Masterminding the largest lottery scam in American history
nytimes.com
nytimes.com
Tipton’s extra lines of code first checked to see if the coming lottery drawing fulfilled Tipton’s narrow circumstances. It had to be on a Wednesday or a Saturday evening, and one of three dates in a nonleap year: the 147th day of the year (May 27), the 327th day (Nov. 23) or the 363rd day (Dec. 29). Investigators noticed those dates generally fell around holidays — Memorial Day, Thanksgiving and Christmas — when Tipton was often on vacation. If those criteria were satisfied, the random-number generator was diverted to a different track. Instead, the algorithm would use a predetermined seed number that restricted the pool of potential winning numbers to a much smaller, predictable set of numbers.
Admittedly, this is based only on the description from the article, which says it is describing pseudocode. But obviously, once this code is found, it's game over. Apparently the audit process for lotteries is terrible enough that this didn't matter.
Compare this with the auto emissions cheating scandal, where the algorithm was complicated in order to hide what was happening, so that the code would not be obvious as a defeat device: http://cseweb.ucsd.edu/~klevchen/diesel-sp17.pdf (see pages 6-8).
I can't believe he put the code in when he knew it would be audited, but then I doubly can't believe he would poke them to take a second look by suggesting something odd was involved at all.
See https://en.wikipedia.org/wiki/Coates_v._City_of_Cincinnati , but Iowa still has "annoying" speech criminalized under Iowa Code 708.7; the ultimate whistleblower retaliation tool.
The lotteries here (besides the statistical argument) are not trustworthy. I urge people who buy tickets to save their money, but the dream of getting rich instantly is too alluring.
>only $8 million
isn't a 75% recovery rate pretty good for cases like this?
edit: 67%
Not unlike the premise of the film, "The Sting".
The article skips right over this. HTH was this code, which the article reports wasn't even hidden, approved by a third party?
Trying to find out, I found this:
https://www.desmoinesregister.com/story/news/investigations/...
Which mentions:
"Tipton designed his rigged coding so that it wasn't detected in the company's random tests, according to a report Fritschie helped present last year."
...as well as: "Toyne said the association does not have any ongoing contractual relations with Gaming Labs."
The "report" mentioned earlier is a DEFCON presentation about gambling fraud in general, pretty interesting read: https://media.defcon.org/DEF%20CON%2025/DEF%20CON%2025%20pre...
In it mentions "The method of rigging the RNG could have been more discrete" and gave the breakdown of reverse engineering the binary to find(?) the source code. It also said the labs tested the RNG for statistical bias (which would pass) and audited the source code (it only gives the Picard Facepalm pic, so I assume the auditors likely relied solely/mostly on the automated test.
The random number is called the seed, and the seed is plugged into the algorithm, a pseudorandom number generator called the Mersenne Twister. At the end, the computer spits out the winning lottery numbers.
https://en.m.wikipedia.org/wiki/Americium#Occurrence if you’re curious how much there generally is and how much it might fluctuate.
"Tipton’s extra lines of code first checked to see if the coming lottery drawing fulfilled Tipton’s narrow circumstances. It had to be on a Wednesday or a Saturday evening, and one of three dates in a nonleap year: the 147th day of the year (May 27), the 327th day (Nov. 23) or the 363rd day (Dec. 29). If those criteria were satisfied, the random-number generator was diverted to a different track. Instead, the algorithm would use a predetermined seed number that restricted the pool of potential winning numbers to a much smaller, predictable set of numbers."
Ah the ol' stackoverflow copy/paste.
"Tommy Tipton had three Facebook friends named Conn." How did they get this data, was it available due to warrant or probable crime?
Yet another reason to not use FB. Like, at all. I doubt the police could ask FB for their "dossier" on you if you're not signed up (or does FB provide shadow profile access to law enforcement?)
Maybe luck is real after all ;)
Great story.
That's the entire problem, right there. He could have been much more brazen and still succeeded.
I've known the young assistant attorney general in this story for more than ten years. Rob Sand is a great guy and is running to be a state auditor of Iowa - you can support him at robsand.com. Also, if you're interested in meeting him in person, I'm also happy to facilitate an introduction (friends across the country like to house him from time to time).
I wonder if he found out they had video recording of the person buying the ticket.
The title is "The Man Who Cracked the Lottery" but it's not about someone actually cracking the lottery, that is, figuring out how to mathematically win the lottery or figuring out existing flaws; its just about straight up insider fraud. A better title is "The Man Who Rigged the Lottery." Or the TL;DR version: "Man Inserted Logic Bomb Into Lottery Draw Code Because There Was No Controls To Stop Him."
Its still somewhat of an interesting read but the title really ruined it for me; I was expecting an entirely different story.
Examples of people actually cracking the lottery/gambling site:
https://highline.huffingtonpost.com/articles/en/lotto-winner...
https://www.developer.com/tech/article.php/616221/How-We-Lea...
> From Tipton’s point of view, it was complicated. He had done something to see if he could do it. To his surprise, it worked. He said he inserted that code only once; after the code was approved by Gaming Laboratories International, machines containing it were shipped all over the country.
- ran the RNG through statistical tests (which of course passed flawlessly)
- audited the source code (but the backdoor was in binaries…)
Source: DEFCON presentation linked elsewhere in comments.