Innovation and Canada
Do you know that Canada is one of the lowest-ranked developed countries in the innovation field. The irony is that, at the same time, Canada is ranked one of the highest in giving tax-money back for R&D.
All about Iyad Atuan and his investing strategies
Do you know that Canada is one of the lowest-ranked developed countries in the innovation field. The irony is that, at the same time, Canada is ranked one of the highest in giving tax-money back for R&D.
Posted by
Iyad Atuan
at
10:47 PM
0
comments
Have you noticed that some commercials are stealing ideas from other commercials?
For example, have you seen that McDonal's commercial where a guy sees someone having a BigMac so later he gets one and someone watches him eating and gets one himself and so on?
Well that commercial is the same idea as a commercial i saw long time ago where one guy smiles to someone in the street, the next guy smiles to someone else and so on till the last guy smiles to the first guy that started the commercial.
Right now in Ontario, the OLG (responsible for the lottery), has a BINGO commercial where a lady sees a lady playing bingo so she goes to play one herself and someone that saw her playing went to play one as well and so on.
What happened to creativity? and isn't that intelectual theft or whatever they call it?
Posted by
Iyad Atuan
at
2:22 PM
0
comments
Hey Steve,
That night that we met at Niagara I left with $200 profit. Then, I went there on Saturday with some friends because they wanted to gamble on such a lucky day (july 7, 2007 – 7/7/07 – 7+7+7=21) but that night I felt like trying the $2/$5 after your advice.
I was quite for awhile studying the dynamics, then I went up to $500 then down to $100 ( I filled it to $200 twice, so I had invested $400) then I went up to $900 and then i played a hand very bad, here are the details:
I had QJs, I raised to $20 and 3 guys called,
At the flop one asian guy opened his eyes wide open when he saw the flop so I knew he got a monster hand.
so then I checked the flop, it was TQ5
so everyone checked to me, I bet $35, the asian guy raises to $70, the next one reraises to $140 and the third guy calls it, so it is back to me, I analyse so I put the asian on QT, the second guy on AQ and the third on Q and some low card. So obviously after the tell and the reraises I should have fold but for some unknow reason I called.
At this time there was $500+ in the pot, the turn comes something useless, the asian bets $100 everyone calls so there is like $800 in the pot and even though I know I am beat I call, the river is an ace, asian checks , second guy goes $200, third calls, I say what the f@#$ and I call and asian calls.
Results, asian had pocket 10s, second guy had AQ(I got it 100% right, it made me so happy, third guy mucked)
So from there I was on a tilt, I went up to $410 and then my friends wanted to leave…so I made $10….hurray
I had mixed feelings because I knew exactly what was going on but till now I don’t know why I wasted close to $500 on that hand. The good news is that I could have made $500 easily J
Ok see ya at the tables before Aug (I am going to Chile for Aug before I start school, and will try the casinos in there and let you know)
Posted by
Iyad Atuan
at
8:45 PM
0
comments
Today is a special day for gamblers; it is July 7, 2007 or 7/7/07 = 7+7+7=21.
I am not a gambler and i don't believe in superstition but a lot of people do, specially asians. i frequent Casino Fallsview where there is a majority of asian players, so today is a great day for me to make some big winnings because they will be relying more on the luck factor and more-than-usual amount of money will pass hands.
This post reminds me of a little trick i use on hardcore supersticious people. When I want them to call my raise; i raise $21, most times i get calls. However, when i am bluffing, i only raise to $13 and they will fold. Since the table has some pros this trick doesn't work on them that is why i only use it if the pros already folded or if i got a tell that they most likely will fold.
On another topic,I came to the plant for a couple of hours to make sure everything was fine, when i am done i will meet some friends and head down to Niagara and have some fun.
Yesterday i gave my notice to my employer. I was relieved that i finally made it and i already feel 10 pounds lighter. I am so excited about school, the opportunities and my future. I know i have a lot of hard work ahead of me but i am up to the challenge....and wasn't that one of my main reasons i wanted to go back to school?...the challenge.
Posted by
Iyad Atuan
at
12:54 PM
0
comments
So as most of you know i will be quiting my job at the end of July to start full time MBA in September. I will use August mainly for 3 reasons:
1. A long-deserved vacation. Since i entered university in 2000 till now, i haven't really taken a vacation, i have always been doing something. So i am planning to use this vacation mainly to discover Ontario.
2. Focus on my FOREX system, it is a great system, it has a lot of potential and one month will give me an opportunity to exploit all of its potential.
3. Get back in top shape. Despite looking and feeling thinner for the last couple of months due to my daily bike commute to work, i can't help it but feel weak. I have lost 3" in my chest, 2" on each bicep and lost a lot of definition. So my focus will be this month to work out and get ready to go full-blast starting September.
Posted by
Iyad Atuan
at
12:06 PM
0
comments
A couple of months ago I opened a real FOREX account with Gain Capital. At first I had some loses due to mistaken trades and bad/mixed signals, but for the last month I have been trying a new simple system that I have developed and it has shown me good return. In the last 7 days I made 47%! The most I have lost is 5% and the biggest day return has been 23%.
I have an idea of opening a small FOREX firm where I invest people’s money for a 4% monthly return with an 80% guarantee on their deposit. The return sounds tempting to most investors (that is a 48% annual ROI) and if 80% of their investment is guaranteed it will make it an investment hard to refuse.
I admit that my last week return is not sustainable, so my goal is more realistic, my goal is to make 1% per day (that is 34% a month or 30% after I pay my investors).
It is too early to say but I will keep you guys posted on my progress.
Posted by
Iyad Atuan
at
3:07 PM
4
comments
Ok, I haven't posted for a long time. I am the contributer to this blog, but I think i have come up with an explanation to this weird series, Lost.
It is an island of lost souls, and therefore comes the name Lost. Ok, let's analyse this.
It has been confirmed twice by two different characters that all the guys in the plane should be dead. We know it is not heaven, and can't be hell, that would be stupid and non-creative. So it is a place where all this Lost souls are put together. I know it may be a little ridiculous, but if we remember the Desmond episode where there was this old lady who was selling the ring, and that knew who would die, then we can get a feeling of the direction of the writers: Supernatural phenomena, destiny, etc. Notice how every single character of the crashed plane that has been introduced to us has a dark history, exept for John Lock, the special one, the chosen.
Also notice how everyone has a file, how else would they gather so much information about such intimate things.
This explains a lot of things, like the black weird thing that kills people, it is like the demon that comes to collect souls. The submarine represented the way out of the Lost island, therefore moving to a better place, saving the soul. Think about Charlie, he must die, and Desmond knows that. His sould should no longer be in the island.
The others could be considered as, i don't know, angels or something of that sort. This makes us think about why women can't have children in the island. Why John is walking again (when you go to Heaven, Hell, or wherever, you are supposed to go with your whole body, not part of it, this brings a whole new discussion).
I still haven't figured this out, I would really appreciate if you would give me your inputs about this, why you thing it is stupid or not, or help to solve the puzzle. Like Dharma??What is Dharma. How the russian didn't die?
Posted by
"La Bomba"
at
11:06 PM
2
comments
Today I was considering the different choices I would have after I finish my MBA. After working as an engineer for 3 years, I’ve realized that engineering was underpaid for the amount of hours that I work and the responsibilities that I have.
Therefore, I decided to focus my MBA in a direction that would help me obtain a career in a profession that aligns with my values, skills and goals. I have narrowed it down to investment banking. In this industry you require the following skills:
spreadsheet (at least when you start as a financial analyst),
math,
interpersonal,
presentation skills, and
multi-tasking.
Surely this position makes a lot of money but you have to work really hard for it and sacrifice some personal time, investment bankers are known to work as much as 120 hours a week! However, IB pays really good specifically here in Toronto due to the lack of good IBs.
My plan is to study really hard and be deeply involved in the finance club at Schulich so it will facilitate me to get an internship in an Investment Bank like Goldman or Merrill.
I will post more details later on,
Posted by
Iyad Atuan
at
1:29 PM
5
comments
So last week I got accepted to Schulich for the MBA program (that was the only school i applied for), too bad i cannot do it full-time then i would have applied other places outside of Canada.
Since it starts in September I am preparing myself to have no social life as i know it now for the next three years. So I will enjoy this summer as much as i can.
So people what do you think about my new blog's look? lovely eh?
Posted by
Iyad Atuan
at
11:26 PM
2
comments
A couple of weeks ago i broke my digital camera (oooops). Despite having an extended warranty (which i misplaced) I decided to get a new camera. After a lot of comparison between the new cameras i decided to go for the Canon Powershot A640. Great camera i am just having trouble connecting it to my computer (damn XP).
I will update more later, i am tired and i need to re-energize.
Posted by
Iyad Atuan
at
12:06 AM
2
comments
So far I got 30% return on my demo account, in 3 days! I have been reading lots about FOREX and technical analysis I believe I am improving by the minute!
I can’t wait till I open an actual; account and become rich…hahahaha
Well I know FOREX is risky business and you have to be smart about it (90% of traders lose in FX).
Posted by
Iyad Atuan
at
1:00 PM
0
comments
This post is a follow up to the last post.
So I was looking for different ways to invest and here are the options and conclusions:
1. Mutual Funds: I am already doing that with a nice return but I feel I could do more.
2. Real Estate: I thought about this idea with a friend of mine that actually works in the industry. We decided to postpone it because my credit is not top notch and the real estate prices in Toronto are too high and we predict the bubble will burst anytime soon.
3. Stocks: This was a tempting option since I follow the markets and business news very closely so I have an idea where to invest. The drawbacks are the trading fees and the minimum capital you need is a little high.
4. Futures: Too complex, I didn’t really look too deep into this and I lost interest.
5. Forex Trading: I wanted to try this for a loooong time but I was under the impression that I needed a lot of capital. However, after doing some investigation I found out that you do not need a lot of capital (just $250) to open a mini account. Also, Forex trading is easy, fun and can be partially automated!
I started a ‘demo’ account yesterday night for 10,000 and I am already at 11,000 from 2 trades I automated before going to bed; when I woke up they were done…awesome.
So my plan is to try the demo for a month, see how I perform then open a mini account. I could open a standard account for 2,000 but I believe using a mini account my confidence will build up and I can play it safe before opening a standard account.
Guys, I will keep you daily updated on my demo account.
Cheers,
Posted by
Iyad Atuan
at
12:45 PM
0
comments
I have been talking about poker for 99% of my posts, so I decided to change it a bit and I will talk about my personal and professional growth goals for these couple of years.
Health – Lose weight and become 225 lbs @ 14% body fat
In September I was 313 lbs and 32% body fat, through proper eating and exercise I have been able to drop my weight to 291 lbs and 27% body fat. I am confident that I can lose the weight like I did 3 years ago BUT this time I will stick to it.
Fitness – Commute both to and from work on my bike during the summer
I partially did this since I just got my bike at the end of the summer.
Financial – Double my savings
I was a great saver when I had no obligations but once the obligations kicked in I saved a lot less so the challenge is to save while you have obligations as well.
Financial – Diversify my portfolio and get ROI of 20% for this year.
Mainly I have been investing in mutual funds and it has been great but I will introduce stocks in the picture see what happens.
Education – Do my MBA
I will apply for admission this September at York University so I can do it part-time while I work.
Career
I have a lot of goals for this but instead of boring you I will tell you that I am planning to finish all my projects and increase the uptime in the plant.
So that’s it, I will let you know what I achieve and what not at the end of this year.
Brought to you by…
EV
Posted by
Iyad Atuan
at
1:10 PM
0
comments
Happy New Year!
I know, i know, i apologize i haven't posted for a while. I was really busy with work and i was under the weather.
I bet all of you are excited about 2007, I am!
First of all, even though i know you are not interested but i want to mention that i have lost 25 LBS since december 1st, i feel great and i feel my poker has improved "a healthy mind in a healthy body".
As you remember i said i was off online poker for good. So i started to frequent an underground poker place in downtown Toronto. Mainly i have been playing tournaments. So far i haven't won any but made it in the money most of the times. The thing is that most players are asian, and i don't won't to offend anyone but i noticed from long time ago that asian poker players are the toughest and riskiest; they see poker from a different perspective than everyone else. I am planning to crack their secret :)
On Jan 2nd, I got an email from PartyPoker that I have a $20 bonus. I said to myself why not use it, i am not losing anything. So i have been playing single-table tournaments and I have been making it in the money (top 3) 80%, I decided to see how far i can take the $20.
As for my poker plans for this year, I am planning to go to Vegas in April to play some tournaments and do what I am doing now; play in the underground place and SNG games online with the bonus i got.
Well I will keep the blog updated and good luck.
EV
Posted by
Iyad Atuan
at
1:22 PM
0
comments
I haven't posted in this blog for ages, I just didn't have anything I wanted to say, nor do right now, I just wanted to update on what has been of my life.
It's been a year since I've been in Chile, god, that year seemed as 10!!
So, there are a few things that changed in the past year:
First, I've become this judgmental pessimist negative energy person. I don't know why this happened or how, it just did.
Second, if one year ago I had any idea what I wanted to do after finishing school, then right now, I have absolutely none, zip, zero, nada, keine idee. I know for sure i don't wanna stay in Chile, nor in any country in the region. Somehow, i am interested right now in investment banking, and it would be hard to get a career in IB if i stay in Chile, so i am checking my options after i'm done with Chile; slim chance, i know. I am thinking about a Master in Economics (one year programme) in Munich, or trying to get into a top 14 law school in the states. I know the last one is not the most orthodox methode of getting into IB, but a JD from a top Law school may give you a descent chance to enter as an asociate into an IB.
Fourth, I started going back to the gym which means that I won't be able to drink anything during the summer, which kinda sucks, since there are a lot of parties going on.
Last, I got the Chilean nationality, no big deal, just thought of mentioning it. I can go to any Latin country with just my Id (no passport) and visit Europe without a visa.
p.s I took 27 credits last semester and still managed to get one of the top grades in my class. I think I am easily ranked top 5%. I am not sure if considering my CGPA I would still be top 5%, but damn it, I know that by the time i finish my degree I will be at least top 5%. God I sound so nerdy,
Iysam's out
Posted by
"La Bomba"
at
9:05 PM
0
comments
Today when i googled my name i found very interesting stuff, this link is of a comment i made while in school.
Word on the Street - News
Posted by
Iyad Atuan
at
2:43 PM
0
comments
Dear online poker players,
I came across this article the other day. In it it shows how the software itself is flawed and cheaters can exploit this to their benefit. I contacted a couple of major online poker rooms, they said that they made the necessary modifications, however, that was not good enough for me, read the following article I got from some site (whish i remember where) and you will understand why i am off online poker for life.
Poker is a card game that many people around the world enjoy. Poker is played at kitchen tables, in casinos, and cardrooms -- and more recently, the Web. A few of us here at Reliable Software Technologies play poker. Since many of us spend a good amount of our days online, it was only a matter of time before some of us put the two interests together. This is the story of how our interest in online poker and software security mixed to create a spectacular security exploit.
The PlanetPoker Internet cardroom offers real-time Texas Hold'em games against other people on the Web for real money. Being software professionals who help companies deliver secure, reliable, and robust software, we were curious about the software behind the online game. How did it work? Was it fair? An examination of the FAQs at PlanetPoker, including the shuffling algorithm (which was ironically published to help demonstrate the game's integrity) was enough to start our analysis wheels rolling. As soon as we saw the shuffling algorithm, we began to suspect there might be a problem. A little investigation proved that this intuition was correct.
The Game
In Texas Hold'em, each player is dealt two cards (called the pocket cards). The initial deal is followed by a round of betting. After the first round, all remaining cards are dealt face up and shared by all players. The dealer places three cards face up on the board (called the flop). A second round of betting then takes place. Texas Hold'em is usually a fixed limit game, meaning that there are fixed amounts that a player may bet in each betting round. For example, in a $3 to $6 game, the first two betting rounds are $3 bets while the third and fourth betting rounds are $6 bets. After the second round of betting, the dealer places another card face up on the board (called the turn). A third round of betting then takes place. Finally, the dealer places the last card face up on the board (called the river), and a final round of betting ensues. Each remaining player takes their two pocket cards and combines them with the five community cards to make the best five-card poker hand. The best hand among the players is determined by standard poker hand order.
Texas Hold'em is a fast-paced and exciting game. Bluffing is an essential part of the game, and quick decisions about who is holding what sorts of cards separate winners from losers. Interestingly, Texas Hold'em is the poker game played at the World Series of Poker which is held annually in Las Vegas.
Now that everybody and their dog is online, and virtually all types of businesses are represented on the Internet, it's only natural that casinos and cardrooms are there too. Even with the reasonably easy availability of casinos on Indian reservations and riverboats, there is still real demand for more accessible games. Being able to play online in the comfort of your own home (not to mention in your pajamas), without having to endure second-hand smoke and obnoxious players, is definitely appealing.
Security Risks Abound
All this convenience comes at a price. Unfortunately, there are real risks to playing poker online. The casino may be a fraud, existing only to take money from naïve players without ever intending to pay back winnings. The server running the online casino could be cracked by a malicious attacker looking for credit card numbers, or trying to leverage some advantage in the game. Since a majority of casinos don't authenticate or encrypt the network traffic between the player running the client program and the server hosting the card game, a malicious player could conceivably examine the network traffic (with a classic person-in-the-middle attack) for the purposes of determining his opponent's cards. These risks are all very familiar to Internet security experts.
Collusion is a problem that is unique to poker (as opposed to other games like blackjack or craps), since poker players play against each other and not the casino itself. Collusion occurs when two or more players seated at the same table work together as a team, often using the same bankroll. Colluding players know what their team members' hands are (often through subtle signals), and bet with the purpose of maximizing their team's profits on any given hand. Though collusion is a problem in real cardrooms, it is a much more serious problem for online poker. Using tools like instant messaging and telephone conference calls makes collusion a serious risk to online poker players. What if all the players in an online game are all cooperating to bilk an unsuspecting Web patsy? How can you be assured that you're never a victim of this attack?
Last, but not least (especially in terms of our story), there is a real risk that the software behind an online poker game may be flawed. Software problems are a notorious form of security risk often overlooked by companies obsessed with firewalls and cryptography. The problem is that a software application can introduce truck-sized security holes into a system. We spend a great deal of time in our day jobs finding and solving software security problems. It is only natural that we turned our attention to online poker. The rest of this article is devoted to a discussion of software security problems we found in a popular online poker game.
Software Security Risks
Shuffling a Virtual Deck of Cards
The first software flaw we'll focus on involves shuffling virtual cards. What does it mean to shuffle a deck of cards fairly? Essentially, every possible combination of cards should have an equal likelihood of appearing. We'll call each such ordering of the 52 cards a shuffle.
In a real deck of cards, there are 52! (approximately 2^226) possible unique shuffles. When a computer shuffles a virtual deck of cards, it selects one of these possible combinations. There are many algorithms that can be used to shuffle a deck of cards, some of which are better than others (and some of which are just plain wrong).
We found that the algorithm used by ASF Software, Inc., the company that produces the software used by most of the online poker games, suffered from many flaws. ASF has changed their algorithm since we contacted them regarding our discovery. We have not looked at their new approach. Getting everything exactly right from a security perspective is not easy (as the rest of this article will show).
Figure 1: The Flawed ASF Shuffling Algorithm
procedure TDeck.Shuffle;
var
ctr: Byte;
tmp: Byte;
random_number: Byte;
begin
{ Fill the deck with unique cards }
for ctr := 1 to 52 do
Card[ctr] := ctr;
{ Generate a new seed based on the system clock }
randomize;
{ Randomly rearrange each card }
for ctr := 1 to 52 do begin
random_number := random(51)+1;
tmp := card[random_number];
card[random_number] := card[ctr];
card[ctr] := tmp;
end;
CurrentCard := 1;
JustShuffled := True;
end;
The shuffling algorithm shown in Figure 1 was posted by ASF Software in order to convince people that their computer-generated shuffles were entirely fair. Ironically, it had the exact opposite effect on us.
The algorithm starts by initializing an array with values in order from 1 to 52, representing the 52 possible cards. Then, the program initializes a pseudo-random number generator using the system clock with a call to Randomize(). The actual shuffle is performed by swapping every position in the array, in turn, with a randomly chosen position. The position to swap with is chosen by calls to the pseudo-random number generator.
Problem One: An Off-By-One Error
Astute programmers will have noticed that the algorithm in question contains an off-by-one error. The algorithm is supposed to traverse the initial deck while swapping each card with any other card. Unlike most Pascal functions, the function Random(n) actually returns a number between 0 and n-1 instead of a number between 1 and n. The algorithm uses the following snippet of code to choose which card to swap with the current card: . The formula sets random_number to a value between 1 and 51. In short, the algorithm in question never chooses to swap the current card with the last card. When ctr finally reaches the last card, 52, that card is swapped with any other card except itself. That means this shuffling algorithm never allows the 52nd card to end up in the 52nd place. This is an obvious, but easily correctable, violation of fairness.
Problem Two: Bad Distribution Of Shuffles A closer examination of the shuffling algorithm reveals that, regardless of the off-by-one problem, it doesn't return an even distribution of decks. The basic algorithm at the heart of the shuffle is shown in Figure 2.
Shuffling
A closer examination of the algorithm reveals that, regardless of the off-by-one error, it doesn't return an even distribution of shuffles. That is, some shuffles are more likely to be produced than others are. This uneven distribution can be leveraged into an advantage if a tipped-off player is willing to sit at the table long enough.
To illustrate this problem using a small example, we'll shuffle a deck consisting of only three cards (i.e, n=3) using the algorithm described above.
Figure 2: How not to shuffle cards
for (i is 1 to n)
Swap i with random position between 1 and n
Figure 2 contains the algorithm we used to shuffle our deck of three cards, and also depicts the tree of all possible decks using this shuffling algorithm. If our random number source is a good one, then each leaf on the tree in Figure 2 has an equal probability of being produced.
Given even this small example, you can see that the algorithm does not produce shuffles with equal probability. It will produce the decks 231, 213, and 132 more often than the decks 312, 321, 123. If you were betting on the first card and you knew about these probabilities, you would know that card 2 is more likely to appear than any other card. The uneven probabilities become increasingly exaggerated as the number of cards in the deck increase. When a full deck of 52 cards is shuffled using the algorithm listed above (n=52), the unequal distribution of decks skews the probabilities of certain hands and changes the betting odds. Experienced poker players (who play the odds as a normal course of business) can take advantage of the skewed probabilities.
Figure 3: How to shuffle cards
for (i is 1 to 3)
Swap i with random position between i and 3
Figure 3 provides a much better shuffling algorithm. The crucial difference between the two algorithms is that number of possible swap positions decreases as you progress through the deck. Once again, we show a tree illustrating this algorithm on our sample deck of three cards. The change between this new algorithm and the one used by ASF is that each card i is swapped with a card from the range [i, n], not [1, n]. This reduces the number of leaves from the 3^3 = 27 given by the bad algorithm listed above to 3! = 6. The change is important because the n! number of unique leaves means that the new shuffling algorithm generates each possible deck only once. Notice that each possible shuffle is produced once and only once so that each deck has an equal probability of occurring. Now that's fair!
Generating Random Numbers on a Deterministic Machine
The first set of software flaws we discussed merely changes the probabilities that certain cards will come up. The associated skews can be used by a clever gambler to gain an edge, but the flaws really don't constitute a complete break in the system. By contrast, the third flaw, which we explain in this section, is a doozy that allows online poker to be completely compromised. A short tutorial on pseudo-random number generators sets the stage for the rest of our story.
How Pseudo-Random Number Generators Work
Suppose we want to generate a random number between 1 and 52, where every number has an equal probability of appearing. Ideally, we would generate a value on the range from 0 to 1 where every value will occur with equal probability, regardless of the previous value, then multiply that value by 52. Note that there are an infinite number of values between 0 and 1. Also note that computers do not offer infinite precision!
In order to program a computer to do something like the algorithm presented above, a pseudo-random number generator typically produces an integer on the range from 0 to N and returns that number divided by N. The resulting number is always between 0 and 1. Subsequent calls to the generator take the integer result from the first run and pass it through a function to produce a new integer between 0 and N, then return the new integer divided by N. This means the number of unique values returned by any pseudo-random number generator is limited by number of integers between 0 and N. In most common random number generators, N is 2^32 (approximately 4 billion) which is the largest value that will fit into a 32-bit number. Put another way, there are at most 4 billion possible values produced by this sort of number generator. To tip our hand a bit, this 4 billion number is not all that large.
A number known as the seed is provided to a pseudo-random generator as an initial integer to pass through the function. The seed is used to get the ball rolling. Notice that there is nothing unpredictable about the output of a pseudo-random generator. Each value returned by a pseudo-random number generator is completely determined by the previous value it returned (and ultimately, the seed that started it all). If we know the integer used to compute any one value then we know every subsequent value returned from the generator.
The pseudo-random number generator distributed with Borland compilers makes a good example and is reproduced in Figure 4. If we know that the current value of RandSeed is 12345, then the next integer produced will be 1655067934 and the value returned will be 20. The same thing happens every time (which should not be surprising to anyone since computers are completely deterministic).
long long RandSeed = #### ;
unsigned long Random(long max)
{
long long x ;
double i ;
unsigned long final ;
x = 0xffffffff;
x += 1 ;
RandSeed *= ((long long)134775813);
RandSeed += 1 ;
RandSeed = RandSeed % x ;
i = ((double)RandSeed) / (double)0xffffffff ;
final = (long) (max * i) ;
return (unsigned long)final;
}
Based on historical precedent, seeds for number generators are usually produced based on the system clock. The idea is to use some aspect of system time as the seed. This implies if you can figure out what time a generator is seeded, you will know every value produced by the generator (including what order numbers will appear in). The upshot of all this is that there is nothing unpredictable about pseudo-random numbers. Needless to say, this fact has a profound impact on shuffling algorithms!
On To Poker, Or How To Use A Random Number Generator Badly
The shuffling algorithm used in the ASF software always starts with an ordered deck of cards, and then generates a sequence of random numbers used to re-order the deck. Recall that in a real deck of cards, there are 52! (approximately 2^226) possible unique shuffles. Also recall that the seed for a 32-bit random number generator must be a 32-bit number, meaning that there are just over 4 billion possible seeds. Since the deck is reinitialized and the generator re-seeded before each shuffle, only 4 billion possible shuffles can result from this algorithm. Four billion possible shuffles is alarmingly less than 52!.
To make matters worse, the algorithm of Figure 1 chooses the seed for the random number generator using the Pascal function Randomize(). This particular Randomize() function chooses a seed based on the number of milliseconds since midnight. There are a mere 86,400,000 milliseconds in a day. Since this number was being used as the seed for the random number generator, the number of possible decks now reduces to 86,400,000. Eight-six million is alarmingly less than four billion. But that's not all. It gets worse.
Breaking the System
The system clock seed gave us an idea that reduced the number of possible shuffles even further. By synchronizing our program with the system clock on the server generating the pseudo-random number, we are able to reduce the number of possible combinations down to a number on the order of 200,000 possibilities. After that move, the system is ours, since searching through this tiny set of shuffles is trivial and can be done on a PC in real time.
The RST exploit itself requires five cards from the deck to be known. Based on the five known cards, our program searches through the few hundred thousand possible shuffles and deduces which one is a perfect match. In the case of Texas Hold'em poker, this means our program takes as input the two cards that the cheating player is dealt, plus the first three community cards that are dealt face up (the flop). These five cards are known after the first of four rounds of betting and are enough for us to determine (in real time, during play) the exact shuffle. Figure 5 shows the GUI we slapped on our exploit. The "Site Parameters" box in the upper left is used to synchronize the clocks. The "Game Parameters" box in the upper right is used to enter the five cards and initiate the search. Figure 5 is a screen shot taken after all cards have been determined by our program. We know who holds what cards, what the rest of the flop looks, and who is going to win in advance.
Figure 5: The GUI for our exploit
Once it knows the five cards, our program generates shuffles until it discovers the shuffle that contains the five cards in the proper order. Since the Randomize() function is based on the server's system time, it is not very difficult to guess a starting seed with a reasonable degree of accuracy. (The closer you get, the fewer possible shuffles you have to look through.) Here's the kicker though; after finding a correct seed once, it is possible to synchronize our exploit program with the server to within a few seconds. This post facto synchronization allows our program to determine the seed being used by the random number generator, and to identify the shuffle being used during all future games in less than one second!
Technical detail aside, our exploit garnered spectacular press coverage. The coverage emphasizes the human side of our discovery. See our Web site for our original press release, the CNN video clip, and a New York Times story .
Doing Things Properly, or How to Shuffle Virtual Cards
As we have shown, shuffling virtual cards isn't as easy as it may appear at first blush. The best way to go about creating a shuffling algorithm is to develop a technique that can securely produce a well-shuffled deck of cards by relying on sound mathematics. Furthermore, we believe that publishing a good algorithm and opening it up to real-world scrutiny is a good idea (which meshes nicely with the opinions of the Open Source zealots). The main thing here is not relying on security by obscurity. Publishing a bad algorithm (like AFS did) is a bad idea, but so is not publishing a bad algorithm!
Cryptography relies on solid mathematics, not obscurity, to develop strong algorithms used to protect individual, government, and commercial secrets. We think shuffling is similar. We can stretch the analogy to include a parallel between cryptographic key length (which is directly proportional to the strength of many cryptographic algorithms) and the size of the random seed that is used to produce a shuffled deck of cards.
Developing a card-shuffling algorithm is a fairly straightforward task. The first thing to realize is that an algorithm capable of producing each of the 52! shuffles is not really required. The reasoning underlying this claim is that only an infinitesimally small percent of the 52! shuffles will ever be used during play. It is important, however, that the shuffles the algorithm produces maintain an even distribution of cards. A good distribution ensures that each position in the shuffle has an approximately equal chance of holding any one particular card. The distribution requirement is relatively easy to achieve and verify. The following pseudo-code gives a simple card-shuffling algorithm that, when paired with the right random number generator, produces decks of cards with an even distribution.
START WITH FRESH DECK
GET RANDOM SEED
FOR CT = 1, WHILE CT <= 52, DO
X = RANDOM NUMBER BETWEEN CT AND 52 INCLUSIVE
SWAP DECK[CT] WITH DECK[X]
Key to the success of our algorithm is the choice of a random number generator (RNG). The RNG has a direct impact on whether the algorithm above will successfully produce decks of even distribution as well as whether these decks will be useful for secure online card play. To begin with, the RNG itself must produce an even distribution of random numbers. Pseudo-random number generators (PRNG), such as those based on the Lehmer algorithm, have been shown to possess this mathematical property. It is therefore sufficient to use a good PRNG to produce "random" numbers for card shuffling.
As we have seen, choice of initial seed for the PRNG is a make or break proposition. Everything boils down to the seed. It's absolutely essential that players using a deck of cards generated using a PRNG can't determine the seed used to produce that particular shuffle.
A brute force attempt to determine the seed used to produce a particular shuffle can be made by systematically going through each of the possible seeds, producing the associated shuffle, and comparing the result against the deck you're searching for. To avoid susceptibility to this kind of attack, the number of possible seeds needs to be large enough that it is computationally infeasible to perform an exhaustive search within certain time constraints. Note that on average only half of the seed space will need to be searched until a match is found. For the purposes of an online card game, the time constraint would be the length of that game, which is usually on the order of minutes.
In our experience, a simple program running on a Pentium 400 computer is able to examine approximately 2 million seeds per minute. At this rate, this single machine could exhaustively search a 32-bit seed space (2^32 possible seeds) in a little over a day. Although that time period is certainly beyond the time constraints we have imposed on ourselves, it is certainly not infeasible to use a network of computers to perform a distributed search within our real time bounds.
The subject of brute force attacks serves to emphasize the aptness of our analogy between key length in a cryptographic algorithm and the seed behind shuffling. A brute-force cryptographic attack involves attempting every possible key in order to decrypt a secret message. Likewise a brute-force attack against a shuffling algorithm involves examining every possible seed. A significant body of research studying the necessary lengths of cryptographic keys already exists. Generally speaking, things look like this:
Algorithm Weak Key Typical Key Strong Key
DES 40 or 56 56 Triple-DES
RC4 60 80 128
RSA 512 768 or 1024 2048
ECC 125 170 230
People used to think that cracking 56-bit DES in real time would take too long to be feasible, but history has shown otherwise. In January 1997, a secret DES key was recovered in 96 days. Later efforts broke keys in 41 days, then 56 hours, and, in January 1999, in 22 hours and 15 minutes. The leap forward in cracking ability doesn't bode well for small key lengths or small sets of seeds!
People have even gone so far as to invent special machines to crack cryptographic algorithms. In 1998, the EFF created a special-purpose machine to crack DES messages. The purpose of the machine was to emphasize just how vulnerable DES (a popular, government-sanction algorithm) really is. (For more on the DES cracker, see http://www.eff.org/descracker/.) The ease of "breaking" DES is directly related to the length of its key. Special machines to uncover RNG seeds are not outside the realm of possibility.
We believe that a 32-bit seed space is not sufficient to resist a determined brute-force attack. On the other hand, a 64-bit seed should be resistant to almost any brute force attack. A 64-bit seed makes sense since many computers provide the ability to work with 64-bit integers off the shelf, and a 64-bit number should be sufficient for the purposes of protecting card shuffling against brute-force attacks.
64-bits alone won't do it though. We can't overemphasize that there must be absolutely no way for an attacker to predict or approximate the seed that is used by the PRNG. If there is a way to predict the seed, then the computationally-taxing brute-force attack outlined above becomes irrelevant (since the entire system breaks much more easily). In terms of our exploit, not only did ASF's flawed approach rely on a too-small 32-bit PRNG, but the approach relies on a seed based on the time of day as well. As our exploit demonstrated, there is very little randomness in such an approach.
In final analysis, the security of the entire system relies on picking a random seed in a non-predictable manner. The best techniques for choosing such a random number are hardware-based. Hardware-based approaches rely on unpredictably random data gathered directly from the physical environment. Since online poker and other games involving real money are extremely security critical undertakings, it's probably worth investing the necessary resources to ensure that random number generation is done correctly.
In concert, a good shuffling algorithm and a 64-bit pseudo-random number generator seeded with a proven hardware device should produce shuffles that are both fair and secure. Implementing a fair system is not overly difficult. Online poker players should demand it.
Posted by
Iyad Atuan
at
1:08 PM
0
comments
Today I read in Discovery that statistically speaking, beautiful couples have daughters as their first child while engineers, mathematicians, violent & big people have sons. Since I am big, and an engineer I am assuming I am going to have a son.
Also, the other day I read in a book that left handed people get 15% higher salaries than a right handed person. No explanation was provided because they did not have one to offer. This explains a lot, since medieval ages, righties have been punishing lefties; I even remember a senior back home telling me how the nuns at school used to hit lefties with a ruler until they stopped using it. We lefties have been the envy of righties for centuries because we are smarter, why else would we get paid more for the same job
I wonder if lefty poker players are more successful…
Posted by
Iyad Atuan
at
1:42 PM
0
comments
Yesterday night I was watching a show called ‘Heroes’. In this show a group of people discover they have unusual powers such as painting the future, immortality, flying, bending time in space and mind reading.
My question to you…as a poker player, what superpower would you chose?
I can confidently guess most of you would choose the power of mind reading. Indeed this is the power that would make you a great poker player, even maybe the greatest. As David Slansky wrote in his book ‘The Theory of Poker’:
Every time you play your hand different than if you could see their hands; they gain.
Every time you play your hand exactly the same as if you could see their hands; they loose.
Every time your opponent plays different than if they could see your hand; they loose.
Every time your opponent plays exactly the same as if they could see your hand; they win.
Posted by
Iyad Atuan
at
9:17 PM
0
comments
Both players played the hand perfectly, but sometimes stuff like that happens in poker. Well i guess 10 grands well spend Hudson.
Posted by
Iyad Atuan
at
6:11 PM
3
comments