Author

Topic: Primedice.com | Since 2013 | Longest Running Crypto Casino | 113 BTC Jackpot! - page 1081. (Read 1989815 times)

legendary
Activity: 2464
Merit: 1037
CEO @ Stake.com and Primedice.com
Jeezzz i just saw this. Im glad that he didn't get away with much more coins.

And btw unmuted u Associates .

full member
Activity: 196
Merit: 104
I would find it hard to keep track of each server seed if I run an automatic bot. How do I verify each roll in that case?

Yes it's so hard to track server seed with auto-bet, we need to working on some API calls to solve this untrust.

Wait... So you guys could potentially observe the betting pattern of players and change the server seed to make them lose? Can't the server modify the result and show a server seed when the user requests for it via the API and gives the user the losing result when calculated?

There is a possibility of that happening. It would be better for the user to change the client seed frequently, if thats the case.
legendary
Activity: 1274
Merit: 1001
"shh, he's coding..."
Wait... So you guys could potentially observe the betting pattern of players and change the server seed to make them lose?
Does that mean you can interfere with the results?

No, no.

We only working on a system to preserve players and investors
full member
Activity: 157
Merit: 100
HUKOM BITAY! ✝✝✝
I would find it hard to keep track of each server seed if I run an automatic bot. How do I verify each roll in that case?

Yes it's so hard to track server seed with auto-bet, we need to working on some API calls to solve this untrust.

Wait... So you guys could potentially observe the betting pattern of players and change the server seed to make them lose? Can't the server modify the result and show a server seed when the user requests for it via the API and gives the user the losing result when calculated?

Does that mean you can interfere with the results?
legendary
Activity: 3038
Merit: 4418
Crypto Swap Exchange
I would find it hard to keep track of each server seed if I run an automatic bot. How do I verify each roll in that case?

Yes it's so hard to track server seed with auto-bet, we need to working on some API calls to solve this untrust.

Wait... So you guys could potentially observe the betting pattern of players and change the server seed to make them lose? Can't the server modify the result and show a server seed when the user requests for it via the API and gives the user the losing result when calculated?
full member
Activity: 157
Merit: 100
HUKOM BITAY! ✝✝✝
-snip-
Was this resolved?

Yes it was resolved.
I think this post was from a long time ago.
full member
Activity: 238
Merit: 100
I would find it hard to keep track of each server seed if I run an automatic bot. How do I verify each roll in that case?

Yes it's so hard to track server seed with auto-bet, we need to working on some API calls to solve this untrust.
legendary
Activity: 840
Merit: 1000
Part of fixing the issue is forcing all accounts to set a new seed pair, in an hour expect to be prompted to set a new pair.

We (bikinidice) change server seed every rool. That's isn't very pretty for player (need to check every time his pair to make sure of our fair system) but we need to protect our investors coin.

Sites like bikinidice which pick a new server seed for every roll are a real pain to play on for the paranoid gambler. In order to be sure that the rolls are fair, you have to make a note of each new server seed hash, and then pick a new random client seed as well - for every roll - and then verify the rolls afterwards, too.

If any player force the sha256 server seed is a BIG problem. Yes it's difficult but not impossible.

I would find it hard to keep track of each server seed if I run an automatic bot. How do I verify each roll in that case?
legendary
Activity: 1274
Merit: 1001
"shh, he's coding..."
Lol?

I think if you had some coin of other player you need to take more care than a "lol"  Wink
legendary
Activity: 1876
Merit: 1303
DiceSites.com owner
Part of fixing the issue is forcing all accounts to set a new seed pair, in an hour expect to be prompted to set a new pair.

We (bikinidice) change server seed every rool. That's isn't very pretty for player (need to check every time his pair to make sure of our fair system) but we need to protect our investors coin.

Sites like bikinidice which pick a new server seed for every roll are a real pain to play on for the paranoid gambler. In order to be sure that the rolls are fair, you have to make a note of each new server seed hash, and then pick a new random client seed as well - for every roll - and then verify the rolls afterwards, too.

If any player force the sha256 server seed is a BIG problem. Yes it's difficult but not impossible.
Lol?
full member
Activity: 238
Merit: 100
Part of fixing the issue is forcing all accounts to set a new seed pair, in an hour expect to be prompted to set a new pair.

We (bikinidice) change server seed every rool. That's isn't very pretty for player (need to check every time his pair to make sure of our fair system) but we need to protect our investors coin.

Sites like bikinidice which pick a new server seed for every roll are a real pain to play on for the paranoid gambler. In order to be sure that the rolls are fair, you have to make a note of each new server seed hash, and then pick a new random client seed as well - for every roll - and then verify the rolls afterwards, too.

If any player force the sha256 server seed is a BIG problem. Yes it's difficult but not impossible.
hero member
Activity: 525
Merit: 500
Stunna just said in chat that the guy abused an exploit and therefore could use an unhashed seed; so he could predict the rolls. Obviously won't be allowed to withdraw.


Why people abuse exploits like this?

He could earn some buck either by telling Stunna about the bug or by moderating his luck, but the way he did  he got no winnings

What else could it be other than greed? Stunna mentioned that he withdrew 40btc before he was caught and I doubt the bounty for bugs would've been this big. Shame about the exploit and the fact that it was exploited but these are sadly just part of the business.
legendary
Activity: 3192
Merit: 1279
Primedice.com, Stake.com

Maybe he has been using the exploit in a less obvious way for a while now on other accounts and has already won all the coins he wanted to win. This could be his fun way of "reporting" it.

Could be doog knowing how some hackers are
Just taking his 40 Bitcoin commission and then showing off the trick of the trade


It's a pretty complex situation, we put in a basic fix which was defeated and now we're taking stronger measures to ensure this doesn't happen again.

Part of fixing the issue is forcing all accounts to set a new seed pair, in an hour expect to be prompted to set a new pair.

I'll be providing full information later this week after we've done some extensive testing. I am comfortable saying that there was no breach of server or database and all account balances are 100% safe, no accounts should be effected by this issue it only effects us.
member
Activity: 109
Merit: 10
Could an admin or moderator of the website please unmute me on PrimeDice? I have been muted for over 2 days and i already sent an email in.

User : Associates

Why did they muted you?
Try to message support or Stunna here.
Its easier that way.
legendary
Activity: 1834
Merit: 1094
Learning the troll avoidance button :)

Maybe he has been using the exploit in a less obvious way for a while now on other accounts and has already won all the coins he wanted to win. This could be his fun way of "reporting" it.

Could be doog knowing how some hackers are
Just taking his 40 Bitcoin commission and then showing off the trick of the trade
legendary
Activity: 2940
Merit: 1333
your IQ must be high if you can't tell if it's a joke or not

It's hard to tell with you sometimes.

With most people it's easy: if it's funny, it's a joke... Wink

Why people abuse exploits like this?

He could earn some buck either by telling Stunna about the bug or by moderating his luck, but the way he did  he got no winnings

Because sites often don't pay well for reported exploits. Just yesterday a guy was posting on the SatoshiDice thread about how he can withdraw his balance twice to double his bankroll, but they don't believe him and so won't pay him.

the way he used the exploit was dumb, betting large amounts that can be seen by other people hmmmm... Obvious way to get caught cheating

Maybe he has been using the exploit in a less obvious way for a while now on other accounts and has already won all the coins he wanted to win. This could be his fun way of "reporting" it.
hero member
Activity: 868
Merit: 1000
can someone explain how to do this and how i can get away with it?







thanks

You've got to be joking about this post bro. If you are joking, it's not funny at all. If you aren't, go buy some intelligence at the nearby elementary school.



your IQ must be high if you can't tell if it's a joke or not
full member
Activity: 172
Merit: 100
Stunna said in chat that the guy abused an exploit and thereby used an unhashed seed; so he could predict the rolls. Obviously won't be allowed to withdraw.

He managed to withdraw 40 coins here before we caught him

https://blockchain.info/address/14HQ67ZhmATviHi9RdYhbUriAGSFmJpYoB

We're investigating this now, I think I know what's happening though but I'm not going to reveal it until we've 100% patched it up.


Naturally the "this is rigged" etc arguments will start rolling in but at the end of the day anyone can mathematically verify all rolls they made. I'll explain how he managed to get an unhashed seed when we've resolved this. Working on it now

Thanks for letting us know! I hope you guys can get this patched up promptly and thoroughly.
hero member
Activity: 908
Merit: 657
Stunna just said in chat that the guy abused an exploit and therefore could use an unhashed seed; so he could predict the rolls. Obviously won't be allowed to withdraw.


Why people abuse exploits like this?

He could earn some buck either by telling Stunna about the bug or by moderating his luck, but the way he did  he got no winnings

He withdrew 40 btc and probably took a lot more without detection before this run. The thing is, there is no amount Stunna could really offer to make this worthwhile financially for any exploiter, since he can take a great deal more through theft.
Jump to: