I have never posted in this forum and I wouldn't usually start a thread, but this is a very serious issue.
Disclaimer: The level of incompetence required from Cereus for such a security flaw to be real would be so great, I'm having a hard time believing that this is true. But until PTR's story has been disproved, I advise extreme caution.
http://forumserver.twoplustwo.com/29...curity-778002/
http://www.poker*table*ratings.com/b...poker-network/
Quote:
The issue in general terms is that rather than using industry standard SSL encryption Cereus has used a custom form of encoding (not encryption) which can be cracked using the windows calculator.
Quote:
Almost every poker network uses some implementation of the SSL protocol, which is the same type of security mechanism that everyone from banks to government agencies use to secure their data. There are several freely available implementations of this protocol including the open source OpenSSL . SSL is the industry standard, and is generally regarded as best practice for encrypting network transmissions.
The problem is that the Cereus Poker network does not use SSL to encrypt their communications; they use a custom form of encryption which is XOR-based. This form of encryption is known to be extremely weak, and in fact their particular implementation makes it particularly simple to decrypt network data due to an easily discoverable key.
In fact, the encryption that the Cereus Network employs isn’t so much encryption as it is encoding. To see how simple it is to decode this data, simply open up your windows calculator and set it on scientific mode. All that is really necessary to decode the data stream is the XOR button .
As a computer engineer, this is an extremely serious security flaw that shows a level of incompetence previously unheard of (even for UB).
DO NOT PLAY ON UB/AP. DO NOT LOG ON UB/AP. And if you do so, don't do it on any form of public network or wireless network with weak security and only do so to cash out your bankroll. This isn't about UB/AP being shady or having done wrong in the past. This is a very real and serious security issue.