Secret list! List! Not the transaction ID.
I swear it's like people keep repeating what others said instead of thinking for themselves.
This is troubling. I'm not much of a gambler, and haven't ever played SatoshiDice, but someone bringing a casino to the Bitcoin community is really not doing their homework to not understand how SatoshiDice's hashing works and why knowing the secret list ahead of time isn't a problem if it's being hashed with the transaction ID. The algorithm is too simple for someone willing to build a casino website to not understand, and the overconfident attitude is highly misplaced. Sorry, but I must apply my stamp of disapproval to this one.
Just to make it clear, I have no interest in anything gambling-related whatsoever.
I actually hoped you would swallow your pride there and admit that I was right for a second, especially considering you decided to delete your own post. Which further accused us of trying to scam.
I like you all guys regardless and appreciate the feedback
I'll give it to you as requested!
The post I deleted was based on the assumption that you didn't understand how hashing works (you admit this in the context of password security) and was an attempt to explain it. The reason I deleted it was that I came to understand that your point might have been that the secret list would permit the business to defraud its shareholders, not so much the business to defraud bettors. I don't know that to be certain, but felt it was prudent to give you the benefit of the doubt.
I don't think I ever accused you of trying to scam - rather, my contention was that you didn't appear to have the requisite security knowledge to run a bitcoin casino and handle other people's money, and appeared to be taking an attitude not of trying to learn it, but boldly dismissing it with overconfidence.
When you are confronted with someone engaging you on a security-related topic,
I swear it's like people keep repeating what others said instead of thinking for themselves.
isn't an appropriate response. The correct response is to either alleviate the concern, or address it on its own merits, without reference to people "not thinking for themselves". In this case, the correct response would be "Including the transaction ID in the hash protects the bettors but doesn't solve the problem that leaves the shareholders vulnerable to insider fraud."
It's really not a matter of pride for me: I'll be proud of you if you bring a stable secure trusted casino to the Bitcoin world with a willingness to learn whatever you need to do to build the best business you can.