Open Side Menu Go to the Top
Register
Lock poker major security issue Lock poker major security issue

03-11-2012 , 03:19 PM
Quote:
Originally Posted by Unta8
Not even trolling. I literally can't login to the casino, I understand it's a problem for everyone, but my casino doesn't exist exist and there is no way for me to view the source code.
your password is still visible to employees of lock poker tho, which is a big enough security issue in and of itself.
Lock poker major security issue Quote
03-11-2012 , 03:29 PM
Quote:
Originally Posted by deafeye
I informed them about this back in June of '11. The response was they'd get right on it. Nothing has been done. I figured enough time had passed for me to put them on blast.
I just noticed this part. Lol Lock Security.
Lock poker major security issue Quote
03-11-2012 , 04:03 PM
Quote:
Originally Posted by AllBlackDan
Fixing this will take money, most likely YOUR money

Glad Ive not created an account on Merge
What? They have developers that work for them, thats what they're paid to do?
Lock poker major security issue Quote
03-11-2012 , 04:09 PM
Quote:
Originally Posted by SGT RJ
As a reminder (or new info for those unaware), Lock is also the site that had Girah as a pro, and DQed him after he won a Lock challenge but has never been upfront about what they knew or when.

Girah won the challenge via a chip dump from DogIsHead, which even a blind chimpanzee should have been able to see during even a minimal audit.
And Lock also straight up lied about their reasons for DQ'ing Girah before the chip dump was revealed, presumably in an attempt to cover it up.

Quote:
Originally Posted by Unta8
Not even trolling. I literally can't login to the casino, I understand it's a problem for everyone, but my casino doesn't exist exist and there is no way for me to view the source code.
Just because you can't access the casino doesn't mean that others can't see your password there.
Lock poker major security issue Quote
03-11-2012 , 04:43 PM
Quote:
Originally Posted by SGT RJ
As a reminder (or new info for those unaware), Lock is also the site that had Girah as a pro, and DQed him after he won a Lock challenge but has never been upfront about what they knew or when.

Girah won the challenge via a chip dump from DogIsHead, which even a blind chimpanzee should have been able to see during even a minimal audit.
Also the site that poached from all other Merge skins by advertising a bonus 20% rakeback, and then never actually paid it out
Lock poker major security issue Quote
03-11-2012 , 04:45 PM


Lock poker major security issue Quote
03-11-2012 , 04:59 PM
I can't make it work. I can only see a hashed pass.
Lock poker major security issue Quote
03-11-2012 , 05:06 PM
If this is true then jfc...
Lock poker major security issue Quote
03-11-2012 , 05:16 PM
Quote:
Originally Posted by Daddy Warbucks
What? They have developers that work for them, thats what they're paid to do?
Doubtful, what have these developers been doing for the last 9 months?
Lock poker major security issue Quote
03-11-2012 , 05:19 PM
Pathetic. Truly pathetic.
Lock poker major security issue Quote
03-11-2012 , 05:21 PM
Wow this is on a par with Sony Playstation not encrypting their data.

If anyone can't remember how that one ended, here's a reminder

http://www.eweek.com/c/a/Security/So...counts-208028/

Not only are your passwords being stored in plain text for Lock employees to see, but they are also being sent across the internet for anyone to intercept too.

Now that the breach is out in the open, seriously be careful guys. This is a really serious security breach.
Lock poker major security issue Quote
03-11-2012 , 05:23 PM
Anyone tried this on other merge skins?
Lock poker major security issue Quote
03-11-2012 , 05:27 PM
Can't wait to see the excuse Rizen gives us for this one.

And the excuse he gives for staying on board at Lock, claiming that he still hasn't seen any concrete examples of shadiness on their part.

So I guess it's pretty clear that Lock suffers from the same unethical-AND-competent malady that plagued UB for all these years.

Anyone who plays there instead of another Merge skin is insane and must hate money.

Quote:
Originally Posted by DeuceSeven
Anyone tried this on other merge skins?
This would only be able to be tried on the ones that have casinos.

Last edited by SGT RJ; 03-11-2012 at 05:38 PM.
Lock poker major security issue Quote
03-11-2012 , 05:37 PM
Quote:
Originally Posted by Sea Salt
This would only be able to be tried on the ones that have casinos.
Dont they all have casinos?
Lock poker major security issue Quote
03-11-2012 , 05:44 PM
This situation is pretty messed up. Ive read through a tonne of these lock poker threads and I must say Im surprised that 2+2 allows them to have a sub forum here. What is the reason they are allowed here? Im actually curious as to the answer.
Lock poker major security issue Quote
03-11-2012 , 05:45 PM
Quote:
Originally Posted by JimAfternoon
Dont they all have casinos?
No. Hero doesn't have one.

I don't think Black Chip has one, either. I think there's plenty of other Merge skins that don't. In general, casino gambling pisses off the DOJ more than simply offering poker.
Lock poker major security issue Quote
03-11-2012 , 05:46 PM
Quote:
Originally Posted by Byrung
This situation is pretty messed up. Ive read through a tonne of these lock poker threads and I must say Im surprised that 2+2 allows them to have a sub forum here. What is the reason they are allowed here? Im actually curious as to the answer.
Lock poker major security issue Quote
03-11-2012 , 05:59 PM
The casino side is using RTG software. I don't know of any other Merge skin that uses RTG.

I'm pretty sure this is not an RTG software issue. RTG are one of the biggest casino software providers (alongside playtech and MG) and it's pretty battle-worn. Not that they are the most reputable in the world (about half the casinos using RTG are 'rogue' or 'caution' on casinomeister) but the software itself is pretty solid. It's also used on bodog and other reputable skins, some that use the flash, and i tested one and it doesn't have this issue. so it seems a custom lock system they've developed to facilitate account sharing between 'lock' accounts in poker and casino.

Last edited by Hood; 03-11-2012 at 06:05 PM.
Lock poker major security issue Quote
03-11-2012 , 06:21 PM
Quote:
Originally Posted by txpstwx
I can't make it work. I can only see a hashed pass.
+1
Lock poker major security issue Quote
03-11-2012 , 06:25 PM
http://forumserver.twoplustwo.com/sh...42&postcount=5

Quote:
Originally Posted by LockRizen
RTG (the casino side) pushed an update that broke our encryption, we have since pushed a software update out that fixes this. When it was originally reported (what OP in original thread is referring to) we fixed it and then when this new update was pushed it broke it again.

We have taken steps to ensure that future updates won't cause this to happen again. No one should be seeing it anymore, and if for some reason someone does please let me know about it ASAP so I can have the appropriate people look at it.

Thanks

-Rizen
Lock poker major security issue Quote
03-11-2012 , 06:25 PM
Quote:
Originally Posted by Sea Salt
No. Hero doesn't have one.

I don't think Black Chip has one, either. I think there's plenty of other Merge skins that don't. In general, casino gambling pisses off the DOJ more than simply offering poker.
Except for neither PokerStars or FTP offered casino games.
Lock poker major security issue Quote
03-11-2012 , 06:39 PM
Quote:
Originally Posted by AllBlackDan
Doubtful, what have these developers been doing for the last 9 months?
Developing other parts of the software?
Lock poker major security issue Quote
03-11-2012 , 06:56 PM
if this is over https its not nearly as big of a deal as otherwise. (but still bad form!)

edit: obv storing passwords in plaintext is terrible and unforgivable. but loads of places do incorrectly for CS reasons or otherwise and you just never hear about it.
Lock poker major security issue Quote
03-11-2012 , 07:01 PM
Quote:
Originally Posted by ryan0x2
if this is over https its not nearly as big of a deal as otherwise. (but still bad form!)
It's not over https.
Lock poker major security issue Quote
03-11-2012 , 07:09 PM
not sure why this got moved seems like a really big deal.
Lock poker major security issue Quote

      
m