Bitcoin Forum
July 01, 2024, 07:42:06 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: Luckynumber.me has holes in their provably fair system, allows for manipulation  (Read 3321 times)
RGBKey (OP)
Hero Member
*****
Offline Offline

Activity: 854
Merit: 658


rgbkey.github.io/pgp.txt


View Profile WWW
April 24, 2014, 11:33:36 AM
 #1

Luckynumber.me is not provably fair, because of the inclusion of time down to the millisecond in the decision of the final roll, this is why.

Say you make a bet at 3:34 PM, 13.23 seconds. The outcome of the roll was a win.

Luckynumber looks at your roll and calculates that it would be a win. So they pretend the server got the message a millisecond later. Let's do a new roll with a new time.

Your bet was now made at 3:34 PM, 13.24 seconds. The outcome of this roll is a loss.

This allows for major roll manipulation. They don't have to do this every bet. They can just do it on larger bets, or once every 20 rolls or so. It doesn't matter if some people win because they still have to keep their image up.

They can also repeat the time process multiple times until they get a losing roll.

You might say that you can see the clock at the bottom of the game and you know exactly when you clicked roll. Did you really? Do you know exactly how long it takes the message to get to the server and for the server to record the time? These are all things that can be used against you.

Gamble carefully.
roslinpl
Legendary
*
Offline Offline

Activity: 2212
Merit: 1199


View Profile WWW
April 24, 2014, 12:12:00 PM
 #2

Thanks for a warning.

This seems like dangerous for players and for them in a same time.

I hope they will read your post and maybe will change something in their system.

Regards
Stunna
Legendary
*
Offline Offline

Activity: 3192
Merit: 1279


Primedice.com, Stake.com


View Profile
April 24, 2014, 04:33:20 PM
 #3

Something I also noticed:

Quote from: stunna
Another ridiculous detail is that the server time on site is different to actual server time as it uses javascript to calc individual server times. I have both my laptops open on luckynumber and the time is off by 2 sec. So effectively he can choose between the best few server times (with ease)

Given that they offer 60 coin payouts for individual bets with a very small bank it makes this possibility more concerning. This all goes without saying that giftcoins was unethical in stealing actual design files from PD that were unreleased, not just images. I will post more about that in the near future.

Stake.com Fastest growing crypto casino & sportsbook
Primedice.com The original bitcoin instant dice game
sana8410
Sr. Member
****
Offline Offline

Activity: 448
Merit: 250



View Profile
May 01, 2014, 12:58:12 AM
 #4

good catch guys, anyway they can get the scammer tag???

RENT MY SIG FOR A DAY
Rupture
Full Member
***
Offline Offline

Activity: 182
Merit: 100


View Profile
May 01, 2014, 02:39:07 AM
 #5

The forum does not do scammer tags.
coinnewbit
Sr. Member
****
Offline Offline

Activity: 266
Merit: 250



View Profile
May 01, 2014, 07:10:18 AM
 #6

Wow. No wonder I have lost so much money there.
kleineaap
Hero Member
*****
Offline Offline

Activity: 532
Merit: 500


View Profile
May 01, 2014, 08:31:20 AM
 #7

In my opinion there is no ideal system for off-chain sites right now, I have voiced my opinion that someone should develop an open-source standard and require all sites to run it to be "provably fair".

Even Stunna is acknowledging that every system has no ideal provably fairness.
New developments have to be made to end this scam accusations that lack insight.
I think this thread is pretty closed then.

| Minexcoin A new era of payments

LINK TO ICO | LINK TO DISCUSSION
Varicon
Member
**
Offline Offline

Activity: 90
Merit: 10



View Profile
May 01, 2014, 09:05:54 AM
 #8

In my opinion there is no ideal system for off-chain sites right now, I have voiced my opinion that someone should develop an open-source standard and require all sites to run it to be "provably fair".

Even Stunna is acknowledging that every system has no ideal provably fairness.
New developments have to be made to end this scam accusations that lack insight.
I think this thread is pretty closed then.

I'd agree in saying that each system has its flaws, but the way this site implements it's provably fair allows for a much easier way for rolls to be manipulated, there isn't a 100% sure-fire way to know that your roll hasn't been manipulated. Other sites display a non-changing nonce (displayed before rolls) or an editable field, which as long as we record the nonce or edit our client-seed we can be sure our roll is not manipulated. We can neither edit or be sure of the time that the roll was placed because the time ticks by too quickly and as pointed out by another user, the time isn't even accurate.
kleineaap
Hero Member
*****
Offline Offline

Activity: 532
Merit: 500


View Profile
May 01, 2014, 09:18:30 AM
 #9

In my opinion there is no ideal system for off-chain sites right now, I have voiced my opinion that someone should develop an open-source standard and require all sites to run it to be "provably fair".

Even Stunna is acknowledging that every system has no ideal provably fairness.
New developments have to be made to end this scam accusations that lack insight.
I think this thread is pretty closed then.

I'd agree in saying that each system has its flaws, but the way this site implements it's provably fair allows for a much easier way for rolls to be manipulated, there isn't a 100% sure-fire way to know that your roll hasn't been manipulated. Other sites display a non-changing nonce (displayed before rolls) or an editable field, which as long as we record the nonce or edit our client-seed we can be sure our roll is not manipulated. We can neither edit or be sure of the time that the roll was placed because the time ticks by too quickly and as pointed out by another user, the time isn't even accurate.

Sure thing. But I'd risk to say that 99.9% of the players on PD, for example, do not change client seed every bet.
Is it not - statistically - the same room for manipulation on both sites? Considering that both can, at their will, manipulate the rolls. The thing is that they don't. The problem is on the system itself, they have different provably fairs, and hopefully they can both change them one day, when a new system arrives that is more foolproof than now.

It's almost a linguistics question. People are saying that LN can't affirm it's provably fair because they cannot prove it's fair. But PD can't prove its fair system either, if client seed is not changed. Yet they are provably fair?  Huh
I think there are accusations being made that are pointless, yet very serious because they are alarming users that don't understand how this fair system works.

Truth is we need a new system, to end up all this misunderstandings.
I'm pretty much sure that PD and LN are not manipulating anything, though.

| Minexcoin A new era of payments

LINK TO ICO | LINK TO DISCUSSION
coinnewbit
Sr. Member
****
Offline Offline

Activity: 266
Merit: 250



View Profile
May 01, 2014, 09:19:52 AM
 #10

In my opinion there is no ideal system for off-chain sites right now, I have voiced my opinion that someone should develop an open-source standard and require all sites to run it to be "provably fair".

Even Stunna is acknowledging that every system has no ideal provably fairness.
New developments have to be made to end this scam accusations that lack insight.
I think this thread is pretty closed then.

I'd agree in saying that each system has its flaws, but the way this site implements it's provably fair allows for a much easier way for rolls to be manipulated, there isn't a 100% sure-fire way to know that your roll hasn't been manipulated. Other sites display a non-changing nonce (displayed before rolls) or an editable field, which as long as we record the nonce or edit our client-seed we can be sure our roll is not manipulated. We can neither edit or be sure of the time that the roll was placed because the time ticks by too quickly and as pointed out by another user, the time isn't even accurate.

Sure thing. But I'd risk to say that 99.9% of the players on PD, for example, do not change client seed every bet.
Is it not - statistically - the same room for manipulation on both sites? Considering that both can, at their will, manipulate the rolls. The thing is that they don't. The problem is on the system itself, they have different provably fairs, and hopefully they can both change them one day, when a new system arrives that is more foolproof than now.

It's almost a linguistics question. People are saying that LN can't affirm it's provably fair because they cannot prove it's fair. But PD can't prove its fair system either, if client seed is not changed. Yet they are provably fair?  Huh
I think there are accusations being made that are pointless, yet very serious because they are alarming users that don't understand how this fair system works.

Truth is we need a new system, to end up all this misunderstandings.
I'm pretty much sure that PD and LN are not manipulating anything, though.
I saw you on Luckynumber chat just now!
kleineaap
Hero Member
*****
Offline Offline

Activity: 532
Merit: 500


View Profile
May 01, 2014, 09:21:36 AM
 #11

So what?

| Minexcoin A new era of payments

LINK TO ICO | LINK TO DISCUSSION
coinnewbit
Sr. Member
****
Offline Offline

Activity: 266
Merit: 250



View Profile
May 01, 2014, 09:27:21 AM
 #12

So what?
Nothing much.
kleineaap
Hero Member
*****
Offline Offline

Activity: 532
Merit: 500


View Profile
May 01, 2014, 09:28:28 AM
 #13


Heh. You see me in PD too Smiley

| Minexcoin A new era of payments

LINK TO ICO | LINK TO DISCUSSION
Varicon
Member
**
Offline Offline

Activity: 90
Merit: 10



View Profile
May 01, 2014, 10:40:58 AM
 #14

I can change the game type and client seed at my will to at least make sure my bets are fine. Not that I change it every roll, but I frequently change game type so that's also one method.
RGBKey (OP)
Hero Member
*****
Offline Offline

Activity: 854
Merit: 658


rgbkey.github.io/pgp.txt


View Profile WWW
May 01, 2014, 01:34:10 PM
 #15

In my opinion there is no ideal system for off-chain sites right now, I have voiced my opinion that someone should develop an open-source standard and require all sites to run it to be "provably fair".

Even Stunna is acknowledging that every system has no ideal provably fairness.
New developments have to be made to end this scam accusations that lack insight.
I think this thread is pretty closed then.

I'd agree in saying that each system has its flaws, but the way this site implements it's provably fair allows for a much easier way for rolls to be manipulated, there isn't a 100% sure-fire way to know that your roll hasn't been manipulated. Other sites display a non-changing nonce (displayed before rolls) or an editable field, which as long as we record the nonce or edit our client-seed we can be sure our roll is not manipulated. We can neither edit or be sure of the time that the roll was placed because the time ticks by too quickly and as pointed out by another user, the time isn't even accurate.

Sure thing. But I'd risk to say that 99.9% of the players on PD, for example, do not change client seed every bet.
Is it not - statistically - the same room for manipulation on both sites? Considering that both can, at their will, manipulate the rolls. The thing is that they don't. The problem is on the system itself, they have different provably fairs, and hopefully they can both change them one day, when a new system arrives that is more foolproof than now.

It's almost a linguistics question. People are saying that LN can't affirm it's provably fair because they cannot prove it's fair. But PD can't prove its fair system either, if client seed is not changed. Yet they are provably fair?  Huh
I think there are accusations being made that are pointless, yet very serious because they are alarming users that don't understand how this fair system works.

Truth is we need a new system, to end up all this misunderstandings.
I'm pretty much sure that PD and LN are not manipulating anything, though.

The major difference is that Primedice, you can change your client seed every roll. If you don't, it's negligence and your own fault. If you bet on lucky number you're already giving up the fairness as soon as you roll.
kleineaap
Hero Member
*****
Offline Offline

Activity: 532
Merit: 500


View Profile
May 01, 2014, 04:10:52 PM
 #16

In my opinion there is no ideal system for off-chain sites right now, I have voiced my opinion that someone should develop an open-source standard and require all sites to run it to be "provably fair".

Even Stunna is acknowledging that every system has no ideal provably fairness.
New developments have to be made to end this scam accusations that lack insight.
I think this thread is pretty closed then.

I'd agree in saying that each system has its flaws, but the way this site implements it's provably fair allows for a much easier way for rolls to be manipulated, there isn't a 100% sure-fire way to know that your roll hasn't been manipulated. Other sites display a non-changing nonce (displayed before rolls) or an editable field, which as long as we record the nonce or edit our client-seed we can be sure our roll is not manipulated. We can neither edit or be sure of the time that the roll was placed because the time ticks by too quickly and as pointed out by another user, the time isn't even accurate.

Sure thing. But I'd risk to say that 99.9% of the players on PD, for example, do not change client seed every bet.
Is it not - statistically - the same room for manipulation on both sites? Considering that both can, at their will, manipulate the rolls. The thing is that they don't. The problem is on the system itself, they have different provably fairs, and hopefully they can both change them one day, when a new system arrives that is more foolproof than now.

It's almost a linguistics question. People are saying that LN can't affirm it's provably fair because they cannot prove it's fair. But PD can't prove its fair system either, if client seed is not changed. Yet they are provably fair?  Huh
I think there are accusations being made that are pointless, yet very serious because they are alarming users that don't understand how this fair system works.

Truth is we need a new system, to end up all this misunderstandings.
I'm pretty much sure that PD and LN are not manipulating anything, though.

The major difference is that Primedice, you can change your client seed every roll. If you don't, it's negligence and your own fault. If you bet on lucky number you're already giving up the fairness as soon as you roll.

I understand exactly what you mean, but saying you are giving up on fairness is quite a bold statement, and it's not entirely true.
Saying there are holes in that provably fair system is correct, as in the title of this thread. Otherwise you have users that can interpret your words and extend them right away to "scam website".
Heck, you posted this thread in Scam Accusations, which is not correct. Having a faulty provabilty fair system doesn't mean you are running a scam. Loads of other sites have and had problems with this system.

About Primedice, I have to say then that the majority actually give up on the fairness then, even Stunna said somewhere that most users don't change client seeds.
Is it their negligence? Yes, yet you will have accusations of manipulation, and eventually get responses "What, then I have to change seed every bet otherwise it's my fault and they are allowed to manipulate my roll?"

I'm trying to discuss the system here, which in my belief should be upgraded from the current we have now.

Hope you understand my two cents.

| Minexcoin A new era of payments

LINK TO ICO | LINK TO DISCUSSION
zeeshanblc
Sr. Member
****
Offline Offline

Activity: 390
Merit: 250



View Profile
May 01, 2014, 04:34:26 PM
 #17


well when I take a look at their high bets it doesn't look like they are scammers and manipulating



That guy made over 5BTC in 8min

RGBKey (OP)
Hero Member
*****
Offline Offline

Activity: 854
Merit: 658


rgbkey.github.io/pgp.txt


View Profile WWW
May 02, 2014, 03:41:35 AM
 #18


well when I take a look at their high bets it doesn't look like they are scammers and manipulating



That guy made over 5BTC in 8min


Why would they make it obvious?
RGBKey (OP)
Hero Member
*****
Offline Offline

Activity: 854
Merit: 658


rgbkey.github.io/pgp.txt


View Profile WWW
May 07, 2014, 01:56:25 PM
 #19

Bump.
kleineaap
Hero Member
*****
Offline Offline

Activity: 532
Merit: 500


View Profile
May 07, 2014, 02:14:48 PM
 #20

In my opinion there is no ideal system for off-chain sites right now, I have voiced my opinion that someone should develop an open-source standard and require all sites to run it to be "provably fair".

Even Stunna is acknowledging that every system has no ideal provably fairness.
New developments have to be made to end this scam accusations that lack insight.
I think this thread is pretty closed then.

I'd agree in saying that each system has its flaws, but the way this site implements it's provably fair allows for a much easier way for rolls to be manipulated, there isn't a 100% sure-fire way to know that your roll hasn't been manipulated. Other sites display a non-changing nonce (displayed before rolls) or an editable field, which as long as we record the nonce or edit our client-seed we can be sure our roll is not manipulated. We can neither edit or be sure of the time that the roll was placed because the time ticks by too quickly and as pointed out by another user, the time isn't even accurate.

Sure thing. But I'd risk to say that 99.9% of the players on PD, for example, do not change client seed every bet.
Is it not - statistically - the same room for manipulation on both sites? Considering that both can, at their will, manipulate the rolls. The thing is that they don't. The problem is on the system itself, they have different provably fairs, and hopefully they can both change them one day, when a new system arrives that is more foolproof than now.

It's almost a linguistics question. People are saying that LN can't affirm it's provably fair because they cannot prove it's fair. But PD can't prove its fair system either, if client seed is not changed. Yet they are provably fair?  Huh
I think there are accusations being made that are pointless, yet very serious because they are alarming users that don't understand how this fair system works.

Truth is we need a new system, to end up all this misunderstandings.
I'm pretty much sure that PD and LN are not manipulating anything, though.

Friendly reminder.

| Minexcoin A new era of payments

LINK TO ICO | LINK TO DISCUSSION
Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!