Pages:
Author

Topic: PSA: Betcoin.ag/PlayBetr.com/Coinbet.ag Data Breach (Read 692 times)

legendary
Activity: 3458
Merit: 6231
Crypto Swap Exchange
Do we have to add to not your keys not your coins, not your server not your email?

I think the better phrase would be "not your domain, not your email". I wouldn't recommend that people host their own mail servers due to the difficulty of setting up and maintaining, and using your own domain with another provider is a more reasonable compromise between convenience and security. This way, someone else handles your emails for you (ProtonMail in my case), but if they ever go offline/disable accounts/adopt a bad policy, I can move my domain to another service without having to re-register any accounts or missing any emails.

Don't want to take this too far off topic (I probably say that way too many times)

But the issue is that yeah, it's your domain you can move it from proton to gmail to Guerrilla Mail and so on, but you still are subject to their rules.
Running your own mail server is time consuming, annoying, easy to screw up, stressful and 1000 other things that will cause you to loose your hair, loose sleep and who knows what else. On the other hand, when someone sends you something you know what happened to it.

If you accept the fact that occasionally because it's not your server you might not get something that's fine. Most people are, but when it's important and you don't get it then too bad.

I'm a nerd, I'm good with that fact so yes I do run my own server.
I also know that if it explodes how to route around the issue.

I have seen too many people loose / not get important emails because they were hosting at a place that decided to black hole stuff because they felt like it that day. And then complain about it. Sorry, you knew the rules going it.

Sorry for the rant, it's just one of those things that sets me off.

-Dave
legendary
Activity: 2758
Merit: 3282
Do we have to add to not your keys not your coins, not your server not your email?

I think the better phrase would be "not your domain, not your email". I wouldn't recommend that people host their own mail servers due to the difficulty of setting up and maintaining, and using your own domain with another provider is a more reasonable compromise between convenience and security. This way, someone else handles your emails for you (ProtonMail in my case), but if they ever go offline/disable accounts/adopt a bad policy, I can move my domain to another service without having to re-register any accounts or missing any emails.
legendary
Activity: 3556
Merit: 1092
Betcoin.ag Forum Rep - Sportsbook, Casino
Both members who said they hadn't received the email have 'Site news & announcements' turned off on their email notification settings. For this to happen, they would have to have turned these off manually or requested it from our staff. We have had many replies to this email, so we know that the majority of players received it. Thanks again and good luck to all.
legendary
Activity: 2436
Merit: 1804
guess who's back
I got the email 6 days ago , thing is that the subject of the email wasn't about the breach lol
( Parlay Promo is Back! New Slots, Deposit Bonuses and More! ) that was the email subject , but if you open it you will see that they talk about the breach that happened

so at first thought it was just a promotion email but they first talk about the breach in that email

Quote
We are back with all the latest news about what is happening at Betcoin.ag.

It is important to let you know that a data breach occurred at Betcoin.ag. This incident occurred in March, however we just became aware of this recently. At no time were any passwords or player funds compromised, however email addresses were acquired. We take your security very seriously, and if you ever have a concern about an email you have received, we ask that you contact us by email, support ticket or live chat immediately. In addition, we will never send deposit addresses by email. We are committed to continuing to improve our security everyday and we thank you for your support.

Parlay Promo Returns ....
snip
legendary
Activity: 3458
Merit: 6231
Crypto Swap Exchange
I didn't get mine either. Some other Betcoin emails did land in spam, but nothing about a security breach (those were ticket replies).

I'm starting to wonder if some mail places are dumping more and more mail that they think is spam into a black hole and never even delivering it to your spambox.
I had a VERY spamlike email make it to the server I manage and the headers showed it also went to another account I have with Yahoo but the Yahoo account never got it.
The originating IP was not blacklisted but I only got the 1 copy.

Do we have to add to not your keys not your coins, not your server not your email?

-Dave
legendary
Activity: 2758
Merit: 3282
It's been well over 3 weeks now.

I'm thinking you either don't think it's that important or you don't want to send the email because you'd prefer the vast majority of your players not be made aware of their information being compromised (while appearing to be proactive on the forums).

I suppose it's also possible you guys can't figure out how to send 285k+ emails.  

We were pleased to have sent this email last Friday (6 days ago). Informing the community about this was a high priority, and we have done everything we could to do so via every medium available. Thank you.

hmmm, I didn't receive it.  Anyone else?

I didn't get mine either. Some other Betcoin emails did land in spam, but nothing about a security breach (those were ticket replies).
legendary
Activity: 2520
Merit: 2014
Join the world-leading crypto sportsbook NOW!
I think I got mine. The email account I use for gambling has so much going through it in terms of legit email / promo email / general announcements / and spam that unless I am looking for something it just gets deleted. I did see something from them come in over the last few days and since I have not played there in a while I ignored it and it just auto deleted after 48 hours. I do that to all mail coming into that account unless I move it.

So the standard good advice that all of you should be following.
1) 2FA
2) Different passwords for every site.
3) Don't leave BTC out there. Remember, not your keys not your coins.

-Dave

I did get one of these on monday from Betcoin:

Quote
The following IP needs to be whitelisted for your account: 42.190.96.171

Please click the link below to whitelist this IP and login: https://www.betcoin.ag/authenticate?token=XXX

I've been getting one every month or so for over a year. The ip address is almost always in Malasya.  (and obv I never click it)
legendary
Activity: 3458
Merit: 6231
Crypto Swap Exchange
I think I got mine. The email account I use for gambling has so much going through it in terms of legit email / promo email / general announcements / and spam that unless I am looking for something it just gets deleted. I did see something from them come in over the last few days and since I have not played there in a while I ignored it and it just auto deleted after 48 hours. I do that to all mail coming into that account unless I move it.

So the standard good advice that all of you should be following.
1) 2FA
2) Different passwords for every site.
3) Don't leave BTC out there. Remember, not your keys not your coins.

-Dave
legendary
Activity: 2520
Merit: 2014
Join the world-leading crypto sportsbook NOW!
It's been well over 3 weeks now.

I'm thinking you either don't think it's that important or you don't want to send the email because you'd prefer the vast majority of your players not be made aware of their information being compromised (while appearing to be proactive on the forums).

I suppose it's also possible you guys can't figure out how to send 285k+ emails.  

We were pleased to have sent this email last Friday (6 days ago). Informing the community about this was a high priority, and we have done everything we could to do so via every medium available. Thank you.

hmmm, I didn't receive it.  Anyone else?
legendary
Activity: 3556
Merit: 1092
Betcoin.ag Forum Rep - Sportsbook, Casino
It's been well over 3 weeks now.

I'm thinking you either don't think it's that important or you don't want to send the email because you'd prefer the vast majority of your players not be made aware of their information being compromised (while appearing to be proactive on the forums).

I suppose it's also possible you guys can't figure out how to send 285k+ emails.  

We were pleased to have sent this email last Friday (6 days ago). Informing the community about this was a high priority, and we have done everything we could to do so via every medium available. Thank you.
legendary
Activity: 2520
Merit: 2014
Join the world-leading crypto sportsbook NOW!
Yup, an email was what I was expecting. There's probably a lot of players who are inactive as well and thus wouldn't see the article.

We made posts on our BitcoinTalk thread and player forum the day the investigation concluded, with plans of an email to follow. This email will be sent shortly. Thank you very much for all you do for the community.

It's been well over 3 weeks now.

I'm thinking you either don't think it's that important or you don't want to send the email because you'd prefer the vast majority of your players not be made aware of their information being compromised (while appearing to be proactive on the forums).

I suppose it's also possible you guys can't figure out how to send 285k+ emails.  
legendary
Activity: 3556
Merit: 1092
Betcoin.ag Forum Rep - Sportsbook, Casino
Yup, an email was what I was expecting. There's probably a lot of players who are inactive as well and thus wouldn't see the article.

We made posts on our BitcoinTalk thread and player forum the day the investigation concluded, with plans of an email to follow. This email will be sent shortly. Thank you very much for all you do for the community.
legendary
Activity: 2758
Merit: 3282
Bump. It doesn't seem like either Betcoin nor PlayBetr have notified their players (yet).

Hello, we notified our players the day that we concluded our investigation
https://www.betcoin.ag/player-email-address-database-breached-march



I'd be surprised if even half your players saw this article.  An email would be much more effective and considering every players email address was compromised (again) should've been the first thing you did after finding out.

Yup, an email was what I was expecting. There's probably a lot of players who are inactive as well and thus wouldn't see the article. As of right now, I have not received an email from Betcoin or PlayBetr (and I don't have a CoinBet account).
legendary
Activity: 2520
Merit: 2014
Join the world-leading crypto sportsbook NOW!
They can find out another way but getting spammed with other websites, maybe they'll realize something was compromised but might not help them pinpoint that to the original source

Or the emails could be used to phish players (again)
newbie
Activity: 7
Merit: 0
They can find out another way but getting spammed with other websites, maybe they'll realize something was compromised but might not help them pinpoint that to the original source
legendary
Activity: 2520
Merit: 2014
Join the world-leading crypto sportsbook NOW!
Bump. It doesn't seem like either Betcoin nor PlayBetr have notified their players (yet).

Hello, we notified our players the day that we concluded our investigation
https://www.betcoin.ag/player-email-address-database-breached-march



I'd be surprised if even half your players saw this article.  An email would be much more effective and considering every players email address was compromised (again) should've been the first thing you did after finding out.
legendary
Activity: 3556
Merit: 1092
Betcoin.ag Forum Rep - Sportsbook, Casino
Bump. It doesn't seem like either Betcoin nor PlayBetr have notified their players (yet).

Hello, we notified our players the day that we concluded our investigation
https://www.betcoin.ag/player-email-address-database-breached-march

legendary
Activity: 2758
Merit: 3282
Bump. It doesn't seem like either Betcoin nor PlayBetr have notified their players (yet).
legendary
Activity: 2520
Merit: 2014
Join the world-leading crypto sportsbook NOW!
I think this very well could be a lie.

Blaming a former employee looks much less bad on Betcoin than a third party gaining access.  Also, Betcoin has a history of telling blatant lies both big and small.  (Including lying about having a "new start, new owners etc", multiple times, in order to blame past scandals on someone else)

I can definitely see where your coming from, but given that PlayBetr/Coinbet were also breached (and any other sites using the same software), it's harder to believe. I suppose the argument could be made that they are all the same site but I think it's more likely that they're just using the same provider.

Coinbet.ag and Betcoin.ag were definitely managed by the same people a couple years ago.  I once even got a withdraw approved on Coinbet through the Betcoin chat.  They also used to advertise Coinbet dice tourneys on Betcoin.

I also stumbled on Playbetr a couple years ago before it was actually launched.  It was identical to Betcoin but had a bunch of obvious bots in the chat and at the poker tables making the site appear active.  It was really weird.  They seem to have made a bunch of changes, including getting a lol curacao gaming license and not allowing US players.  (something the Betcoin was planning on doing in 2018)

https://bitcointalksearch.org/topic/m.16797364

legendary
Activity: 2758
Merit: 3282
I think this very well could be a lie.

Blaming a former employee looks much less bad on Betcoin than a third party gaining access.  Also, Betcoin has a history of telling blatant lies both big and small.  (Including lying about having a "new start, new owners etc", multiple times, in order to blame past scandals on someone else)

I can definitely see where your coming from, but given that PlayBetr/Coinbet were also breached (and any other sites using the same software), it's harder to believe. I suppose the argument could be made that they are all the same site but I think it's more likely that they're just using the same provider.
Pages:
Jump to: