Big Fish launches real-money gambling app in UK via Betable
techcrunch.com
techcrunch.com
Several casinos in the United States (Nevada, from what I've seen) have already built and released apps to allow, for example, poker or sports betting from within the associated casino. Some of these also allow betting from wireless connections within the state of Nevada.
This is where the idea starts to get really sticky.
If you're allowed to gamble from certain geographic locations, but not entire regions, how do you enforce access control? GeoIP is somewhat reliable, but border towns can fall on either side of the coin.
Wireless networking is generally not super long-range, but the DEFCON wireless shootout proved that it's possible to sustain a wireless signal from hundreds of miles away, given the correct (in this case, desert) conditions.
And that's not even mentioning transport layer issues. Could I set up a VPN in England to use this Big Fish app and gamble pseudo-legally from my phone in the States? If I do so, who's liable? What about simple SOCKS proxies? Dedicated/colocated boxes in the "allowed" region?
I think that this is really cool technology, and I'm excited to see it succeed. That said, as a security guy, I can't help but wonder who would be liable in these edge cases.
And, as I mentioned at the beginning of the post, I'd love to know exactly what security precautions are in place to prevent unauthorized bets and tampering. For example, let's say you're using this phone in a Starbucks. Will an SSL error (I can only hope they're using SSL) prevent the connection occurring at all? Will it give the user a chance to accept the change? Can I just submit a spoofed request to transfer me money, or is there some sort of "two factor" key on the phone itself?
It's an interesting problem, and I'm sure Big Fish has come up with interesting solutions.
While I can't give you a technical answer as I'm just the marketing guy, I can tell you that simply setting up a VPN in England is not going to work. We have a number of state-of-the-art gating techniques for identifying and prohibiting players from using our service illegally. We check for much more than Geo-location and IP. Obviously I can't get into as much detail as I'd like, but that's the gist of it.
Also, as Betable is doing all of the gambling, in the event that an extreme edge case occurs we would be liable, not the game developer working with us.
Unfortunately I can't answer the following questions about security precautions, but I can see if one of our engineers can hop on the thread to respond. I'll get back to you.
Come on, we all know that security through obscurity is weak. Tell us how the security system works and the community will test it for you!
"Unfortunately I can't answer the following questions about security precautions, but I can see if one of our engineers can hop on the thread to respond."
I don't think he's not explaining it because it would be insecure. He's not explaining it because he doesn't know it well enough.
The brilliant part of their business is that they're the casino. You give them the inputs, they give you the outputs but all of the actual gambling, for every app, all of the odds - everything - is all handled by them.
I am not sure how deeply you can go into your vetting process publicly, but I'd love to know how you can prevent a shadier company from pulling a bait-and-switch to change the odds of their games after you've approved them as a trusted vendor.
You guys have a really smart team, though, so I'm sure you have something awesome figured out. Congrats on the exposure this should net you! :)