Two Plus Two Publishing LLC Two Plus Two Publishing LLC
 

Go Back   Two Plus Two Poker Forums > General Poker Discussion > News, Views, and Gossip

News, Views, and Gossip For poker news, views, and gossip

Reply
 
Thread Tools Display Modes
Old 07-26-2010, 03:48 PM   #1
centurion
 
Join Date: Jan 2010
Location: Washington D.C.
Posts: 106
Cake encryption vulnerabilities (update from Lee Jones)

PTR posted another security update about cake, basically showing that you can crack the encryption with programs freely available (which I will not mention here, but I'm sure people familiar with linux know what it is), and gain access to account information, login/password as well as holecard information.

Quote:
Originally Posted by PTR
Suggestions for Players

As suggested previously there is no way to be 100% secure at the moment while playing on Cake poker. It is not possible to know that you’re safe, even when plugged directly into your router.

The only guarantee of safety is to change your password, and stop playing on the Cake network until these issues have been fully resolved and verified by us. Until Cake has switched to OpenSSL, or the TwoFish encryption their webpage says they use, there is no way to be sure you are secured.

If you must continue to play in the mean time you should plug directly into your router or cable modem. If this is not an option you should make absolutely sure your wireless network is encrypted using WPA2 encryption.

Do NOT play on any unknown or public networks, especially wireless network. Also it may be wise to keep the fact that you play on the Cake network to yourself so as to avoid making yourself a target.
KrazyOranges is offline   Reply With Quote
Old 07-26-2010, 03:59 PM   #2
grinder
 
wiggum's Avatar
 
Join Date: Jul 2007
Location: ITT
Posts: 417
Re: Cake encryption vulnerabilities

Cake is really trying hard to be like UB. The ship the pot to the wrong person bug a few months back, and now this.
wiggum is offline   Reply With Quote
Old 07-26-2010, 04:05 PM   #3
Rigged for her pleasure
 
bellatrix's Avatar
 
Join Date: Dec 2005
Location: bloggin'
Posts: 4,253
Re: Cake encryption vulnerabilities

Paging Lee Jones!
bellatrix is offline   Reply With Quote
Old 07-26-2010, 04:05 PM   #4
adept
 
jmrd27's Avatar
 
Join Date: Dec 2009
Location: Montreal
Posts: 1,115
Re: Cake encryption vulnerabilities

hmmmm wtf
jmrd27 is offline   Reply With Quote
Old 07-26-2010, 04:10 PM   #5
Is Right
 
NoahSD's Avatar
 
Join Date: Aug 2005
Posts: 17,771
Re: Cake encryption vulnerabilities

1) This is a legitimate risk. I wouldn't play on Cake right now.

2) It appears that somebody at Cake was intentionally deceptive. Their web site claims that they use a method of encryption (256-bit TwoFish) for all of their network traffic and even specifically says that what PTR did is impossible. They also recently rewrote their software from the ground up and had the exact same flaw in place, so they can't have simply been relying on the promises of people who worked way in the past.

Here's the statement that's still on Cake Poker's web site: "All communications between the client program running on your computer and the Cake Poker server in Curacao are encrypted using the accepted industry standard 256-bit TwoFish encryption algorithm. The unique cards dealt to each player are delivered exclusively to that particular player's computer thus maintaining privacy and integrity of play. Packet-sniffing by other players cannot be used to gain any advantage. Each player's cards are sent exclusively to that particular player's computer. None of the other computers know what your hidden cards are, thus preventing an opponent from hacking their client software to determine your cards." http://cakepoker.com/en/PlayPoker/Re.../Security.aspx

3) Whereas Cereus was a company that pretty much everyone agreed was scummy and incompetent, Cake is generally very well respected.

4) Cereus handled their situation well by acknowledging the risk publicly, but they did not shut down their network in spite of the legitimate security risk to their customers. We still have no clue if anyone lost money because of this, and we likely never will. Let's see if Cake handles this better.

5) Cake needs to open an independent investigation into whether or not this exploit was ever used against its customers. Of course, there's legitimate question as to whether or not there's any company that's up to the task since it's clear that the people who claim to license and regulate this industry are completely incompetent.

6) Lee Jones works for Cake and is widely regarded as a totally stand-up guy. I'd like to think that his presence will lead to Cake handling this well, but I won't bet on it.

7) We really really need online poker to be licensed and regulated by a government that has the ability to prevent problems like this. The fact that two different networks had a huge security flaw that was easily detectable for years but nobody bothered to find it, including the multiple people who claim to certify the security of these sites, the various players on the sites, and the site's own security departments shows that we need a new system.
NoahSD is offline   Reply With Quote
Old 07-26-2010, 04:20 PM   #6
veteran
 
Slap My Jack's Avatar
 
Join Date: Jan 2006
Location: VERIFIED COOCH
Posts: 2,872
Re: Cake encryption vulnerabilities

Quote:
Originally Posted by wiggum View Post
Cake is really trying hard to be like UB. The ship the pot to the wrong person bug a few months back, and now this.
I'd say the opposite is true.

Cake is trying really hard NOT to be like UB.

Lee Jones seems to have the right idea about the direction to take and the need for new software.

Plus, he is actually open about addressing major issues. I'd lay money that he posts on 2p2 about this soon.

Give credit where it's due.

Plus Cake's customer support has been faster than any other site on average, for the last several months, even Stars.

Hopefully Lee Jones takes care of the exploitation of the game by shortstack grinders, like FTP, rather than encouraging it like Pokerstars.
Slap My Jack is offline   Reply With Quote
Old 07-26-2010, 04:27 PM   #7
centurion
 
Join Date: Feb 2010
Location: Mississippi
Posts: 115
Re: Cake encryption vulnerabilities

Quote:
Originally Posted by Slap My Jack View Post
Plus Cake's customer support has been faster than any other site on average, for the last several months, even Stars.
No doubt.
fourfades is offline   Reply With Quote
Old 07-26-2010, 04:31 PM   #8
old hand
 
Join Date: Jan 2010
Posts: 1,699
Re: Cake encryption vulnerabilities

here we go again. badhum
spankedtwice is offline   Reply With Quote
Old 07-26-2010, 04:36 PM   #9
veteran
 
DunlopFuzzy's Avatar
 
Join Date: Mar 2010
Location: On a pair draw
Posts: 2,157
Re: Cake encryption vulnerabilities

Quote:
Originally Posted by Slap My Jack View Post
Plus Cake's customer support has been faster than any other site on average, for the last several months, even Stars.
Great, they'll be the fastest to feed you some form letter bs as to why this is happening. It's ok though, it will be fast.
DunlopFuzzy is offline   Reply With Quote
Old 07-26-2010, 04:45 PM   #10
veteran
 
Flip-Flop's Avatar
 
Join Date: Jun 2007
Posts: 2,127
Re: Cake encryption vulnerabilities

From the official cake feedback thread:

Quote:
Originally Posted by Lee Jones View Post
We're on this right now - I'll post here when I know more. This is news to me too.

Best regards,
Lee Jones

Cake Poker Cardroom Manager
Flip-Flop is offline   Reply With Quote
Old 07-26-2010, 04:46 PM   #11
adept
 
Romi's Avatar
 
Join Date: May 2010
Posts: 770
Re: Cake encryption vulnerabilities

Just read about this on PTR, shocking
Romi is offline   Reply With Quote
Old 07-26-2010, 04:48 PM   #12
Is Right
 
NoahSD's Avatar
 
Join Date: Aug 2005
Posts: 17,771
Re: Cake encryption vulnerabilities

I *think* Lee Jones meant to post this in this thread, since linking a thread to itself seems silly:


Quote:
Originally Posted by Lee Jones View Post
This is being discussed on the Cake Feedback thread. I will post everything I know about the situation there.

Best regards,
Lee Jones

Cake Poker Cardroom Manager
NoahSD is offline   Reply With Quote
Old 07-26-2010, 04:51 PM   #13
veteran
 
Flip-Flop's Avatar
 
Join Date: Jun 2007
Posts: 2,127
Re: Cake encryption vulnerabilities

Noah he posted that in another thread that got merged with the official, that's why you see it there.
Flip-Flop is offline   Reply With Quote
Old 07-26-2010, 05:20 PM   #14
centurion
 
Basalt13's Avatar
 
Join Date: Jun 2010
Posts: 193
Re: Cake encryption vulnerabilities

TBH, how much do you think PTR is getting paid by the US government to "find" all these security leaks.
Basalt13 is offline   Reply With Quote
Old 07-26-2010, 05:22 PM   #15
Carpal \'Tunnel
 
Scary_Tiger's Avatar
 
Join Date: Oct 2005
Location: United States
Posts: 19,723
Re: Cake encryption vulnerabilities

Quote:
Originally Posted by Basalt13 View Post
TBH, how much do you think PTR is getting paid by the US government to "find" all these security leaks.
I'm gonna go with 0.
Scary_Tiger is offline   Reply With Quote

Reply
      

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -5. The time now is 12:29 AM.


Powered by vBulletin®
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 ©2011, Crawlability, Inc.
Copyright © 2008-2010, Two Plus Two Interactive
 
Forums Directory