Author

Topic: BetterBets.io |V2 NXT betting + Shapeshift.io|🎲 DICE★PLINKO★PVP Game CORE - page 134. (Read 315813 times)

legendary
Activity: 1988
Merit: 1007
Due to recent events, we have to change some of our great contests and bonuses temporarily to recover the loss of funds.
It is not by choice for us but by necessity to alter these in order to continue giving back to our players in every way we can.


First change will be in regards to our Monthly Raffle which this month is for a Trezor Bitcoin hardware wallet (or BTC equivalent in value). We must move the date of the prize drawing and winner to Tuesday August, 11th. After the winner is announced and his or her prize claimed the following day Augusts' new monthly raffle prize will be announced.

Second change is in regards to Cashback Club payment for this coming Sunday August 2nd. Due to the recent financial loss, we have no choice but to reduce this Sunday's payment by 70% across all player accounts who earned cashback during the week of July 26th - August 2nd. We are in no way happy to do this but the alternative course of action was to completely remove Cashback club. This was not something I wanted for our players to miss out on, so this became the only option available. Normal Cashback club rewards will continue after this Sunday as they have been in the past.

Affiliate payouts for this Sunday are unaffected.

The newest promotion for this week the "BetterBets.io VIP Event" will continue as planned, and players can start working towards it again as soon as BetterBets.io maintenance is complete. In the event that maintenance lasts longer than 24-48 hours we will alter the promotion dates to accommodate players and allow them the chance to still win these large prizes for their volume.


Thank you to everyone who has helped make this site successful, and we hope you understand the temporary changes needed to continue operations after the recent issue.


Thank you for letting us know. It's sad to see this happen, but IMO, having something is better than nothing. That said, it looks like things will be back on track soon enough, and that's a great thing.

About affiliate/cashback payments, how are those going to work if the site's still down through Sunday? Will they be sent out on time, still, or be done once the site's back up?
legendary
Activity: 3682
Merit: 4469
This saddens me Sad glad some asshole has to fuck shit up for all of us. My 1st week hitting dbl cash back n screwed. Thx to the asshole scanner who's to big a pussy to make his own money
hero member
Activity: 728
Merit: 500
Betterbets.io Casino
Due to recent events, we have to change some of our great contests and bonuses temporarily to recover the loss of funds.
It is not by choice for us but by necessity to alter these in order to continue giving back to our players in every way we can.


First change will be in regards to our Monthly Raffle which this month is for a Trezor Bitcoin hardware wallet (or BTC equivalent in value). We must move the date of the prize drawing and winner to Tuesday August, 11th. After the winner is announced and his or her prize claimed the following day Augusts' new monthly raffle prize will be announced.

Second change is in regards to Cashback Club payment for this coming Sunday August 2nd. Due to the recent financial loss, we have no choice but to reduce this Sunday's payment by 70% across all player accounts who earned cashback during the week of July 26th - August 2nd. We are in no way happy to do this but the alternative course of action was to completely remove Cashback club. This was not something I wanted for our players to miss out on, so this became the only option available. Normal Cashback club rewards will continue after this Sunday as they have been in the past.

Affiliate payouts for this Sunday are unaffected.

The newest promotion for this week the "BetterBets.io VIP Event" will continue as planned, and players can start working towards it again as soon as BetterBets.io maintenance is complete. In the event that maintenance lasts longer than 24-48 hours we will alter the promotion dates to accommodate players and allow them the chance to still win these large prizes for their volume.


Thank you to everyone who has helped make this site successful, and we hope you understand the temporary changes needed to continue operations after the recent issue.



sr. member
Activity: 348
Merit: 250
Hi Everybody,

as you know, we've been successfully attacked today and lost some BTC (not a huge amount, but still). As a precaution, we've put our site into maintenance mode (in effect, it's down and when accessing it you're being redirected to our maintenance page) until we reopen. To recap, here is the situation:

1) Everybody who lost BTC in the attack has been compensated. So this means that none of our players lost money permanently.

2) The site is in maintenance mode while we:
a) Investigate how the attack was performed. We know that the attack was performed directly against Moneypot's API and not through the BetterBets API entry point. There is however a concern that the information necessary to perform this attack was somehow obtained from our server so this necessitates the maintenance mode we've put the site under.
b) Further improve some of the security precautions we put into our API already
c) Audit the code to ensure that no sensitive information ever leaves our server
d) Increase logging to make sure that we better catch hacking attempts and the output they generate

3) We expect to remain in maintenance mode for 24-48 hours. Hopefully it will be on the lower end of that scale, but we want to make sure that things are as good as we know how to make them before turning the site back on again.

So, in summary: This is an unexpected and unfortunate incident but we're dealing with it as best as we know. We'll be back soon and hopefully be better and safer than ever before.

We appreciate your patience and understanding during this time. We're in this for the long run and we'll be back soon.
legendary
Activity: 1988
Merit: 1007
Hello dear players,

Today, we have been attacked by someone and have suffered a loss of over 8+ BTC in the process. Currently, we are working with Moneypot to find the exact cause of this issue and have refunded all players affected except one who lost more than we held on site, but they will be taken care of as soon as the root cause of this attack is determined.

It is unfortunate, in the life of our casino as we have had start-up expenses that have greatly outweighed our current profits and this attack forces us to make immediate changes to the programs we currently offer.  More information will follow once it is 100% clear that all systems are securely patched and operations can continue. Our deepest apologies to those who were affected by this and we hope to have a very swift resolution.


-Bjorn
 

It sucks that this happened. I look forward to seeing the resolution and finding out what the changes are in regards to the offered programs.
legendary
Activity: 3500
Merit: 1354
Hello dear players,

Today, we have been attacked by someone and have suffered a loss of over 8+ BTC in the process. Currently, we are working with Moneypot to find the exact cause of this issue and have refunded all players affected except one who lost more than we held on site, but they will be taken care of as soon as the root cause of this attack is determined.

It is unfortunate, in the life of our casino as we have had start-up expenses that have greatly outweighed our current profits and this attack forces us to make immediate changes to the programs we currently offer.  More information will follow once it is 100% clear that all systems are securely patched and operations can continue. Our deepest apologies to those who were affected by this and we hope to have a very swift resolution.


-Bjorn
 

I'm sorry to hear that, 8+ btc is not a small amount..so shocked to know that over 90% of the total lost amount is owned by only 1 player. But the good news is that you're going to refund all the affected players. Hope it will be resolved soon and there will no one can do this kind of attack again in the future.
hero member
Activity: 728
Merit: 500
Betterbets.io Casino
Hello dear players,

Today, we have been attacked by someone and have suffered a loss of over 8+ BTC in the process. Currently, we are working with Moneypot to find the exact cause of this issue and have refunded all players affected except one who lost more than we held on site, but they will be taken care of as soon as the root cause of this attack is determined. (this user is now paid, all users affected have been credited!)

It is unfortunate, in the life of our casino as we have had start-up expenses that have greatly outweighed our current profits and this attack forces us to make immediate changes to the programs we currently offer.  More information will follow once it is 100% clear that all systems are securely patched and operations can continue. Our deepest apologies to those who were affected by this and we hope to have a very swift resolution.


-Bjorn
 
legendary
Activity: 1463
Merit: 1886
There's a good chance the person who exploited the site is reading this, so if you let us know how you did it before we figure it out I'll give you a nice bounty =)

Just include your address. Feel free to post the details publicly here, or email it to me: [email protected]
legendary
Activity: 1050
Merit: 1000
Receiving error message AUTH_ID_OR_SECRET each time i try to bet.  Ive logged in and out of the site and money pot.  Any idea on resolving?

Thanks,
molloype

Betterbets got some serious issue today so that error cause of this, Bjorn and Ryan trying hard to get fix this and be back this to online for betting so have patience for little more time everything will be ok very soon.
legendary
Activity: 2562
Merit: 1414
Receiving error message AUTH_ID_OR_SECRET each time i try to bet.  Ive logged in and out of the site and money pot.  Any idea on resolving?

Thanks,
molloype

Oh Hi molloype, didnt expect to see that you in Bitcointalk. Apparently the site is under entire system check at the moment. It will be back soon however there is no ETA for that ( dont quote me on this ). Im terribly sorry for this  Sad
newbie
Activity: 23
Merit: 0
Receiving error message AUTH_ID_OR_SECRET each time i try to bet.  Ive logged in and out of the site and money pot.  Any idea on resolving?

Thanks,
molloype
legendary
Activity: 1463
Merit: 1886
While on the topic of provably fair, one idea I had would be that users could pick a client seed string like "LuckSeed" that they use on the app page. Then each bet the app does something like:

sha256('LuckySeed|' + nonce)

and take the first 4 bytes of that hash to use as the API client seed on MoneyPot. That has the huge advantage of:

a) The app being able to instantly verify each bet  (which is, way, way easier to do programmatically)
b) The user is able to batch verify bets  (which is way, way, easier to do as a human)


The big disadvantage is that if the app developer was conspiring with moneypot they could send the "client seed string" to moneypot which would allow moneypot to predict what clientSeeds the bets are going to use. In reality it probably wouldn't be feasible, but is a bit inelegant.  I guess it's up to each individual app to decide if that's a good idea or not. But for the case of a downloadable betting app (which requires trust) it seems perfect.


But for a website probably the best thing to do is:


a) Generate a strong, unpredictable client seeds for each bet (I recommend something along the lines of dustdice's function: https://gist.github.com/RHavar/a6511dea4d4c41aeb1eb )


b) Store/Save the server hash in the case of errors, or before making bets. Using localStorage is fine. The idea is that if moneypot ever returns an error, the same hash and client seed must be reused  ( to prevent the described "stalling" )


c) Actually verify that the results are what they should be, the hash matches and the profit is expected. In the case of any provably fair error, the app should at least notify the user





sr. member
Activity: 348
Merit: 250
Added your site to http://dicesites.com for stats and also made a BetterBets provably fair verifier Smiley




While making this verifier I noticed a few things:
1) What is "Client Seed Sequence"? It seems to be not used at all.
2) Could you show the "server secret" (which is MP's roll) on the bet detail popup? Obviously used for verifying the rolls, and it's not very convenient to let the players go to 2 sites to copy the data.
3) IMO, you should generate a random client seed before every bet in the browser. If a player bets with the same client seed every time, in theory MoneyPot could give "next server seeds" based on their betting pattern. So if a player is betting high every time, they would give low numbers based on the same repeated client seed. I am not accusing MoneyPot of this AT ALL, RHavar seems a trustworthy person to me, but provably fair is all about not needing to trust the site owner.
4) AFAIK you should allow the client seed to be a number in the range of 0 and 2^32-1. However you are saving it now a signed INT which has a limit of 2^31-1. You should make it unsigned so the player can put the full range of numbers as client seed. In theory again MP could influence the outcomes with the information that the client seed will always be limited/low.
5) It is possible to directly link to my verifier with: a link like this (ss = salt, ssh = server seed, sr = secret, cr = client seed) There are several sites that do link to my verifiers, which make it easier for the players to verify their bets, but it's obv up to you Smiley


1) It's the number of bets which have been taken with this client seed
2) Yes, will add.
3) That sort of defeats the purpose of letting the user set a client seed, doesn't it? Or do you mean generate a client seed based on the user's chosen client seed?
4) Will fix.
5) Yes, will add to the bet popup screen.

Thanks for your feedback and suggestions, they're very much appreciated.
hero member
Activity: 728
Merit: 500
Betterbets.io Casino
Added your site to http://dicesites.com for stats and also made a BetterBets provably fair verifier Smiley




While making this verifier I noticed a few things:
1) What is "Client Seed Sequence"? It seems to be not used at all.
2) Could you show the "server secret" (which is MP's roll) on the bet detail popup? Obviously used for verifying the rolls, and it's not very convenient to let the players go to 2 sites to copy the data.
3) IMO, you should generate a random client seed before every bet in the browser. If a player bets with the same client seed every time, in theory MoneyPot could give "next server seeds" based on their betting pattern. So if a player is betting high every time, they would give low numbers based on the same repeated client seed. I am not accusing MoneyPot of this AT ALL, RHavar seems a trustworthy person to me, but provably fair is all about not needing to trust the site owner.
4) AFAIK you should allow the client seed to be a number in the range of 0 and 2^32-1. However you are saving it now a signed INT which has a limit of 2^31-1. You should make it unsigned so the player can put the full range of numbers as client seed. In theory again MP could influence the outcomes with the information that the client seed will always be limited/low.
5) It is possible to directly link to my verifier with: a link like this (ss = salt, ssh = server seed, sr = secret, cr = client seed) There are several sites that do link to my verifiers, which make it easier for the players to verify their bets, but it's obv up to you Smiley


Thank you NLNico, I just want you to know I personally appreciate you taking the time to add us to your site. As to the questions you had I must step aside to let development answer those, but still want you to know your addition of BetterBets was very important to me.
legendary
Activity: 1876
Merit: 1295
DiceSites.com owner
@NLNico that sounds great betterbets get listed to dicesites collection so that is great achievement for BB team, i am also interested to know about how they will make satisfied you for your listed question
It's mostly about wagered amount (=popularity) and site age. However since BB uses MoneyPot and the funds/RNG/etc are on MP (so the player mostly has to trust MP), the site age is less relevant to me. BB has almost 4k wagered in 2 months, which is pretty good for a new site.

I replied to your comment also in the DiceSites thread, so if you have specific questions about other sites, pls reply there Smiley

.. and when the verifier link will be functional to verify bet result through this.
The verifier works already, only you need to copy the data (seeds, salt and secret) yourself. It's up to BB if they want to link to my verifier :p
legendary
Activity: 1050
Merit: 1000
@NLNico that sounds great betterbets get listed to dicesites collection so that is great achievement for BB team, i am also interested to know about how they will make satisfied you for your listed question and when the verifier link will be functional to verify bet result through this.
legendary
Activity: 1876
Merit: 1295
DiceSites.com owner
Added your site to http://dicesites.com for stats and also made a BetterBets provably fair verifier Smiley




While making this verifier I noticed a few things:
1) What is "Client Seed Sequence"? It seems to be not used at all.
2) Could you show the "server secret" (which is MP's roll) on the bet detail popup? Obviously used for verifying the rolls, and it's not very convenient to let the players go to 2 sites to copy the data.
3) IMO, you should generate a random client seed before every bet in the browser. If a player bets with the same client seed every time, in theory MoneyPot could give "next server seeds" based on their betting pattern. So if a player is betting high every time, they would give low numbers based on the same repeated client seed. I am not accusing MoneyPot of this AT ALL, RHavar seems a trustworthy person to me, but provably fair is all about not needing to trust the site owner.
4) AFAIK you should allow the client seed to be a number in the range of 0 and 2^32-1. However you are saving it now a signed INT which has a limit of 2^31-1. You should make it unsigned so the player can put the full range of numbers as client seed. In theory again MP could influence the outcomes with the information that the client seed will always be limited/low.
5) It is possible to directly link to my verifier with: a link like this (ss = salt, ssh = server seed, sr = secret, cr = client seed) There are several sites that do link to my verifiers, which make it easier for the players to verify their bets, but it's obv up to you Smiley
member
Activity: 83
Merit: 10
Players, you can track your Cashback Club Bonus in your account menu at our casino.
Win or lose every week you qualify for Cashback it is credited to your account, this event and extra BTC, is for this promotion only.
For more info on CashBack Club and our generous affiliate program see our FAQ: https://betterbets.io/app/content/faq/

Very generous bonuses on this one. Nice work guys!

Hopefully you can attract some big hitters who will take full advantage of it.
hero member
Activity: 728
Merit: 500
Betterbets.io Casino
Players, you can track your Cashback Club Bonus in your account menu at our casino.
Win or lose every week you qualify for Cashback it is credited to your account, this event and extra BTC, is for this promotion only.
For more info on CashBack Club and our generous affiliate program see our FAQ: https://betterbets.io/app/content/faq/
sr. member
Activity: 348
Merit: 250
We just pushed out a new version which improves the API, fixes Guest mode and a bunch of other stuff. Please see the dev post (2nd post of this thread) for all the gory details.

Enjoy and play it safe.
Jump to: