 percent of racing wagers in North America.
Industry and law enforcement officials said that the F.B.I. had joined the police and the New York State Racing and Wagering Board in the inquiry of the wager, known as a pick six, which requires bettors to pick winners in six straight races. Payoff on the bet, made through the Catskill Off-Track Betting hub by telephone from Baltimore, has been held up.
Investigators are also looking into whether there have been questionable payoffs at other tracks. "This goes beyond one afternoon and the East Coast," said an investigator, speaking on condition of anonymity.
Though Mr. Weil tried to calm investors in his conference call yesterday, his disclosures pointed up the vulnerability of the $14.5 billion-a-year betting industry for which consumer confidence is crucial.
As racing has become more reliant on off-track and telephone betting, it is also depending more on a network of computers that link tracks and off-track sites. If the systems are proved flawed, or susceptible to manipulation, it could scare off bettors worried about the integrity of the process.
"There needs to be total review of the system so everyone can feel good and see that these things are not widespread," said Bill Nader, a New York Racing Association vice president. "Without integrity in the way a wager is processed, we don't have a sport."
The case in question involves the pick six bet on the last six races of the Breeders' Cup, horse racing's season-ending championship. The entire winning pool was held by Derrick Davis, a 29-year-old Maryland man who made the bets by phone.
Investigators are looking into whether the computer system was manipulated so that a bet made after several races had been run would appear to have been made beforehand.
Though Mr. Weil did not name the dismissed employee, the state investigator and racing officials identified him as Chris Harn, 29, who worked in Autotote's offices in Newark, Del.
Mr. Davis owns a Baltimore-based computer networking business, Utopian Networks Inc., but said yesterday that he was a knowledgeable bettor whose winning tickets were legitimate. "I didn't do anything wrong here," he said, refusing to elaborate and referring questions to his Baltimore lawyer, Steven A. Allen. Mr. Allen said his client was cooperating with the authorities and had nothing to hide.
"He is caught in the middle of a maelstrom," Mr. Allen said. "As far as he's concerned, he made a legitimate bet. The race was run, and he won, and he should have received his payoff. And that should have been the end of it. Now, instead, there's an investigation, people are making a variety of wild accusations, and his reputation is being sullied for no good reason."
Thomas Davis, Derrick's father, said his son grew up in Baltimore and attended engineering school in Pennsylvania, but would not be more specific. "I just think it's like the equivalent of his hitting the lottery," the father said. "I know in the bottom of my heart that it's a legitimate bet."
Stacy Clifford, a spokeswoman for the state wagering board, would not comment on the personnel involved in the investigation or its progress.
"The board routinely involves other organizations in its investigations and will involve law enforcement if it feels appropriate," she said. "They fired this person in connection with what happened Saturday, and since we're investigating what happened Saturday, we're certainly looking into it."
What started the investigation last Sunday was the configuration of the winning tickets and that they belonged to one bettor, Mr. Davis, who called his bets in by phone to the Catskill OTB hub, one of five regional corporations that, with New York City OTB, handle off-track bets in New York.
The winning tickets featured "singles," or races with only one horse selected, in the first four legs of the ticket, and then every horse in the final two races. On a $2 ticket, those combinations and strategy cost $192.
Mr. Davis bet a $12 pick-six ticket, or played that exact combination six separate times, costing him $1,152. It was a highly unusual strategy for betting the pick six -- horseplayers like to cover as many combinations as possible -- and the configuration raised suspicions of New York Racing Association officials, who alerted Breeders' Cup Ltd. and the state wagering board.
Mr. Davis had opened the Catskill OTB account within two weeks of the Breeders' Cup, had deposited money on five occasions -- four increments of $500 and one of $250 -- but had not made a bet until that pick six, according to investigative sources.
The six winning tickets were each worth $428,392. In addition, by including every horse in the last two races, the bettor collected 108 of the 186 consolation payoffs for hitting five of six winners; each consolation ticket was worth $4,606.20.
After an initial review on Monday, officials for Autotote and Catskill OTB said the tickets were recorded about 20 minutes before the first leg and appeared legitimate. But after further review, Mr. Weil said, the company determined that the fired employee had taken advantage of a weakness in the processing of bets.
While the tickets were logged and totaled at satellite sites such as Catskill OTB, they were not transferred to the host site, Arlington Park outside Chicago, until after the fifth race when the exact bets were verified. In this state of limbo, Mr. Weil said, the employee, who had the password to the data system, was able to alter the ticket after the results of the first four races of the pick six were known.
When Scientific Games announced the firing, trading in its stock was suspended on Nasdaq for more than 20 minutes. The stock closed at $7.62, down 57 cents. Mr. Weil maintained he was confident Autotote's systems were impenetrable to outside hackers.
"I think people see this for what it is -- a rogue individual bound and determined to exploit the only weak link we see in the system so far," he said.
Re:Obligatory Karma Whoring...The NYT Article. (Score:2)
NY Times only asks that you spend 30 seconds of your life to make a login. They don't spam you and they won't sell your e-mail. Support the media when they create something you're actually interested in. CLICK ON IT... or just go to the Google link. Or DON'T READ IT!
An interesting question: Why can't Slashdot get a partner link like Google has.
Feel free, to mod ME down with the above post.
This is pretty funny... (Score:2)
Anyone who's tried this hates it... (Score:5, Insightful)
The fact is that implementing a gaming system is a nightmare, be it on the ground or in the air. IMHO, quite a bit more difficult than point of sale or banking systems. In addition to being secure, it's gotta be completely fail safe (so if a passenger's terminal goes down seconds after a jackpot he won't loose his winnings and take it out on the cabin crew). Also, it's going to be transaction heavy - hundreds of smaller, individual bets over a gambling session as opposed to, say, a higher end credit card transaction every minute at a department store cash register. If you add in the fact that gambling is a potentially addictive activity that piques the interest of organized crime, you have a recipe for any disaffected insider to slip in hacks and back doors.
On the whole, I'm not surprised that someone corrupted a gambling system. I'm just surprised that this doesn't make the newspaper more often.
High-risk, high reward (Score:2)
That being said, I am sure it is just a matter of time before it is commonplace. The payoff is just too high, and the airlines are just too hard pressed to let go of a profit opportunity like this.
Tor
Re:Anyone who's tried this hates it... (Score:5, Insightful)
(*SIGH*)
No racism intended - it's just a fact that Pacific Rim airlines have been primary movers in in flight gaming. Gambling is more accepted there than in the West, with less stigma attached. No Asian businessman expects to get dirty looks from another passenger if he drops a bundle of his own money on blackjack, but I bet you (yes, lame pun intended) that you'd see a lot of that on any US, Canadian, or European carrier (exception: I know Swissair has at least tried gaming. 'Don't know if it's still going strong). And when you think of it, they've got a point - what business is it of anyone how someone looses their cash?
Also, the U.S. flight attendants' unions fight airborne gaming tooth and nail. As my cousin, an attendant for Delta told me "So now they'll expect us to deal with a guy who's both drunk *and* has lost $500?!"
Again, this is just a simple observation of cultural differences. The fact is that most of our Asian customers (the arilines) don't understand why we regulate gaimng so strongly in the U.S. Once we pitch the technical (and regulatory) challnanges, though, they usually decide to request different features in lieu of gaming.
Re:Anyone who's tried this hates it... (Score:2)
comment about race-relations courses... Lighten
up...
Software is insecure (Score:4, Informative)
Just so you know.
What's next? (Score:2, Funny)
-B
Vulnerable, Period (Score:5, Insightful)
The Breeder's Cup incident was an inside job! There have been numerous Casino incidents where employees have tried to scam their employers. A security system is only as good as the people with whom the system is entrusted. This is true for physical security as well as computer security.
Lastly, criminals are not, inherently, stupid. It only seems like that as the stupid ones are the ones that usually get caught. Borrowing from Kaiser Sousay (Kevin Spacey) in Usual Suspects : the greatest trick a master criminal has ever pulled is convincing the world that a crime has not been committed.
Re:Vulnerable, Period (Score:2)
Doh, and thanks for spoiling the movie for anyone who might not have seen it.
Re:(-1, Offtopic) (Score:2)
Plus, yes, the attribution at the time of reading wouldn't mean anything to those reading it. But as soon as they started watching the movie they'd immediately would make the connection, especially since KS is such a big star now (unless of course their short term memory is like mine, in which case they'd probably forget they read it, what movie are we talking about again?)
Re:(-1, Offtopic) (Score:2)
Wake up with a horse's head next to him.... (Score:2)
He may very well wake up one morning with a horse's head in his bed.
Or more probably, wake up to that particular clammy feeling one gets from freshly mixed cement around one's body....
Hmm...Next week's headline? (Score:3, Funny)
I have friends who work (and worked) there... (Score:5, Interesting)
1) They fired the QA department due to cutbacks over a year ago.
2) There is no "Production Control" group. The same people who develop the apps support them (with little to no oversight). They have never had a way of preventing this type of fix.
He needn't worry about the authorities... (Score:3, Funny)
I see evidence that this guy is pretty lame - he's dumb enough to screw up a good scam his first time out by shooting for the moon. We can't assume that a novice is the first person to find this scam, but AutoTote indicates he's the first to be caught.
I'll wager dollars to doughnuts that he's just closed the loop on a lucrative betting system being utilized by any number of "organized" gamblers, and will be hearing from a guy named Vito in the near future.
Why it was so suspicious (Score:2)
In the Pick-6 scheme, you get a jumbo prize if you pick all 6 winners correctly.
What this guy did was buy a number of bets - each for $12 (that's probably all he had available). In each of the bets, the winners of the first 4 races were the same and he chose every possible combination for the winners of the last 2 races. Sounds like he knew who was winning the first 4 races and bet on every possible outcome for the last 2.
Bad design... (Score:2)
Go and handicapping similar. (Score:2, Interesting)
Similar case with bingo (Score:2, Interesting)
Is there some development methodology or practice a company can implement to protect itself from "rogue" programmers like this? The NSA / CIA / FBI / Pentagon must have software that they want to guarantee is uncompromised. How do they do it?
Re:I don't mind (Score:2)
We are all someones child after all
Stealing from common criminals? (Score:2, Insightful)
Re:Computerized betting is always vulnerable (Score:2)
Re:Computerized betting is always vulnerable (Score:2)
It's pretty easy to get a (nearly) random seed these days. Just hash the current time to the microsecond with the temperature ouside the building with MSFT's current stock price with the number of comments in the most recent Slashdot story . . . you get the idea. This is for all practical purposes a solved problem.
Re:Computerized betting is always vulnerable (Score:2)
Re:Computerized betting is always vulnerable (Score:2)
You bring up an interesting point about the sigmoid denominator but I am afraid that it too would suffer from the same flaw, namely the Pootang Conjecture, which state those who sound smart indeed are.
Re:Computerized betting is always vulnerable (Score:4, Insightful)
Re:This just goes to show (Score:3, Insightful)
It can be just as entertaining to spend $10 or $20 playing video poker as it was spending the same amount playing arcade games when I was younger. Just realize when you go in that you have a set amount to spend, and don't go nuts.
If a person has a problem with gambling, just as with alcohol or drugs, it's up to them to recognize it and get help. It's called "personal responsibility". Don't go trying to take my fun away because your neighbor couldn't control himself.
Re:What operating system was used? (Score:2)
Re:What operating system was used? (Score:2)
Otherwise, just because some user has a password does not inherently make them a god. Their account or access must be sufficient, or cracked.
Of course, this may be all a matter of badly written software or procedures and little to do with the OS.
Re:What operating system was used? (Score:3, Insightful)
It makes you wonder how it was done, though. Going straight to the database would clearly leave a trace in the logs that something was done. So was there an application with the purpose of changing bets, with the option to override bets already decied ?
Re:Drexel CS Student? (Score:2)
Drexel rules! I hope to work for a Drexel MBA at some point in my career.
Re:Too much too quickly... (Score:2, Insightful)
Re:Too much too quickly... (Score:2)
My little brother won a Tri-Super jackpot at a greyhound racing track a few years back. He hit three dogs in order (trifecta box) in the first race, and having won that he could then try to guess the first four dogs, in order, in the next race. Needless to say, he hit all four in order, otherwise I wouldn't be telling the story. He won $360,000. Half was split with an off-track bettor who picked the same dogs. Out of the remaining $180,000, $135,000 was left after taxes. Alas, my little brother was 16 at the time, and thus ineligible to bet - the money legally went to my mom's evil lawyer husband. My little brother got a brand-new Chevy Malibu LS (sport version), and little else. The husband spent it all on deer hunting trips, Reno gambling loss trips, and Jack Daniel's Tennesee Whiskey. Oh, and he beat the living shit out of our mom, too.
A few years later, the Malibu had been wrecked, my mom discovered him cheating on her and divorced him (he could beat her as well as me and she wouldn't leave him, but cheat on her and he's divorced, go figure), and all the money was gone.