|
By:
dunno TP. seems to me like it was totally outwith BF's control that this wasn't a catastrophic security breach rather than a mere nuisance.
|
|
By:
People have no fight left in them any more. They have been ground down by the city machine. Anyone who's lost money through this is no different to the thousands of betfair customers who are fleeced everyday. The only difference is this time they may have been fleeced by someone with intelligence.
|
|
By:
Betfair was not hacked. The directory / naming service above it was hacked, which could have resulted in visitors being directed to the wrong site.
Think of it like a telephone directory. You want to call betfair so you look up their name in the directory. Betfair = 555-1234567 You dial the number and speak to Betfair, all sounds great. Nothing wrong there. Later that day hackers infiltrate the telephone directory and change the number. When you dial Betfair you are now redirected to 666-6666666. When the phone answers you hear some turkish guy ... In most cases your phone would have 'cached' the proper 555-1234567 number. But for some people their cache (the browser, the pc, the ISP) may have refreshed and thus given out the 666-6666666 number instead. Certainly anyone who has never visited Betfair before would have been given the 666-666666 number. Worst Case Scenario Worst case scenario is that the hackers could have created a fake betfair site at 666-6666666 If you tried to login (and on some sites except betfair, even just visiting the site with loaded cookies) you could have given your username and password to the hackers. In this example though I am sure it was just bragging - there was no harmful payload. But if the turkish guys had their 15 minutes of fame what about the hackers who did not boast about their conquest? What if 2 weeks ago serious criminals did the same thing but did not mention it? They could have cloned login details for thousands of customers in a quick 30 second grab and no one would know. As I say this is no fault of betfair, or dell, or the telegraph. It is a wakeup call to the whole internet industry - things are not safe out there and more needs to be done to secure sites. |
|
By:
If there is any criticism of betfair it should be as someone else mentioned on another thread:
The betfair password system is not secure. Any financial site which allows login in by a single password is open to abuse from keyloggers brute forcing (unless there are X incorrect password attempt lock-outs) 3rd party hacking (where XYZ site is hacked and a user has the same username and password on this site) Betfair should only allow login via a unsername, selected letters of a password (enter your 3rd, 5th and 8th letter of your password) and / or a pin number. There should certainly be a separate security code for any request to change your email address or to withdraw money. I have not checked but I wonder if the bank transfer could be to any account no. with a different name to the betfair account holder? That would be bad. |
|
By:
Thanks for the info but I'm aware it's not been hacked, in fact I'd read the piece Betfair plagiarised a good hour or so before they tweeted it.
http://nakedsecurity.sophos.com/2011/09/04/dns-hack-hits-popular-websites-telegraph-register-ups-etc/ I also mentioned in my opening post that it wasn't hacked into as such. I'am also aware it's not betfair's fault as such although there are things they could do to prevent a serious event from happening. What I don't get is why there's been hardly any mention of it on the forum. I'm assuming it's more to do with the time that it happened rather than forumites being mature enough to understand what had happened. I also don't understand why there's no mention at all of the hacking on the BBC website. Surely it's more newsworthy than a car being on Mt Snowdon or a comedian swimming the Thames? |
|
By:
it may not be BF's fault that their DNS was hacked, but it is their responsibility that they don't have stronger measures in place to proof customers against the consequences of such an attack.
by its nature, BF depends on at least some customers maintaining very large balances. without them, liquidity would not be sufficient for the markets to function profitably. BF appears to want to benefit from that without acknowledging that such balances require a bit more by way of security than facebook or twitter. if the DNS had redirected someone to a fake login page, and that had resulted in them being defrauded of 100K, who would have ultimately borne the liability? 1.01 the customer - or are BF going to start giving bank-style guarantees? |
|
By:
viva the way i see it is that banks are responsible for losses that they cant prove are due to their customers fault, so they have introduced higher levels of log in security to help save themselves money. Whereas Betfair have no such legal reponsisbility and hence have poor log in security.
|
|
By:
cynical hazel, but you may be right.
shortsighted if so, though. if customers lost money due to hacked DNS the publicity around it could be crippling to BF. btw, do people who know more about this kind of stuff than me think it's a good idea to log into 84.20.200.28 or 84.20.200.28/sports rather than the standard web-address? is there a downside to this, and if so what is it? |
|
By:
we all log in, and then betfair bosses take 445% pay increase from our comissiens. is big money to take from all of us.
|
|
By:
http://www.telegraph.co.uk/technology/news/8741597/Major-websites-hijacked-by-Turkish-hackers.html
|
|
By:
.. that wrapped on forum classic: /technology/news/8741597/Major-websites-hijacked-by-Turkish-hackers.html
|
|
By:
guardian had interview with them up this morning, they used sql injection on netnames
|
|
By:
templeton - i was on the tennis forum last night and there were a few grumbles, but not many.
the most likely explanation being that many, myself included, would have betfair's real IP address cached locally on our PCs in our dns cache so would not be redirected, so everything was business as usual. the most active users, and therefore those most likely to grumble, were likely have the lowest probability of being affected. pittsburgh - i don't think the single password is the biggest flaw in the betfair security model: unencrypted authentication cookies are. |
|
By:
been up on bbc since this morning
http://www.bbc.co.uk/news/technology-14786524 Bit-squatting - DNS hijacking without exploitation http://nakedsecurity.sophos.com/2011/08/10/bh-2011-bit-squatting-dns-hijacking-without-exploitation/ microsoft is: 0110110101101001011000110_1_1100100110111101110011011011110110011001110100 micr2soft is: 0110110101101001011000110_0_1100100110111101110011011011110110011001110100 weird the amount of traffic he claims to get ![]() |
|
By:
Pittsburgh Phil : The betfair password system is not secure. Any financial site which allows login in by a single password is open to abuse from
keyloggers brute forcing (unless there are X incorrect password attempt lock-outs) 3rd party hacking (where XYZ site is hacked and a user has the same username and password on this site) Brute forcing can be ruled out as I've been locked out several times, the most recent of which was last night. Betfair should only allow login via a unsername, selected letters of a password (enter your 3rd, 5th and 8th letter of your password) and / or a pin number. Or a text message pin sent to your mobile phone, such as paypal does. Problems arise though because any users logged in via the API will have their password submitted many times per hour by their software without their knowledge, this is how I was locked out last night, because Gruss was submitting my old password every time I clicked on a price graph (I changed the password without closing/reopening Gruss). Obviously Gruss/Geek/BA etc can't automatically enter 3rd, 5th and 8th letters many times per hour. Why the continuous API password requirement is required I cannot imagine, but it would have to be scrapped to allow for selected letters log ons. |
|
By:
there is no continous API password requirement.
|
|
By:
Are you guessing DStyle? Are you saying that I've imagined it? Which API software do you use?
|
|
By:
You just need to send the SessionToken via the keepAlive API, no need to Send password after login.
|
|
By:
Trevh , the graphs aren't available via the api so gruss is basically getting round it by logging into the main site to retreive them. It was probably trying to login each time you clicked a graph as you'd changed password and each attempt got rejected.
|
|
By:
sorry trevh - i'm definitely not guessing, but at the same time i'm not saying you've imagined it. i'm saying there is no repeated requirement to log in numerous times in the API. the problem appears to be with gruss doing something it doesn't need to do rather than a requirement being placed on it by the API.
as for the graphs, they are not available via the api as ghetto joe says, but equally you don't even need to log in to the website to view them. even if you do want to log in, there's no reason why you'd need to log in more than once to do so. as i say, it almost certainly appears to be a problem/bug in gruss itself; not a requirement of the API. . |
|
By:
DS, you don't need to login to see the graphs but the data's delayed if you're not logged in.
I very much doubt gruss makes repeated logins once it's retreieved a succesful session cookie for the web but as trev changed passwords mid session any login request to the site using the old password would result in an unsucessful request and subsequent requests for another graph would just try to login again and also fail. |
|
By:
@Trevh
DStyle's right. You need to call login on the API once, then take the session token you get back from log in and submit that with our subsequent calls to the API. No need at all to call login with username & password more than once per session. It *may* be the case that a particular package built on the API does resubmit your username/password, but there's no need for it. Easy to demonstrate using something like (eg) SoapUI to do the calls by hand and inspect the XML you're sending back and forth. |
|
By:
ghetto joe - i guessed that probably what gruss is doing.
are you sure about the graphs being delayed though, i just though it was the prices? besides it would take a very keen eye to pick a relatively minute amount of staleness on a mature market. |
|
By:
"viva the way i see it is that banks are responsible for losses that they cant prove are due to their customers fault, so they have introduced higher levels of log in security to help save themselves money. Whereas Betfair have no such legal reponsisbility and hence have poor log in security"
They might SAY they have no legal responsibility, but rest assured that means didly squat if it is proved they are acting in a negligent manner (and it wouldn't be difficult) |
|
By:
Sorry guys, I didn't mean to turn this into a Gruss thread! But you were all right, Gary from Gruss said...
"It logs in to the website in the background so that it can scrape the price charts from the website and it is this request that is causing failed login attempts". It must do it for every graph request I think, or me changing the password mid session wouldn't have effected it as it had already been logged in for hours. |
|
By:
Once it's logged in via the website it'd hold a session cookie and have no need to login again at each graph request Trev, you can check that by looking at the My Account->My Security tab which will show all login attempts, API and web. Click as many graphs as you want and you'll see no extra logins added to the My Security tab.
It's basically because you changed password mid session and either hadn't loaded a graph by then so gruss hadn't attempted to log into the web side of things or you'd logged out of your browser session to validate the password change which meant any current session cookie in gruss was no longer valid as it held incorrect details and therefore needed to re-login on the next graph request with an invalid password in memory. |
|
By:
Yes you're right Ghetto Joe with the cookie thing, all makes sense now.
I just checked the security tab though, and it shows the last 10 logons from my IP address all at 00:01 and 00:02! I'll check it again later as it may update slowly. |