Online Casinos - Casinomeister Logo Online Casinos - Casinomeister
Results 1 to 8 of 8

Thread: Casino Security

  1. #1
    winbig's Avatar
    winbig is offline mmmm, Foxy.
    Achievements:
    VeteranCreated Album picturesCreated Blog entry50000 Experience PointsPeople Likes You
    Join Date
    Mar 2005
    Location
    Pennsylvania
    Posts
    8,229
    Blog Entries
    4
    Thanks
    1,371
    Thanked 3,608 Times in 2,120 Posts
    Rep Power
    166
    Reputation Points: 19093

    Thumbs down Casino Security

    (Note: Names have been hidden to protect the clueless. )

    There's another thread re: security going on right now, but it's not 100% related to what I'm bringing up here, so I didn't want to derail that thread.

    What's the deal here? It seems that MGS casinos don't give a rats a$$ about player security. As you can see from the screenshot below, this connection is not secure. Even a novice would know this, because 99% of the time people are told time and time again not to submit any personal information/passwords/etc over a connection that doesn't begin with https://.

    SS:



    What I don't get is the fact that they even try to tell you that you're using a secured connection....who are they trying to fool, and why?

    Here's further proof that it's not a secure connection:





    This is even worse than sending out your password via email...the chance for ID theft in this scenario is very high.

    Note: I was sent to this page from within the casino software.
    Operators: If you don't know what Transparency means, then here you go.....now how about practicing it?

    Transparency, as used in the humanities and in a social context more generally, implies openness, communication, and accountability. It is a metaphorical extension of the meaning a "transparent" object is one that can be seen through. ...

  2. The Following 5 Users Say Thank You to winbig For This Useful Post:

    bb28 (5th February 2010), Jasminebed (4th February 2010), Pinababy69 (6th February 2010), Rusty (3rd February 2010), zebedy (6th February 2010)

  3. #2
    newguy68 is offline Newbie member
    Join Date
    Oct 2009
    Location
    Anapa
    Posts
    17
    Thanks
    0
    Thanked 3 Times in 3 Posts
    Rep Power
    11
    Reputation Points: 25
    You forgot to hide the name on the tab, under address bar.
    Casino name is still visible

  4. #3
    vinylweatherman's Avatar
    vinylweatherman is offline Typus Infinitus Achievements:
    Veteran50000 Experience PointsOverdrivePeople Likes You
    Awards:
    Frequent PosterCommunity AwardMost Popular
    Join Date
    Oct 2004
    Location
    United Kingdom
    Posts
    10,796
    Thanks
    414
    Thanked 6,844 Times in 3,671 Posts
    Rep Power
    271
    Reputation Points: 37443
    This casino group use an old version of the loyalty point software. Behind the scenes, the lobby passes both your account number and casino password to this page to ensure an auto-login. This information has CLEARLY been sent over an ordinary http:, or non-encrypted, link. To display that it is 128bit encrypted is highly misleading.

    If someone is monitoring traffic, they will see your account number and password IN PLAIN TEXT, rather than a 128bit encrypted field.

    This is VERY risky over a wireless connection that itself is not encrypted, such as a public WiFi hotspot. Public WiFi is routinely scanned by criminals because it is such a "soft target" for stealing personal details.

    This affair is the fault of MICROGAMING, not the casino. MGS operate the loyalty, Cashcheck, and Playcheck pages in most cases, although many casinos now use their own loyalty managment software, rather than this out of date MGS version.
    Empty Fruities Astern Capt'n
    Back to port for unloading.
    Full Sails - before we get raided ourselves.

  5. #4
    Rhyzz's Avatar
    Rhyzz is offline Experienced Member
    Join Date
    Jan 2008
    Location
    Marbella, Spain
    Posts
    298
    Thanks
    4
    Thanked 93 Times in 70 Posts
    Rep Power
    21
    Reputation Points: 488
    Microgaming had a big issue a few years ago which never came to light (gotta love insider contacts). This exact issue was happened with their client, ie) you logged in, the details were passed to MGS and were not encrypted at all, a basic packet sniffer picked up all of the info.

    They fixed it but how long had it been around for? Many years, as long as MGS Poker had been operating.

    Seems like something they need to look into! I'd make 32Red aware, they're probably the only MGS outfit that would care...

  6. #5
    vinylweatherman's Avatar
    vinylweatherman is offline Typus Infinitus Achievements:
    Veteran50000 Experience PointsOverdrivePeople Likes You
    Awards:
    Frequent PosterCommunity AwardMost Popular
    Join Date
    Oct 2004
    Location
    United Kingdom
    Posts
    10,796
    Thanks
    414
    Thanked 6,844 Times in 3,671 Posts
    Rep Power
    271
    Reputation Points: 37443
    Quote Originally Posted by Rhyzz View Post
    Microgaming had a big issue a few years ago which never came to light (gotta love insider contacts). This exact issue was happened with their client, ie) you logged in, the details were passed to MGS and were not encrypted at all, a basic packet sniffer picked up all of the info.

    They fixed it but how long had it been around for? Many years, as long as MGS Poker had been operating.

    Seems like something they need to look into! I'd make 32Red aware, they're probably the only MGS outfit that would care...
    Not here though, the details are still passed to the MGS loyalty manager, and in this case it is clearly unencrypted. This would STILL expose the account number and password to any basic packet sniffer that was intercepting the traffic. Worse still, this is managed internally by the Viper client, and the player is often unaware of the nature of the connection, nor what is passed through it by the client software.
    Empty Fruities Astern Capt'n
    Back to port for unloading.
    Full Sails - before we get raided ourselves.

  7. #6
    love2winalot's Avatar
    love2winalot is offline Playing to Win, not lose.
    Join Date
    Feb 2009
    Location
    Philippines/Visiting Las vegas
    Posts
    812
    Thanks
    540
    Thanked 434 Times in 267 Posts
    Rep Power
    32
    Reputation Points: 2816
    Hiya: For anyone that may not know this. Here is the easy way to know if a site is secure or not.

    hqttppprrwwe.xxxxxcvbn,on[/url] and on and on. --------------------------------"padlock"

    Just look at the URL address at the top of your screen. Now go all the way over to the right. The last thing you will see on a secure site is a small, "padlock". It looks like the lock inside the red circle on winbig post. This padlock is meaningless anywhere on the web page. Only at the end of a URL is it really a secure site.
    "All I want, is to WIN my fair share, and maybe just a teeny bit more"

  8. #7
    Wildfire7's Avatar
    Wildfire7 is offline Meister Member
    Join Date
    Apr 2006
    Location
    UK
    Posts
    417
    Thanks
    96
    Thanked 178 Times in 113 Posts
    Rep Power
    32
    Reputation Points: 1109
    Quote Originally Posted by vinylweatherman View Post
    This affair is the fault of MICROGAMING, not the casino. MGS operate the loyalty, Cashcheck, and Playcheck pages in most cases, although many casinos now use their own loyalty managment software, rather than this out of date MGS version.
    Agreed, however the casino ought to be aware this is happening and do something about it. Afterall it is the casinos house, if they genuinely
    wanted to keep their own house in good order, then they will fix the problem by reporting it to MG. No secure information should be exchanged on an unencrypted page such as this. It is such a serious breach of basic security that the casino should suspend this page until it has been secured.
    Anything less is totally unacceptable.


    Mike

  9. #8
    GrandMaster's Avatar
    GrandMaster is offline Ueber Meister Achievements:
    Veteran10000 Experience PointsFriends R Us
    Join Date
    Jan 2004
    Location
    UK
    Posts
    2,549
    Thanks
    177
    Thanked 951 Times in 534 Posts
    Rep Power
    73
    Reputation Points: 5493
    Quote Originally Posted by love2winalot View Post
    Hiya: For anyone that may not know this. Here is the easy way to know if a site is secure or not.

    hqttppprrwwe.xxxxxcvbn,on[/url] and on and on. --------------------------------"padlock"

    Just look at the URL address at the top of your screen. Now go all the way over to the right. The last thing you will see on a secure site is a small, "padlock". It looks like the lock inside the red circle on winbig post. This padlock is meaningless anywhere on the web page. Only at the end of a URL is it really a secure site.
    The location of the padlock rather depends on your browser. You should also know that "no encryption" is one of the valid encyption options under https, so it is still not guaranteed that your password or sensitive personal data will be encrypted.
    "The voice of reason"
    http://mb.winneronline.com moderator

Similar Threads

  1. GoldVipClubCasino security =)
    By Scammed in forum Casino Complaints - Bonus Issues
    Replies: 3
    Last Post: 10th November 2009, 07:43 PM
  2. What about your Privacy & Security?
    By aodat2 in forum Online Casinos
    Replies: 25
    Last Post: 13th March 2008, 04:14 PM
  3. Casino Insider Tells (almost) All About Security !!
    By RobWin in forum North American Land Based Casinos
    Replies: 14
    Last Post: 13th March 2008, 02:10 PM
  4. Neteller Security ID
    By padanian in forum Online Casinos
    Replies: 16
    Last Post: 2nd December 2004, 01:55 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Legal Statements and Privacy Policy
Casinomeister.com does not intend for any of the information contained on this website to be used for illegal purposes. You must ensure you meet all age and other regulatory requirements before entering a casino or placing a wager. Online gambling is illegal in many jurisdictions and users should consult legal counsel regarding the legal status of online gambling and gaming in their jurisdictions. The information in this site is for news and entertainment purposes only. Casinomeister.com is an independent directory and information service free of any gaming operator's control. Links to third party websites on Casinomeister.com are provided solely for informative/educational purposes. If you use these links, you leave this Website.