Deckmate Vulnerabilities: "Hackers Rig Casino Card-Shuffling Machines for Full Control' Cheating" (1 Viewer)

lolfdgb

Pair
Joined
Apr 28, 2023
Messages
127
Reaction score
102
Location
Pittsburgh, PA
WIRED magazine reports on a series of new vulnerabilities found with the Deckmate 2 shufflers (and separate vulnerabilities on the original Deckmates) that enable adversaries to know the sequence of cards post-shuffle. From the article:

"Today, at the Black Hat security conference in Las Vegas, Tartaro and two IOActive colleagues, Enrique Nissim and Ethan Shackelford, will present the results of their ensuing months-long investigation into the Deckmate, the most widely used automated shuffling machine in casinos today. They ultimately found that if someone can plug a small device into a USB port on the most modern version of the Deckmate—known as the Deckmate 2, which they say often sits under a table next to players’ knees, with its USB port exposed—that hacking device could alter the shuffler’s code to fully hijack the machine and invisibly tamper with its shuffling. They found that the Deckmate 2 also has an internal camera designed to ensure that every card is present in the deck, and that they could gain access to that camera to learn the entire order of the deck in real time, sending the results from their small hacking device via Bluetooth to a nearby phone, potentially held by a partner who then could then send coded signals to the cheating player."
 
There's a few other notable findings from this work, which was presented yesterday at Black Hat. First, that the original Deckmate devices were also susceptible to a (different) form of tampering:

"The IOActive team also looked at the earlier model of the Deckmate, known as the Deckmate 1, which has no external USB port and no internal camera. The researchers say that the earlier model, which was the one actually used in the Hustler Live Casino game, could nonetheless still be hacked to cheat in a game if a rogue casino staffer or maintenance person had an opportunity to open the shuffler's case and access a particular chip that stores its code. In that case, despite the lack of an internal camera, the cheater could still hack the shuffler to reorder cards—or they could simply prevent the Deckmate from shuffling the deck when a dealer picks up everyone's cards after a hand, giving the cheater information about the location of those previously played cards."
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account and join our community. It's easy!

Log in

Already have an account? Log in here.

Back
Top Bottom