Investigation Into Security Director Who Hacked the Lottery Expands (bgr.com)
An anonymous reader sends the latest update on Eddie Tipton, the man who worked for the Multi-State Lottery Association who was convicted of rigging a lottery game so he could win a $14 million jackpot. BGR reports: "Not too long ago, Eddie Tipton was convicted of hacking into the Multi-State Lottery Association's computer system in order to rig a nearly $17 million jackpot in Iowa. Now comes word that an investigation into Tipton's hacking activities is expanding to include a number of other states. Thus far, lottery officials from Colorado, Wisconsin and Oklahoma have indicated that Tipton may have also gamed lottery jackpots in their respective states. What makes this saga all the more interesting is that Tipton actually used to work at the Multi-State Lottery Association as a security director. In that capacity, Tipton allegedly installed a rootkit onto his company's computer system that influenced the manner in which 'random' numbers were generated. As a result, Tipton was able to calculate and gain access to winning lotto numbers before their public unveiling. With the numbers in tow, authorities claim that Tipton would reveal the winning numbers to friends who would then buy 'winning' lotto tickets and then collect on big paydays."
There are states that use a computer to pick their numbers and not balls pushed out by a machine?
I don't need a lecture on ethics from the frog who rigged the lottery!
I'm not sure about the USA but in the UK the lottery is drawn on live TV. This would make hacking it rather difficult. You do see that there are cameras around the machine. Are we saying that it's possible to make that machine pick only the balls that you want it to? Could a computer with imaging software be made to trigger the ball release? If so are all lotteries rigged anyway?
Does this open the hacked lottery to class action lawsuits by people who played the rigged lottery but had no chance of winning?
Smart enough to rig an RNG but dumb enough not to hide the money trail from the absolutely most basic of financial funny business sniff tests.
Giving winning numbers to friends. Fucking. Stupid.
All lottery winnings are directly reported to the IRS. - Who wants to bet one of his dumbshit friends tried to cheat on his/her taxes and triggered and audit investigation?
Every state that has one uses it to cut taxes on the rich instead of adding to Education budgets (seriously, there's a John Oliver video over on youtube that explains it). It's addictive gambling that often drains the last few dollars from the poor and worse it gives the lower class a false feeling of hope that discourages them from demanding better living conditions. It encourages the downtrodden to think of luck as a skill you work at and view their failure to win as a personal failure. Lotteries are one of the most vile tools for controlling the working class ever devised. How is it nobody but one guy on youtube ever points this out?
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
The numbers are way off on the old system. Since they have switched to a European group running it, the power ball winnings is all over the nation. Prior to that, the winnings were mostly east coast. in fact, Ca with their massive number of citizen should have been one of the top 3 most winning states. Yet, they, like the rest of the western states, won very little. Now, the winnings are running all over the nation like it should of probabilities are correct.
I prefer the "u" in honour as it seems to be missing these days.
The Lottery is a hidden Tax on the Poor.
-The wise argue that there are few absolutes, the fool argues that there are no probabilities.
Next you're going to tell us that elections have been decided by individuals involved with the implementation of electronic voting machines.
I assure you I will be totally shocked when that announcement is made. Shocked!!
It has been seen by me that the CA Supper Lotto "Mega Number" on machine picked numbers at a given location are not random. The numbers I see are almost always from 1 - 15 when the machine picks them.
My personal best guess is that the CA system thus tweaks the majority of winners to geographic locations that they want to favor, because they get larger amounts of earnings from those geographic locations.
It is a racket just like anything the mob runs.
If a computer picks the numbers, it can be rigged.
Better would be to come up with an equation that would take a dynamic natural phenomenon, such as so,e kind solar measurement.or some other naturally occurring and dynamic process in nature, and use that. Or, at the very least have the seed for the random number generator taken from a natural process
When Fascism comes to America, it will call itself Anti-Fascism, and tell you to give up your guns.
Is it too late to 'Friend' this guy on Facebook?
Wow, two conspiracy theories in one post! Good job!
Also, someone with your obviously high level of intelligence is probably confusing Mega Millions with the 'Supper' Lotto (WTF is that, a pile of leftovers?) The Mega Ball is ALWAYS from 1-15.
B32!
Alternatively, they can just predict /dev/random output if it contains sufficiently low entropy. You don't need root access for that.
No you can't, you're mixing things a bit up. /dev/random - in most implementation is of the *blocking* variety. I will never let the entropy go low enough. If there isn't enough entropy, the device will simply block until enough entropy has been gathered. /dev/urandom - which is the *unblocked* one. It will always spits out random numbers, no matter what the current state of the entropy pool is. If gets too low, you're basically just having a CPRNG (a cryptographic *pseudo*-random number generator). It might look random, but if you collect enough data, you can guess the internal state of the generator and predict the next number.
(Because of these pauses, it might be a performance bottleneck), that's why most implementations also offer...
The problem is that, for performance reason, lots of people tend to use the second one, even for situation where this is a bad idea. Like generating the random numbers needed for a cryptographic key.
See Mining Your Ps and Qs: Detection of
Widespread Weak Keys in Network Devices
Linux is one of the unix-like system that implements these kind of split random/urandom duality.
Linux is also incredibly popular on embed device.
Embed devices tend to have *not that much* sources of entropy (e.g.: no harddrive and input devices with chaotic timing)
Gathering enough entropy for the critical process would take time.
But several implementation use urandom (on the grounds that nobody wants to wait 30 minute after turning an appliance now. They want to push the button and the device imediatly tunring on and being operationnal).
Which is a BAD IDEA(tm) for cryptography.
The good idea would have been: defer the generation of keys as late as possible, e.g.: right before they are actually needed for the first time. By then some entropy (network timings, etc...) could have been generated.
"Sufficiently advanced satire is indistinguishable from reality." - [Tips: 1DrYakQDKCQ6y52z6QbnkxHXAocMZJE61o ]
If he can calculate the winning numbers, it's not a random selection of numbers. If he can gain access: Why was physical access unlogged and unsupervised? Alternatively, why was this connected to a network? This sort of software should be running on a pocket calculator, or first generation e-tablet.
Im sure glad nothing like this would ever happen to voting machines
I work retail and operated a lottery machine. I've seen all types of people, some play for fun but most play with a seriousness that one would for working a job. A lot of folks have their "system" and they stick to it. Never mind that they lose 99 times that 100th time that they won means their system is flawless. And then there are the people who think the lotto is a scam, but play anyway. I liken these folk to people who go to a used car dealer who sells but somehow will slip up an sell a good car.
Difference is Stewart knows what's getting laughs from pandering to the audience and what you need to do to get laughs from parodying.
He goes up against his own preconceptions when constructing a joke.
Oliver follows his own preconceptions.
Mit der Dummheit kämpfen Götter selbst vergebens
it's the poor and disadvantaged... We're taking advantage of people who are really vulnerable already. Hell, some of them might know the odds but can't help themselves. Gambling is addictive...
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
So your friend worked for lottery security and he told you the numbers and that's how you won the lottery...
Ummm... what? I did win the lottery. And my friend did tell me the numbers. But he told me BEFORE the numbers were picked.
Yeah, that's what we are saying
So why am I on trial.
Because your friend worked for lottery security and he told you the numbers and that's how you won the lottery...
Oh, boy.
Any guest worker system is indistinguishable from indentured servitude.
It's only a tax on the stupid if you don't know what a tax is. Taxes are imposed.
The Turing test cuts both ways
His profile was already removed from their site in January of 2015, good we have the Wayback machine, don't forget to donate.
http://web.archive.org/web/20141218171155/http://www.musl.com/musl_staff.html
Eddie Tipton, Director of Information Security
As Director of Security, Eddie is responsible for evaluating and providing direction on the security infrastructures within current and future member lottery operations. He additionally provides application design and support services for MUSL-sponsored projects. Prior to joining MUSL, Eddie was the Executive Vice President and a Partner at Systems Evolution Incorporated where he was responsible for LAN Management Security and Outsourcing, Network Operations, and Hosting. He brings 20 years of design, development, security, and general IT experience with him. Mr. Tipton is a certified developer and instructor on multiple technologies, a Certified Information Systems Security Professional (CISSP), and received his bachelor's degree in Management Information Systems and Finance from the University of Houston.
--
In short, from respected SEI consultant to crook. MUSL should update their site including cleaning up their images http://musl.com/images/staff/ETipton.jpg it does leave an impression you can trust this organization to keep it fair and secure.
Should everyone get their money back from those lotteries? There was no chance on winning because of actions by the company organizing the lottery.
You Aint Init.
... and how does one hack it?