It appears that the Cereus Poker network has some serious security flaws. According to Poker Table Ratings, Ultimate Bet uses a flawed encryption system which is vulnerable to malicious hacks. According to PTR:
It appears that this security hole allows your log-in/password info to be picked up by the hackers as well... so technically, your money could be stolen/transferred to another account or someone could log-in and play under your account.PokerTableRatings has discovered a critical flaw in the Cereus Poker software which affects both Absolute Poker and Ultimate Bet, allowing an attacker to hijack victim’s poker accounts and display their hole cards in real time. We have alerted the Cereus Network to this vulnerability, providing them with source code necessary to demonstrate the problem. We hope our e-mail and this bulletin are sufficient motivation for them to fix the problem.
I've included a few interesting snippets from the thread running on 2 Plus 2:
Nobody really knows who is writing code for the company now. The CTO of Excapsa started a subsidiary called RealTimeEdge several years ago which handled all programming and software updates. When Excapsa dissolved, this company was not included in the asset sale to Blast Off, though they did continue on in a support role for the new company; likely as a contractor.
Now, RTE is very busy because with the impending default of BO against the promissory note, Excapsa (now Aspacxe, seriously you cannot make this **** up) made a deal to take back the software IP which they have apparently been using to write/modify/or emulate in a new product/site called Spotlight poker which is set to be rolled out. Since RTE is a soon to be competitor to UB/AP along with the already contentious situation between the original company and the licensor/purchasor, its possible CEREUS doesn't really have much in the way of programming resources at all.
This is all very bad. Having said that, I will take the under that traffic doesn't drop more than 10% in the next month as rated by Pokersitescout. There is no shortage of people who play slots at rural tribal casinos when the yellowhammer guys will actually tell you the payouts are set in the mid 70 percent range. And for whatever inane reasons they give, people will continue to deposit and play poker at UB/AP along with vapid player reps and besotted management shills.
Statement from KGC (Kahnawake Gaming Commission)
The Commission has been advised of a security issue concerning the CEREUS poker network used by the Absolute Poker and Ultimate Bet poker sites. The issue concerns the mechanism used by CEREUS for network transmissions having a potential for player data to be improperly accessed under certain specific circumstances.
The Commission is actively reviewing this matter with senior management of Absolute Poker and Ultimate Bet and with its Approved Agents. The Commission will issue a further notice of its findings as soon as this review is completed. The Commission is monitoring immediate measures that are being taken to address the security issue and is advised that a more permanent solution is to be implemented on an urgent basis.
Based on information available at this time, it appears unlikely that player data was actually compromised. However, this possibility will be reviewed further and, if necessary, the Commission will direct that the appropriate remedial actions be taken. Until a solution to the security issue is fully implemented, the Commission recommends that players use caution when accessing the Absolute Poker or Ultimate Bet sites, in particular when using a public network (wired or wireless) or a private wireless network. For further information, please contact the Kahnawake Gaming Commission at [email protected]
Ultimatebet released the following statement on their blog:
Hello UB’ers,
One hour ago, I learned about an article posted today on Poker Table Ratings (PTR) regarding an issue with the local encryption that we use on the Cereus Poker Network. For those of you not familiar with the issue, PTR was able to crack our local encryption method. I wanted to blog to make sure our players and the poker community know how seriously we take this issue.
I would like to start by reminding everyone that someone would have to have the technical capabilities to crack the encryption method we currently use and they would also have to hack into your local network in order to gain access to sensitive data. We are currently working on implementing a new encryption method and we expect to have it live in a matter of hours.
I would also like to say that I am very embarrassed and upset that this issue was not caught by our internal staff or through the countless audits we’ve been through this year and last year. We’ve invested a great deal of money into all types of security and I am very shocked that this was not identified by us or the many third party auditors we’ve employed.
Needless to say we plan to find new security resources and third parties to help us test this solution and make sure we provide you with the absolute best security that money can buy.
I would also like to thank PTR for identifying this issue and sharing it with us and the poker community.
We will continue to update you on this issue but we will not rest until it is fixed and as I stated earlier, we plan to have this issue resolved within a matter of hours.
Play well,
Paul Leggett
According to a number of software engineers, it is not possible to correct the issues within a few hours. I've quoted one comment from an engineer who posted on 2p2 regarding Paul Leggett's claims:
I'm a software engineer and my company was tasked with adding FIPS 140-2 encryption to our client-server application. It took us approximately 5-6 months to properly implement and test it. Admittedly, we had a small team of 4-5 developers, but having this done "within hours" of it being discovered by an outside source is laughable at best. Basically, what others have stated is accurate: If it is done within hours, it means it was already implemented and a switch was turned on once it was discovered. No chance that proper encryption can be implemented that fast.
Another poster pointed out the following concern with this vulnerability:
I think a point which is missed is that, while most people seem to be concerned about people seeing their hole cards, one of the benefits of SSL is that it prevents so-called "man in the middle attacks," by authenticating the server. Basically, by using SSL, when you login to Stars/FTP, you know you're talking with the Stars/FTP servers. With UB, not only is your password probably being transmitted with XOR, you actually don't even know if you're talking with the UB server.
To make matters worse, UB has the following information posted on their website:
“Our security and safety measures and procedures are constantly reviewed and updated to ensure that all our players have a safe place to enjoy?br />
We have a number of features to protect your privacy while you're playing at UltimateBet.
Our client software uses the certificates issued by our own Certificate Authority (CA) to authenticate our servers. UltimateBet software authenticates our servers by using the industry standard DES combined with AP's custom encryption algorithm.
Our client software uses a combination of DES and UltimateBet's custom algorithm for encryption. We use 256 bit encryption to ensure the highest level of privacy and confidentiality of data both to and from UltimateBet's servers.?br />
And on another page they have this contradictory and untrue claim since they obviously did not have SSL encryption installed!!
"UltimateBet is secure in the transfer of any information between our players and our UltimateBet servers. We use the internationally accepted industry standard SSLv3/TLSv1 encryption algorithm to protect your information as it transfers between our client application running on your computer and our servers.
So whether it is a credit card, your name, password, your cards, your personal address or any other private information, it is protected. Player cards are sent directly and exclusively to the individual player's computer without ever being susceptible to hacking."
Their checkered past:
Add the previous issues with Ultimatebet and Absolute Poker and you've got to wonder why this company continues to exist. They (Cereus) are currently ranked as the 8th largest (busiest) online poker network.
Recent 2p2 thread where players exposed a glitch that showed certain players' hole cards - Why can I see what people fold?
Absolute Cheats
The Absolute Poker Super User Scandal - Cliff Notes
Ultimate Bet Superusers and silence
The Potripper back story
KGC Fingers Russ Hamilton
UB Cheating Scandal
I blogged quite often during the UB Super User scandal - most posts can be found at this link:
UB Superuser Scandal