Two Plus Two Publishing LLC Two Plus Two Publishing LLC
 

Go Back   Two Plus Two Poker Forums > Internet Poker > Internet Poker

Internet Poker Discussions of Internet poker venues.

Reply
 
Thread Tools Display Modes
Old 07-28-2009, 04:25 PM   #511
journeyman
 
Join Date: Jan 2006
Posts: 327
Re: I suspect Pitbull Poker has superusers!

Quote:
Originally Posted by pbdave View Post
we will not be part of the roman circus this has turned into.
Somehow I think if the Roman Empire hadn't fallen, they'd be offended to be lumped in with Pit Bull Poker
nuts busted is offline   Reply With Quote
Old 07-28-2009, 04:29 PM   #512
journeyman
 
Join Date: Jan 2006
Posts: 327
Re: I suspect Pitbull Poker has superusers!

Something strikes me about this thread, which I just spent like 2 hours reading. In light of allegations of super users, PBDave has on more than one occasion claimed that no collusion exists on his site. This seems a bit like a suspect being interrogated in a missing persons case repeatedly answering the question "Did you kidnap her" with a response of "No, how many times do I have to tell you I didn't kill her!".

Maybe this will turn out to be some sort of collusion case that we don't understand? Serge Ravitch is alluding to the possibility there's more at play than we're seeing....
nuts busted is offline   Reply With Quote
Old 07-28-2009, 04:57 PM   #513
adept
 
Join Date: Jun 2007
Posts: 1,021
Re: I suspect Pitbull Poker has superusers!

Quote:
Originally Posted by suzzer99 View Post
FYI - a few hours ago I got a PM from chesterboy saying that he didn't think the table data was encrypted. I looked into it and the URL for the table was not encrypted (http://... vs. https://...). Nor was the URL for the flash object within the HTML page.

The only thing is I don't know enough about flash to know if the flash object can still send it's requests to the server via https, even if it's own address is not. But a guy I know who is pretty good with flash doesn think it can.

NOW, here's the interesting part. The table URL and the rest of the site are https now. I am 100% sure that the table URL and most of the site were not https just a few hours ago. So weird.

The person I mentioned earlier was kind enough to record some images of what he looked at that wasn't secure, and has now apparently been changed. Again, pm me if anyone wants these files.
chesterboy is offline   Reply With Quote
Old 07-28-2009, 05:02 PM   #514
grinder
 
R3AG4N's Avatar
 
Join Date: Nov 2008
Posts: 409
Re: I suspect Pitbull Poker has superusers!

Quote:
Originally Posted by chesterboy View Post
The person I mentioned earlier was kind enough to record some images of what he looked at that wasn't secure, and has now apparently been changed. Again, pm me if anyone wants these files.
PLEASE POST.
R3AG4N is offline   Reply With Quote
Old 07-28-2009, 05:31 PM   #515
banned
 
Join Date: Jun 2009
Posts: 65
Re: I suspect Pitbull Poker has superusers!

I was going to try Pitbull I guess I will wait till this is resolved now
lexa89 is offline   Reply With Quote
Old 07-28-2009, 05:54 PM   #516
Actually Shows Proof
 
spadebidder's Avatar
 
Join Date: Aug 2008
Location: This looks interesting.
Posts: 7,890
Re: I suspect Pitbull Poker has superusers!

Quote:
Originally Posted by suzzer99 View Post
FYI - a few hours ago I got a PM from chesterboy saying that he didn't think the table data was encrypted. I looked into it and the URL for the table was not encrypted (http://... vs. https://...). Nor was the URL for the flash object within the HTML page.

The only thing is I don't know enough about flash to know if the flash object can still send it's requests to the server via https, even if it's own address is not. But a guy I know who is pretty good with flash doesn think it can.
The PB client most definitely uses HTTPS to talk to the server. I went there and got on a playmoney table just to trace the communication and see what it does. Your guy is mistaken.
spadebidder is offline   Reply With Quote
Old 07-28-2009, 06:00 PM   #517
adept
 
Join Date: Jun 2007
Posts: 1,021
Re: I suspect Pitbull Poker has superusers!

Quote:
Originally Posted by R3AG4N View Post
PLEASE POST.


The guy that recorded this says it hasn't been changed as was stated in an earlier post.
I'll let you tech guys handle this if you are interested. He says nothing has been changed so the raw data I have recorded isn't any more useful than just opening up a table and watching. I'm useless in this department.
chesterboy is offline   Reply With Quote
Old 07-28-2009, 06:10 PM   #518
Actually Shows Proof
 
spadebidder's Avatar
 
Join Date: Aug 2008
Location: This looks interesting.
Posts: 7,890
Re: I suspect Pitbull Poker has superusers!

Quote:
Originally Posted by chesterboy View Post


The guy that recorded this says it hasn't been changed as was stated in an earlier post.
I'll let you tech guys handle this if you are interested. He says nothing has been changed so the raw data I have recorded isn't any more useful than just opening up a table and watching. I'm useless in this department.
That's pretty interesting, I saw it opening up ports 443 but also some others too, and I didn't look at them all.
spadebidder is offline   Reply With Quote
Old 07-28-2009, 06:21 PM   #519
Carpal \'Tunnel
 
suzzer99's Avatar
 
Join Date: Nov 2005
Location: on top of the bell curve
Posts: 46,878
Re: I suspect Pitbull Poker has superusers!

Quote:
Originally Posted by spadebidder View Post
The PB client most definitely uses HTTPS to talk to the server. I went there and got on a playmoney table just to trace the communication and see what it does. Your guy is mistaken.
I can guarantee you that it wasn't this morning. And I was not on a play money table. I'm not the guy chester is referring to, but he PMed me about the secure thing so I checked it out.

Here is the link from my browser history:

http://www.pitbullpoker.com/poker/game/child.jsp?id=0&v=h&cv=i&gv=h&rv=g&t=NL%20$0.10%20H oldem,Se7en

(This is from a $0.10 table named Se7en)

And here is the html source for that page:

Code:
<html><head>
<meta http-equiv="content-type" content="text/html; charset=ISO-8859-1">

  <title>www.pitbullpoker.com - Game View</title>
    <link href="child.jsp_files/style.css" rel="stylesheet" type="text/css">

<!-- www.hitslink.com/ web tools statistics hit counter code -->
<script type="text/javascript">//<![CDATA[
var data,nhp,ntz,rf,sr,i,d=new Date(),pageName;

// The pageName variable can be customized if needed
pageName=location.pathname;

document.cookie='__support_check=1';nhp='http';
rf=document.referrer;sr=window.location.search;
if(top.window.location==document.referrer
|| (document.referrer == '' && top.window.location != ''))
{rf=top.document.referrer;sr=top.window.location.search}
ntz=new Date();if(location.href.substr(0,6).toLowerCase()=='https:')
nhp='https';data='&an='+escape(navigator.appName)+ 
'&sr='+escape(sr)+'&ck='+document.cookie.length+
'&rf='+escape(rf)+'&sl='+escape(navigator.systemLanguage)+
'&av='+escape(navigator.appVersion)+'&l='+escape(navigator.language)+
'&pf='+escape(navigator.platform)+'&pg='+escape(pageName);
if(navigator.appVersion.substring(0,1)>'3') {data=data+'&cd='+
screen.colorDepth+'&rs='+escape(screen.width+ ' x '+screen.height)+
'&tz='+ntz.getTimezoneOffset()+'&je='+ navigator.javaEnabled()};
i=new Image();i.src=nhp+'://counter.hitslink.com/statistics.asp'+
'?v=1&s=201&acct=pitbullpoker'+data+'&tks='+d.getTime(); //]]>
</script>
<!-- End www.hitslink.com/ statistics web tools hit counter code -->

<script charset="utf-8" id="injection_graph_func" src="child.jsp_files/injection_graph_func.js"></script></head><body leftmargin="0" topmargin="0" bgcolor="#eae6d9" marginheight="0" marginwidth="0" text="#000000">








<script language="JavaScript">

    //create unique id
    var uid = 1248796261183;


    //create proxy to flash
    //var flashProxy = new FlashProxy(uid, 'JSProxy/JavaScriptFlashGateway.swf');

    //this function is called from Flash


    function activateGame()
    {
	    try{

	    	// window.onfocus = '';
	    	//window.onfocus = activateGame;
	    	// window.onblur = inactivateGame;
	    	 flashProxy.call("onFocused", uid);
	      }
	      catch(e){
	      alert("this is the error"+ e);

	      }
    }

    //window.onfocus = activateGame;
    //window.onblur = inactivateGame;

    function inactivateGame()
    {

     // remove the event to stop an infinite loop!
     flashProxy.call("onLostFocus", uid);
     window.onfocus = activateGame;
     //window.onblur = '';
    }

</script>
<script language="javascript" type="text/javascript">

    var __pingInterval;
    var newWidth = 0;
    var newHeight = 0;
    var currentWidth = 0;
    var currentHeight = 0;
    var MIN_WIDTH = 425 ; //442.22;     // 796/1.8
    var MIN_HEIGHT = 294.0; //305.55;     // 550/1.8
    var DEFAULT_DIFX = 12;
    var DEFAULT_DIFY = 52;

    // We get the screen size
    var screenWidth = screen.width;
    var screenHeight = screen.height;
    var defaultW;
    var defaultH;
    var isOnProcess = false;
    var difX = -1;
    var difY = -1;
    var oldXFactor = 0;
    var oldYFactor = 0;
    var __auxInterval;

    var hasFocus = false;

/**
* Called when the window "unloads"
* @param
*/
       window.onunload = function()
        {
            clearInterval(__pingInterval);
            window.close();
   	}

/**
* Called when the window loads
* @param
*/
    window.onload = function()
    {
        __pingInterval = setInterval('ping()', 250);

        getSize();
        defaultW = newWidth;
        defaultH = newHeight;
        currentWidth = newWidth;
        currentHeight = newHeight;
        hasFocus = true;
        setTitle();

        if( window.innerWidth && window.innerHeight && ( window.innerWidth < 796 || window.innerHeight < 550 ) )
        {
            currentWidth = 796;
            currentHeight = 550;
            setTimeout( 'window.innerWidth = 796; window.innerHeight = 550;', 1000 );
        }
        else if( document.body && document.body.clientWidth && document.body.clientHeight && ( document.body.clientWidth < 796 || document.body.clientHeight < 550 ) )
        {
            currentWidth = 796;
            currentHeight = 550;
            setTimeout( 'window.resizeTo(796, 550);', 1000 );
        }
        else if( document.documentElement && document.documentElement.clientWidth && document.documentElement.clientHeight && ( document.documentElement.clientWidth < 796 || document.documentElement.clientHeight < 550 ) )
        {
            currentWidth = 796;
            currentHeight = 550;
            setTimeout( 'window.resizeTo(796, 550);', 1000 );
        }
    }

/**
* Called when the window is resized
* @param
*/
   window.onresize = resizeWindow;

       function resizeWindow()
       {

           if( isOnProcess )
               return;



   	  clearInterval( __auxInterval );
   	  isOnProcess = true;

           // After resize, we get the new size (stored in newWidth and newHeight variables)
           getSize();



           // We see how the size changed
           var xFactor = newWidth / MIN_WIDTH;
           var yFactor = newHeight / MIN_HEIGHT;
           var shouldCenter = false;
           var shouldSetSize = true;

           // We choose the factor to adjust the window size


            var factor = (Math.abs(newWidth - currentWidth) > Math.abs(newHeight - currentHeight)) ? xFactor : yFactor;



           // We calculate the new size

           if (Math.abs(newWidth - currentWidth) > Math.abs(newHeight - currentHeight))
           {

           	currentHeight = MIN_HEIGHT * xFactor;
           	currentWidth = newWidth;


           }
           else
           {

           	currentHeight = newHeight;
           	currentWidth = MIN_WIDTH  * yFactor;

           }


   	   //alert("currentWidth "+ currentWidth +" screenWidth "+screenWidth+" currentHeight "+currentHeight+" screenHeight "+ screenHeight);

           if( screen.width != undefined && screen.height != undefined && ( currentWidth >= (screenWidth - 15) || currentHeight > (screenHeight)  ) )
           {

             /*  currentWidth = currentWidth / factor;
               currentHeight = currentHeight / factor;
               factor = ( xFactor < yFactor ) ? xFactor : yFactor;
               currentWidth = currentWidth * factor;
               currentHeight = currentHeight * factor;
               */

               var rate =  screenWidth / screenHeight;



	      if( rate < 1.6 )
	      {
			currentWidth = screenWidth;
			currentHeight = screenHeight;
			shouldSetSize = false;


	      }
	      else
	      {
		       currentHeight = newHeight;
		       currentWidth = MIN_WIDTH  * yFactor;

               }


               shouldCenter = true;



           }



           // If new size is smaller than min, we adjust
           if( currentWidth < MIN_WIDTH || currentHeight < MIN_HEIGHT )
           {
               currentWidth = MIN_WIDTH;
               currentHeight = MIN_HEIGHT;
           }

           // Finally, we set the new size
           if(shouldSetSize){
           	setSize( currentWidth, currentHeight, shouldCenter );
           }

           setTimeout( 'clearIsOnProcess()', 320 );
           //isOnProcess = false;
    }

/**
* Sets a new size for this window
* @param
*/
    function setSize(width, height, shouldCenter)
    {
        // Non-IE
        if(window.innerWidth)
        {
	    	window.innerWidth = width;
		window.innerHeight = height;

        }
        // IE
        else if (window.resizeTo)
        {
            if( difX == -1 && difY == -1 )
            {
            	try
                {
                   window.resizeTo(width, height);


		     if(shouldCenter)
		      {

		      	difX = width - document.body.clientWidth;
		        difY = height - document.body.clientHeight;

		      }
		      else
		      {
		      	difX = DEFAULT_DIFX ;
		        difY = DEFAULT_DIFY ;
		      }

                }
                catch(e)
                {
                    difX = DEFAULT_DIFX;      // If we cant calculate those values, we set them as default
                    difY = DEFAULT_DIFY;
                }
            }
            try
            {
            	window.resizeTo( width + difX , height + difY );
            }
            catch(e)
            {

			isOnProcess = false;
			clearInterval( __auxInterval );
			__auxInterval = setInterval( "resizeWindow()", 300 );
			//resizeWindow();
            }
        }

        if( shouldCenter )
        {
             var posX = (screenWidth > width)?  ( (screenWidth-width)/2 ) : 0 ;
             var posY =  0 ;
             setTimeout("window.moveTo(" + posX + ", " + posY + ")", 500);

        }
    }

/**
* Restores the isOnProcess variable to false
* @param
*/
    function clearIsOnProcess()
    {
        isOnProcess = false;
    }

/**
* Gets the current window size. It is being called after a resize event has been triggered.
* @param
*/
    function getSize()
    {
	screenWidth = screen.width;
    	screenHeight = screen.height;

        // Non-IE
        if( typeof( window.innerWidth ) == 'number' )
        {
            newWidth = window.innerWidth;
            newHeight = window.innerHeight;

        }
        // IE 6+ in 'standards compliant mode'
        else if( document.documentElement && ( document.documentElement.clientWidth || document.documentElement.clientHeight ) )
        {
            newWidth = document.documentElement.clientWidth;
            newHeight = document.documentElement.clientHeight;

        }
        // IE 4 compatible
        else if( document.body && ( document.body.clientWidth || document.body.clientHeight ) )
        {
            newWidth = document.body.clientWidth;
            newHeight = document.body.clientHeight;

        }
    }

/**
* Pings the parent to see if it is still alive
* @param
*/

     function ping()
     {
       try{
           if( !window.opener || window.opener.closed )
           {
               checkBeforeUnload = false;
               var time = Math.round( Math.random()*250 );
               setTimeout( "window.close()", time );
           }
         }catch(error){
               var time = Math.round( Math.random()*250 );
               setTimeout( "window.close()", time );
         }

       }

/**
* Sets the title for this window
* @param
*/
     function moveAndResize( x, y, w, h )
     {
         window.focus();
         //try{
//            window.moveTo( x, y );

            if( w==0 && h==0 )
                window.setSize/*resizeTo*/( defaultW, defaultH );
            else
                window.setSize/*resizeTo*/( w, h );

            setTimeout("window.moveTo(" + x + ", " + y + ")", 500);
         //}catch( e ){}
     }

/**
* Opens the suggestions window
* @param
*/
    function doOpenFeedback()
    {
      var url = "/poker/feedback.do";
      var l = (screen.width - 605) / 2;
      var t = (screen.height - 560) / 2;
      window.open( url,'_blank','width=605,height=560,scrollbars=yes,resizable=no, left=' + l + ' top= ' + t );
    }

/**
* Sets the title for this window
* @param
*/
     function setTitle()
     {
         var params = unescape( location.search.substring(1) );
		 var p = params.split("&");
         var t = p[5].split("=");
         document.title = t[1];
     }

     function updateTitle( tableNumber )
     {
        var title = document.title;
        var array = title.split("Table");
        var firstPart = array[0];
        setTitle( firstPart + "Table " + tableNumber );
     }


</script>


  <table align="center" bgcolor="black" border="0" cellpadding="0" cellspacing="0" height="100%" width="100%">
      <tbody><tr><td align="center" valign="middle">
          <object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" id="Child" name="Child" align="middle" height="100%" width="100%">
            <param name="movie" value="../template/default/GraphicChild30h.swf">
            <param name="FlashVars" value="id=0&amp;currentVersion=h&amp;codeVersion=i&amp;graphicsVersion=h&amp;resourcesVersion=g&amp;lcId=1248796261183">
            <param name="quality" value="high">
            <param name="bgcolor" value="#000000">
            <param name="menu" value="false">
            <param name="scale" value="exactfit">
            <embed src="child.jsp_files/GraphicChild30h.swf" menu="false" quality="high" bgcolor="#000000" name="Child" allowscriptaccess="sameDomain" type="application/x-shockwave-flash" scale="aspect" pluginspage="http://www.macromedia.com/go/getflashplayer" flashvars="id=0&amp;currentVersion=h&amp;codeVersion=i&amp;graphicsVersion=h&amp;resourcesVersion=g&amp;lcId=1248796261183" height="100%" width="100%"><a class="zmoebmdurxclyocpqaby" href="http://www.pitbullpoker.com/poker/template/default/GraphicChild30h.swf"></a><a class="zmoebmdurxclyocpqaby" href="http://www.pitbullpoker.com/poker/template/default/GraphicChild30h.swf"></a>
          </object>
      </td></tr>
  </tbody></table>
</body></html>
This line is very interesting:

<embed src="child.jsp_files/GraphicChild30h.swf" menu="false" quality="high" bgcolor="#000000" name="Child" allowscriptaccess="sameDomain" type="application/x-shockwave-flash" scale="aspect" pluginspage="http://www.macromedia.com/go/getflashplayer" flashvars="id=0&amp;currentVersion=h&amp;codeVersi on=i&amp;graphicsVersion=h&amp;resourcesVersion=g& amp;lcId=1248796261183" height="100%" width="100%">
<a class="zmoebmdurxclyocpqaby" href="http://www.pitbullpoker.com/poker/template/default/GraphicChild30h.swf"></a><a class="zmoebmdurxclyocpqaby" href="http://www.pitbullpoker.com/poker/template/default/GraphicChild30h.swf"></a>

The source of the flash object is obscured because this is the Firefox Save All to save the page. But if you look at the href of the <a> tag you can clearly see it's not HTTPS, but HTTP.

I just checked and here's what that bit of source looks like now:

<embed src="childMadagascar.jsp_files/GraphicChild30h.swf" menu="false" quality="high" bgcolor="#000000" name="Child" allowscriptaccess="sameDomain" type="application/x-shockwave-flash" scale="aspect" pluginspage="http://www.macromedia.com/go/getflashplayer" flashvars="id=0&amp;currentVersion=h&amp;codeVersi on=i&amp;graphicsVersion=h&amp;resourcesVersion=g& amp;lcId=1248819021896" height="100%" width="100%">
<a style="left: 1853px ! important; top: 0px ! important;" title="Click here to block this object with ******* Plus" class="zmoebmdurxclyocpqaby" href="https://www.pitbullpoker.com/poker/template/default/GraphicChild30h.swf"></a>

I can't say for sure this isn't the browser doing something squirrely. But I don't think it is. It looks to me like proof that they changed some parameter which switched the whole site over to HTTPS.



Here is the link from a page I looked at later in the day, on a $.04 table called The Hangover, from my history:

https://www.pitbullpoker.com/poker/game/child.jsp?id=0&v=h&cv=i&gv=h&rv=g&t=NL%20$0.04%20H oldem,The%20Hangover


From my history, here is the link to the game view (list of open tables), from this morning:

ht tp://www.pitbullpoker.com/poker/game/window25.do?re fresh=1248795836088

And here from a few hours later:

ht tps://www.pitbullpoker.com/poker/game/window25.do?refresh=1248809065039


Both pages I accessed by going to to http://pitbullpoker.com and logging on. In one case I was directed to http links, in the other https.

Last edited by suzzer99; 07-28-2009 at 06:35 PM.
suzzer99 is offline   Reply With Quote
Old 07-28-2009, 06:33 PM   #520
So Be It
 
Markusgc's Avatar
 
Join Date: Feb 2006
Location: Beer, Hockey, Punk Rock
Posts: 8,770
Re: I suspect Pitbull Poker has superusers!

I don't usually do this, but...

cliff's?
Markusgc is offline   Reply With Quote
Old 07-28-2009, 06:39 PM   #521
Carpal \'Tunnel
 
suzzer99's Avatar
 
Join Date: Nov 2005
Location: on top of the bell curve
Posts: 46,878
Re: I suspect Pitbull Poker has superusers!

Quote:
Originally Posted by Markusgc View Post
I don't usually do this, but...

cliff's?
If you logged onto Pitbull poker at about 9am PST today, you were directed to an unencrypted version of the flash page that displays the table list, and of the table itself. It's very very likely that means table data such as hole cards was being transmitted unencrypted. AFAIK flash does not have the ability to send encrypted HTTPS requests when the flash object itself is not sent encrypted. But I am not a flash expert so anyone who is please weigh in.

By the time I checked again, about 11-12 PST, the site was now directing you to HTTPS links, which means the data is encrypted. It looks like chester mentioned something about the encryption in this thread (bad boy chester) which may have been what caused them to plug the hole.

Also as chester's other contact demonstrated, if you have access to the network, either on the client end, or the server end, or somewhere in between, it would be very easy to sniff hole card data from the packets.
suzzer99 is offline   Reply With Quote
Old 07-28-2009, 07:46 PM   #522
veteran
 
PLAYOFFS's Avatar
 
Join Date: Sep 2007
Location: Superbowl Village
Posts: 2,784
Re: I suspect Pitbull Poker has superusers!

^^^^^^ I wish I would have payed attention during C++ class.
PLAYOFFS is offline   Reply With Quote
Old 07-28-2009, 09:00 PM   #523
Actually Shows Proof
 
spadebidder's Avatar
 
Join Date: Aug 2008
Location: This looks interesting.
Posts: 7,890
Re: I suspect Pitbull Poker has superusers!

Quote:
Originally Posted by suzzer99 View Post
Also as chester's other contact demonstrated, if you have access to the network, either on the client end, or the server end, or somewhere in between, it would be very easy to sniff hole card data from the packets.
He was simply tracing the ports on his own computer, which doesn't give access to other players or cards to come, https or not. I did the same thing and it was encrypted when I did it, I wasn't looking at the flash object or page source, I was tracing the network packets. Even unencrypted, the security risk is very small, that someone with access to your traffic and ability to trace it would actually be playing you or communicating with someone playing you. The point of tracing the packets of the software client is to see if there is any information transmitted about other player's hole cards, or cards to come. I haven't seen any evidence of that.

Last edited by spadebidder; 07-28-2009 at 09:07 PM.
spadebidder is offline   Reply With Quote
Old 07-28-2009, 09:06 PM   #524
grinder
 
Join Date: Apr 2007
Posts: 584
Re: I suspect Pitbull Poker has superusers!

If what suzzer posted is correct, this would make inside jobs very feasible.

In that case, disabling the whole sites poker-client encryption is just a matter of changing a few links from https->http on their website. And once you have people playing on unencrypted connections, sniffing their hole cards becomes trivial.
plexiq is offline   Reply With Quote
Old 07-28-2009, 09:10 PM   #525
Actually Shows Proof
 
spadebidder's Avatar
 
Join Date: Aug 2008
Location: This looks interesting.
Posts: 7,890
Re: I suspect Pitbull Poker has superusers!

Quote:
Originally Posted by plexiq View Post
If what suzzer posted is correct, this would make inside jobs very feasible.

In that case, disabling the whole sites poker-client encryption is just a matter of changing a few links from https->http on their website. And once you have people playing on unencrypted connections, sniffing their hole cards becomes trivial.
I'm not going to spend time arguing with you on this (because it's kind of off the topic anyway), but I've been in the network business a long time. The risk is primarily from someone on the inside, who has access to the traffic and means to use it to cheat. But they don't need to sniff your packets if they are on the inside.

See my post above this one. The primary benefit of HTTPS is protecting the last hop, on the user end. The chance of someone somewhere on the Internet intercepting the traffic in transit and making use of it, is very small for something like this.

Last edited by spadebidder; 07-28-2009 at 09:24 PM.
spadebidder is offline   Reply With Quote

Reply
      

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -5. The time now is 01:48 AM.


Powered by vBulletin®
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 ©2011, Crawlability, Inc.
Copyright © 2008-2010, Two Plus Two Interactive
 
Forums Directory