dooglus
Legendary
Offline
Activity: 2940
Merit: 1333
|
|
November 18, 2014, 07:29:27 PM |
|
PD uses 26 lowercase letters and 10 numbers in their seed, so 36 different characters with a length of 64 characters. So 36^64 = 4011991914547630480065053387702443812690402487741812225955731622655455723258857 248542161222254985216 different seeds. The bitcoin network calculates double SHA256 hashes with a speed of 297,275,048.09 GH/s. [...] Ps, I am not that good in math, if there is a problem please correct me, but the idea is clear I think.
One problem I see is that there are many more client seeds than sha256 outputs. So "just" reversing the hash isn't enough. On average you'll find 3.5e22 different server seeds which hash to any given server seed hash, but you'll need to figure out which one is the right one. Not that it matters. Your point stands that reversing a single PD server seed is much harder than reversing any single Bitcoin private key. So instead of typing to steal a few thousand coins from PD, why not steal tens or hundreds of thousands from a rich Bitcoin address? No, I'm saying that it is safer to change the seed everytime. That's it. But I do not expect you to understand this. So, do not worry.
The risk of somebody being able to brute force an sha256 hash is pretty much zero. The risk of a dice site cheating players is significantly higher. It has happened at least twice this year already (on another site). So if your goal is to "protect players and investors" you should go with the provably fair system that pretty much every established dice site uses (SatoshiDice is the only exception I can think of).
|
Just-Dice | ██ ██████████ ██████████████████ ██████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████ ██████████████ ██████ | Play or Invest | ██ ██████████ ██████████████████ ██████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████████████ ██████████████████████ ██████████████ ██████ | 1% House Edge |
|
|
|
grahvity
|
|
November 18, 2014, 07:33:48 PM |
|
The first time I deposited, it took two emails and several days to get a response. Then it took a couple more days to get it deposited. I gambled a little and left the remainder on site. Login the next day aaaaand it's gone.
Good Luck.
|
|
|
|
TradersWay.JC
|
|
November 18, 2014, 07:43:00 PM |
|
The first time I deposited, it took two emails and several days to get a response. Then it took a couple more days to get it deposited. I gambled a little and left the remainder on site. Login the next day aaaaand it's gone.
Good Luck.
Really? I was feeling good about these guys too. While I understand that there was a delay (as they have a lot of customers), did you ever email them or receive a response as to why your coins are gone?
|
Trader's Way - Forex & Binary Options Trading, Accepts Bitcoin - US Traders Accepted Get a 100% Deposit Bonus when you sign up with us. Free VPS with deposits above $1000
|
|
|
DarKSpectrE
|
|
November 18, 2014, 07:47:53 PM |
|
PD uses 26 lowercase letters and 10 numbers in their seed, so 36 different characters with a length of 64 characters. So 36^64 = 4011991914547630480065053387702443812690402487741812225955731622655455723258857 248542161222254985216 different seeds. The bitcoin network calculates double SHA256 hashes with a speed of 297,275,048.09 GH/s. [...] Ps, I am not that good in math, if there is a problem please correct me, but the idea is clear I think.
One problem I see is that there are many more client seeds than sha256 outputs. So "just" reversing the hash isn't enough. On average you'll find 3.5e22 different server seeds which hash to any given server seed hash, but you'll need to figure out which one is the right one. Not that it matters. Your point stands that reversing a single PD server seed is much harder than reversing any single Bitcoin private key. So instead of typing to steal a few thousand coins from PD, why not steal tens or hundreds of thousands from a rich Bitcoin address? No, I'm saying that it is safer to change the seed everytime. That's it. But I do not expect you to understand this. So, do not worry.
The risk of somebody being able to brute force an sha256 hash is pretty much zero. The risk of a dice site cheating players is significantly higher. It has happened at least twice this year already (on another site). So if your goal is to "protect players and investors" you should go with the provably fair system that pretty much every established dice site uses (SatoshiDice is the only exception I can think of). So how did this lucky SOB get the unhashed server seed? Did somebody at Stunna's HQ 'leaked' the seed to this guy? Very likely, yes?
|
|
|
|
Farmer17
|
|
November 18, 2014, 08:31:34 PM |
|
So how did this lucky SOB get the unhashed server seed? Did somebody at Stunna's HQ 'leaked' the seed to this guy? Very likely, yes? Stunna will share the details later this week, and we will soon know how it happened and what went wrong. It's a pretty complex situation, we put in a basic fix which was defeated and now we're taking stronger measures to ensure this doesn't happen again.
Part of fixing the issue is forcing all accounts to set a new seed pair, in an hour expect to be prompted to set a new pair.
I'll be providing full information later this week after we've done some extensive testing. I am comfortable saying that there was no breach of server or database and all account balances are 100% safe, no accounts should be effected by this issue it only effects us.
|
|
|
|
caga
Full Member
Offline
Activity: 238
Merit: 100
www.secondstrade.com - 190% return Binary option
|
|
November 18, 2014, 08:38:32 PM |
|
So how did this lucky SOB get the unhashed server seed? Did somebody at Stunna's HQ 'leaked' the seed to this guy? Very likely, yes? I doubt that Stunna allows anyone on his HQ to have information regarding the seed, as they could take advantage themselves.
|
|
|
|
|
Omikifuse
Legendary
Offline
Activity: 1848
Merit: 1009
|
|
November 18, 2014, 09:01:00 PM |
|
The oldest trick known since the beginning. No way to fix unless you forbid people vs people games or put a minimum bet bigger than the faucet claim
|
|
|
|
Gianluca95
Legendary
Offline
Activity: 1624
Merit: 1196
Reputation first.
|
|
November 18, 2014, 09:57:10 PM |
|
I'm so sad about the problem of PrimeDice and hope that Stunna will solve it as soon as possible. It's very strange to see this cheaters in the biggest bitcoin casinò
|
|
|
|
MadZ
|
|
November 18, 2014, 10:03:58 PM |
|
This is actually no faster than going all in on your first bet to hit 50k tip minimum and then sending it to another account, it just has less variance.
|
|
|
|
adaseb
Legendary
Offline
Activity: 3878
Merit: 1733
|
|
November 18, 2014, 10:49:05 PM |
|
Yes I agree but honestly this is going on with anything related to Bitcoin.
And its actually one of the reasons why BTC might fail in the future. Due to people like that.
|
|
|
|
philiveyjr
Legendary
Offline
Activity: 840
Merit: 1000
|
|
November 18, 2014, 11:43:29 PM |
|
This is actually no faster than going all in on your first bet to hit 50k tip minimum and then sending it to another account, it just has less variance. The Process listed on it would take ages to make some respectable amount.!! lol..!! kinda useless it is.!
|
|
|
|
Malin Keshar
|
|
November 19, 2014, 12:10:09 AM |
|
People cheating for 100's of coins and people bothering with people abusing faucet for $1/hour or less.
Too many work for too much job, guess it is not much used
|
|
|
|
coingamblingreviews
Legendary
Offline
Activity: 1043
Merit: 1032
★Bitcoin Gambling Reviews★
|
|
November 19, 2014, 12:38:41 AM |
|
What countries does Prime Dice block players from playing from?
|
|
|
|
Omikifuse
Legendary
Offline
Activity: 1848
Merit: 1009
|
|
November 19, 2014, 12:48:08 AM |
|
What countries does Prime Dice block players from playing from?
none, as far I know
|
|
|
|
ranochigo
Legendary
Offline
Activity: 3038
Merit: 4420
Crypto Swap Exchange
|
|
November 19, 2014, 01:16:46 AM |
|
What countries does Prime Dice block players from playing from?
none, as far I know Wrong, AFAIK, Stunna said people from Australia will not be allowed to register a long time ago. Due to regulatory laws and legal advice, Primedice 3 will not be allowing Australian users to register.
Sorry to all those who this affects.
Just use a VPN or Tor to bypass this, it's easy.
|
|
|
|
Omikifuse
Legendary
Offline
Activity: 1848
Merit: 1009
|
|
November 19, 2014, 01:23:32 AM |
|
What countries does Prime Dice block players from playing from?
none, as far I know Wrong, AFAIK, Stunna said people from Australia will not be allowed to register a long time ago. Due to regulatory laws and legal advice, Primedice 3 will not be allowing Australian users to register.
Sorry to all those who this affects.
Just use a VPN or Tor to bypass this, it's easy. How if Stunna himself is from Australia?
|
|
|
|
Dabs
Legendary
Offline
Activity: 3416
Merit: 1912
The Concierge of Crypto
|
|
November 19, 2014, 03:47:52 AM |
|
PD uses 26 lowercase letters and 10 numbers in their seed, so 36 different characters with a length of 64 characters.
I'm going to use UPPERCASE LETTERS too, that should improve my anti-bruteforce-ability of my seeds right? (kidding...)
|
|
|
|
trekk
Newbie
Offline
Activity: 6
Merit: 0
|
|
November 19, 2014, 04:11:37 AM |
|
Hi, my account is Trekk.
I was playing in primedice for months and i won like 0.1 BTC from faucet and too much fun... so i decided desposit 8.5 BTC to get more lvl and faucet and of corse, try to win... i lose all but i get a GOOD faucet.
A week ago i don't know why my BTC WAGERED was restarted, and i do nothing because my english is not good and anyone was avaliable to help me and traslate my words.
Today i use google traductor to comunicate with PD support for this problem and these were his answers: "Chat messages no longer count towards faucet. The faucet is free coin that we offer users and can change at any time." So... i say, i have -8.1 BTC profit, and 0.054 BTC waraged... that is imposible
After send my email, i checked my account again and MAGIC my BTC waraged is 0.000000 and lvl 0 again, can't use chat when i really need some help.
Finally the last replay was: "Your account was botting the faucet along with other accounts."
I know nothing about that, i just play and claim faucet every 3 minutes and if i get 0.001 or more just withdraw and start again... so, be carefull, if you claim faucet a lot, you will marked as a BOT and they will restart your stats and steal your money and time invested.
PD: Sorry for my bad english, a friend did his best to translate this.
|
|
|
|
Stunna (OP)
Legendary
Offline
Activity: 3192
Merit: 1279
Primedice.com, Stake.com
|
|
November 19, 2014, 04:20:38 AM |
|
Hi, my account is Trekk.
I was playing in primedice for months and i won like 0.1 BTC from faucet and too much fun... so i decided desposit 8.5 BTC to get more lvl and faucet and of corse, try to win... i lose all but i get a GOOD faucet.
A week ago i don't know why my BTC WAGERED was restarted, and i do nothing because my english is not good and anyone was avaliable to help me and traslate my words.
Today i use google traductor to comunicate with PD support for this problem and these were his answers: "Chat messages no longer count towards faucet. The faucet is free coin that we offer users and can change at any time." So... i say, i have -8.1 BTC profit, and 0.054 BTC waraged... that is imposible
After send my email, i checked my account again and MAGIC my BTC waraged is 0.000000 and lvl 0 again, can't use chat when i really need some help.
Finally the last replay was: "Your account was botting the faucet along with other accounts."
I know nothing about that, i just play and claim faucet every 3 minutes and if i get 0.001 or more just withdraw and start again... so, be carefull, if you claim faucet a lot, you will marked as a BOT and they will restart your stats and steal your money and time invested.
PD: Sorry for my bad english, a friend did his best to translate this.
Here's the address you were cashing out to: https://blockchain.info/address/1KcWYJ24WGq4n3UTjZTX8UHpGFktBCamyaThis address was used by over 40 Primedice accounts to cash out to 24/7. You were abusing the faucet and ruining it for all the people who do it legitimately. If it wasn't for people like you the faucet would be up to 5x higher. Not to mention the amount of claims you made per day would reflect you have slept for a little over 24 minutes in the last 2 weeks. Nice.
|
|
|
|
|